Problème virus avec AVAST

Bonjour,
J'ai AVAST comme antivirus pourtant plusieurs problème :
des onglets s'ouvrent inopinément et j'ai Vista et le rond (de recherche, ancien sablier) tourne et se blque. Je suis obligée de tout fermer...
+ problème sur ma messagerie avec mail en anglais et Euro Casino... dont je n'arrive pas à me débarasser...
Et j'ai des messages de Windows internet explorer qui indiquent que mon ordi est infecté et me demande si je veux analyser mon ordi avec proposition de télécharger un logiciel.... Faut-il le faire ?
Quel antivius fau-il prendre ?
Merci de vos conseils
Configuration: Windows Vista
Internet Explorer 7.0

26 réponses

Résumé de la discussion

Plusieurs symptômes signalent une infection sur Windows Vista malgré l'utilisation d'Avast: des onglets s'ouvrent sans avertissement, le rond de recherche tourne sans fin et des messages d'IE invitent à analyser l'ordinateur. Parmi les réponses pertinentes, l'utilisation d'un outil antimalware dédié comme Malwarebytes' Anti-Malware est recommandée pour analyser et supprimer les éléments malveillants après détourage des programmes non fiables. D'autres propositions incluent ComboFix pour un nettoyage plus profond après déconnexion, puis des outils comme HijackThis et OTMoveIt pour identifier et supprimer des éléments persistants et indésirables. Certains messages ajoutent des conseils de sécurité tels que privilégier des antivirus reconnus et éviter les téléchargements suspects, tout en notant que certains outils nécessitent la désactivation temporaire de protections pour fonctionner correctement.

Bobot (l’IA à votre service)
  1. elecharge malwarebytes

    -> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

    Tu l´instale; le programme va se mettre automatiquement a jour.

    Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

    Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".

    Puis click sur "rechercher".

    Laisse le scanner le pc...

    Si des elements on ete trouvés > click sur supprimer la selection.

    si il t´es demandé de redemarrer > click sur "yes".

    A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

    Copie et colle le rapport stp.

    ps : les rapport sont aussi rangé dans l onglet rapport/log
    1. alors j'ai lancé 2 fois malwarebytes mais il y a eu 2 fermetures de mon ordi donc scan pas terminé et pas de rapport !!! Comment faire ????
      Merci d'avance
    2. @gicha1) Redémarre en "Mode sans échec"

      Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
      Sélectionner "Mode sans échec" et appuie sur [Entrée]
      Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
      Regarde ici si besoin : http://pageperso.aol.fr/loraline60/mode_sans_echec.htm

      Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.

      2) Scan avec Malwarebyte's Anti-Malware

      *Lance Malwarebyte's Anti-Malware
      *Puis vs dans l'onglet "Recherche" puis coche "Exécuter un examen complet" puis "Rechercher sélectionne tes disques durs" puis clique sur "Lancer l’examen"
      *A la fin du scan >>> clique sur Afficher les résultats puis sur Enregistrer le rapport
      *Suppression des éléments détectés >>>> clique sur Supprimer la sélection
      *S'il t'es demandé de redémarrer >>> clique sur "Yes"

      *--> Un rapport de scan s'ouvre, enregistre sur ton Bureau et poste ce rapport en réponse.</ital>
    3. @Utilisateur anonymeComment je fais pour redémarreen mode sans échec alors que mon ordi s'est allumé correctement ?
      Il faut que je relance le scan, que ça replante, pour redémarrer sans échec ?
  2. *Téléchargez lopS&D.exe sur votre bureau (Clique-droit sur le lien > Enregistrer la cible du lien sous)
    https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
    *Désactivez votre antivirus au cas où (vous pourrez le réactiver après la fin du scan)
    *Double-clique sur lopS&D pour lancer l'installation
    *Une fois installé, double-clique sur Lop S&D
    *Sélectionne la langue en appuyant sur la touche F, puis choisissez l'option 1 (Recherche)
    *Si lopS&D vous demande de redémarrer acceptez et attendez la fin du scan.
    1. Bonjour,
      J'ai essayé mais quand j'ouvre LOP Sand D, j'indique la langue en français, je mets 1 (recherche) il ouvre une fenêtre rouge indiquant de faire clic droit + Exécuter en tant qu'administrateur, presser 1 touche pour continuer...
      Mais lorsque je fais un clic droit, ça indique "Selectionner ou Coller ou Selectionner tout, ou Rechercher"... Et bref, aucun scan ne se fait...
      Et je n'arrive plus à récupérer AVAST maintenant ???
      ET windows n'arrête pas de me dire que mon ordi est plein de virus ???
      Comment faire ?
      Merci d'avance !
  3. Modérateur
    Salut,

    Stop de proposer des tools qui n'ont rien à voir avec ce que la personne décrit.

    - Télécharge HijackThis V 2.02 (HijackThis Installer) :
    http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe

    - Fais un double-clic sur HJTInstall.exe afin de lancer l'installation

    - Clique sur Install ensuite sur I Accept

    - Clique sur Do a scan system and save log file

    - Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
    1. Bonsoir,
      Voilà ce qui est indiqué, merci d'avance !

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 00:00:37, on 16/06/2008
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16681)
      Boot mode: Normal

      Running processes:
      C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\ASUS\ASUS Live Update\ALU.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Windows\System32\rundll32.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAANOTIF.EXE
      C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\ASUS\ATK Media\DMedia.exe
      C:\Windows\ASScrPro.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
      C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Users\Charlotte Mélandre\AppData\Local\caesqu.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      C:\Program Files\Infineon\Security Platform Software\PSDrt.exe
      C:\Program Files\Infineon\Security Platform Software\SpTna.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\Common Files\Teleca Shared\Generic.exe
      C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
      C:\Windows\system32\wuauclt.exe
      C:\Windows\system32\conime.exe
      C:\Windows\explorer.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O2 - BHO: ASUS Security Protect Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [Skytel] Skytel.exe
      O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
      O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
      O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
      O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
      O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
      O4 - HKLM\..\Run: [IFXSPMGT] C:\Windows\system32\ifxspmgt.exe /NotifyLogon
      O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll,RegisterModule
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
      O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [caesqu] c:\users\charlotte mélandre\appdata\local\caesqu.exe caesqu
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O16 - DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} (Module de délivrance de certificat MINEFI) - https://static.impots.gouv.fr/abos/static/securite/certdgi1.cab
      O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
      O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerVistaADP-1.1.cab
      O16 - DPF: {D3166EE4-3E00-46CA-8F62-8E01D2314A7F} - http://www.cig.canon-europe.com/ph/fr_FR/st/download/ddup/CNIMGUP_01_210102F.cab
      O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - https://www.photostation.fr/?404;http://www.photostation.fr:80/aurigma/ImageUploader4.cab
      O20 - AppInit_DLLs: APSHook.dll
      O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
      O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
      O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Windows\system32\ifxspmgt.exe
      O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Windows\system32\ifxtcs.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
      O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
      O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Windows\system32\IfxPsdSv.exe
      O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
  4. je te conseille d'enlever AVAST met qq chose de plus consistant comme kaspersky
    1. Modérateur
      Infection Magic.Control.

      Désactive l'UAC :
      https://www.zebulon.fr/astuces/pratique/220-desactiver-l-uac-dans-vista.html

      Désactive Avast.

      Fais ceci :

      - Télécharge Navilog1 (de IL-MAFIOSO) et enregistre-le sur le bureau :
      http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

      - Double-clique sur Navilog1.exe afin de lancer l'installation

      - Si le fix ne lance pas automatiquement après son installation, double-clique sur Navilog1 présent sur le bureau

      - Appuie sur F ou f puis valide par Entrée

      - Appuie sur une touche de ton clavier à chaque fois que cela est demandé, tu arriveras au menu des options

      - Choisis l'option 1 et appuie sur la touche Entrée pour valider ton choix

      - Patiente jusqu'au message : *** Analyse Termine le ..... ***

      - Le scan fini, le bloc-notes contenant le rapport sera affiché, poste le contenu de ce rapport dans ta prochaine réponse

      - Si le résultat du scan ne s'affiche pas, tu le trouveras dans C:\fixnavi.txt

      N'utilise pas l'option 2, 3 et 4 sans notre accord, des fichiers légitimes peuvent être inclus dans ce scan.
      1. j'ai installé NAVILOG mais rien ne se passe ?
    2. Faut-il vraimentidésa ctiverl 'UAC??? ETtélécharge runtrucd 'IlMAFIOSO alorsque monor diestvirusé ???Co mmentêtre sure queçanevapas empirer?
      1. Modérateur
        Si tu suis mes instructions à la lettre, aucun problème.

        L'UAC, on le réactivera quand on aura supprimé l'infection. ;)
        1. Salut
          Désactiver l' uac, oui, lis quelques dizaines de pages de forum et tu verras que la désinfection se fait pas si tu le fais pas.
          Il Mafioso, il te faudra lire des dizaines de pages depuis des années, tu comprendras qu' il participe à la mise au point de certains outils utilisés ici, et il a aussi désinfecté sur ccm.
          Destrio 5 se réveille depuis 21h mais semble utiliser les logiciels courants sur ce forum , et bien connaitre leur mode d' emploi.
          1. En attendant , tu peux utiliser cet excellent antimalware, si tu ne touche rien dans l' onglet "protection," il reste en gratuit. Mais il n' a pas la protection temps réel en gratuit. Aujourd' hui pour nettoyer et une fois de temps en temps.
            https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

            Antivir en gratuit est plus efficace que avast, tu peux le mettre, n' oublies pas de désinstaller proprement avast avec l' utilitaire qui va bien. Après installation et mise à jour, nettoyage complet en mode sans échec.
            http://www.commentcamarche.net/faq/sujet 3045 tutoriels tutoriels de logiciels
            http://www.commentcamarche.net/faq/sujet 7367 desinstaller proprement liens et astuces

            Un bon parefeu, comodo pro gratuit meilleur pour vista. désactiver celui de vista. (1 seul sur le pc )

            Pour avoir quand même un antispyware avec protection temps réel, spybot gratuit, il a une 2ème fonction il surveille le registre.
            https://jesses.pagesperso-orange.fr/Docs/Logiciels/Spybot.htm
            Je lui adjoint spywareblaster en gratuit, il met des protections dans les navigateurs, en gratuit tu le fermes pendant une semaine, mise à jour manuelle chaque semaine et c' est tout.
            https://www.google.com

            Celui-là sert à faire le ménage des fichiers inutiles, après une désinfection mais aussi tous les jours, le tuto explique bien. gratuit
            http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

            De temps en temps tu peux aussi contrôler avec un antivirus différent , en ligne c' est important car tu ne dois pas en avoir 2 actifs sur le pc. Kaspersky et bitdéfender sont bons et nettoient. Tu peux le faire aujourd' hui pour nettoyer.
            https://www.informatruc.com

            Après toutes ces installations tu peux défragmenter si tu veux.

            Voilà déjà une bonne protection de base,en gratuit pour fermer le pc, si tu as encore des problèmes, tu peux passer aux logiciels spécialisés. Ici. bizz
            1. Bonjour,
              J'essaie de mettre en place tout ça...
              Une question.
              J'ai installé spy bot... ET après quand j'ai installé comodo, une fenêtre spybot s'ouvre et me demande si j'autorise ou pas les modifs... Je dois accepter ou refuser les modifs ?
              Comment je sais lesquelles accepter ou pas ???
              Merci d'avancE.
          2. J' oubliais de répondre à la question, non ne télécharges rien proposé par internet explorer, n' écoutes que les logiciels que tu as installé.

            Tu surfes avec firefox, gratuit et son module complémentaire antipub adblockplus, c' est plus sur.
            ( les pubs qui passent quand même, c' est parcequ' elles sont téléchargées depuis l' intérieur du pc, ce qu' on te proposait de nettoyer avec des logiciels spécialisés )

            De la même façon, Thunderbird gratuit est un gestionnaire de courriel qui intègre un filtre antispam, tu peux mettre des filtres et lui "apprendre" ce qui est du spam pour toi. tu mets en "indésirable" les mails à rejeter et peu à peu, il les reconnait tout seul. Il sait importer tes mails et ton carnet d' adresse.
            Il tourne "à côté" de windows et ne passe pas par IE, comme firefox, grâce au même moteur gecko.
            http://frenchmozilla.sourceforge.net/
            Ce livre gratuit à télécharger pour tout savoir et qui sert de tuto.
            http://www.framabook.org/thunderbird.html
            Ce forum en français est spécialisé pour les logiciels libres , firefox et thunderbird donc.
            https://www.hugedomains.com/domain_profile.cfm?d=geckozone&e=org
            1. Merci, e vais essayer ça, mais je crois que j'ai déjà télécharger un truc du centre windows ? ET il ne fallait pas ...
              Par contre, je ne sais ps tyrop comment "désinstaller proprement AVAST avec l'utilitaire qui va bien", ni désactiver le pare-feu de vista ? c'est où ?
              ET comment supprimer le résuktat du bloc note dans ma réponse d'avant ?
              Merci d'avance
            2. Bon,

              tout redéconne, a nouveau fenêtre pub + eu message : access violation at adress 004B6BE9 in module tea timer.exe. Read of adress 00000010

              ET le rond de Vista tourne tourne et ne s'arrête pas, si onje recommence ça bloque tout !Je suis obligée de faire CTRL ALT SUP et de fermer la session !!!

              Je fais quoi ?

              Merci d'avance
          3. Modérateur
            Re,

            Bon là, on s'égare. T'es infecté par Magic.Control, il faut utiliser Navilog1.
            1. Modérateur
              Relis mes canneds. Tout est expliqué.
              1. J'ai déjà lu, mais lorsque je double clique, je mets exécuter, il me demande la langue, l'acceptation du contrat, suivant, installer terminer et c'est tout !
            2. Modérateur
              Sur ton bureau, tu dois avoir un raccourci, double-clique dessus.
              1. C'est ce que je fais, mais la suite est celle que j'ai indiqué dans mon message précédent ?? Il ne démarre pas de recherche ni rien ??
            3. Modérateur
              Après l'installation, il ne faut pas double-cliquer sur l'installateur mais bien sur le raccourci qui vient d'être créé.
              1. Bon, il ne se lançait pas depuis l'icone bureau, je suis passée par programmes.... ET voilà le résultat :

                Search Navipromo version 3.5.8 commencé le 16/06/2008 à 13:15:40,07

                !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                !!! Postez ce rapport sur le forum pour le faire analyser !!!
                !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                Outil exécuté depuis C:\Program Files\navilog1
                Session actuelle : "Charlotte Mélandre"

                Mise à jour le 06.06.2008 à 18h00 par IL-MAFIOSO

                Microsoft Windows Vista 6.0.6000
                Internet Explorer : 7.0.6000.16681
                Système de fichiers : NTFS

                Recherche executé en mode normal

                *** Recherche Programmes installés ***

                *** Recherche dossiers dans "C:\Windows" ***

                *** Recherche dossiers dans "C:\Program Files" ***

                *** Recherche dossiers dans "C:\ProgramData" ***

                *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                *** Recherche dossiers dans "c:\users\charlo~1\appdata\roaming\micros~1\windows\startm~1\programs" ***

                *** Recherche dossiers dans "C:\Users\Charlotte M‚landre\AppData\Local\virtualstore\Program Files" ***

                *** Recherche dossiers dans "C:\Users\Charlotte M‚landre\AppData\Roaming" ***

                *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                pour + d'infos : http://www.gmer.net

                Aucun Fichier trouvé

                *** Recherche avec GenericNaviSearch ***
                !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                !!! A vérifier impérativement avant toute suppression manuelle !!!

                * Recherche dans "C:\Windows\system32" *

                * Recherche dans "C:\Users\Charlotte M‚landre\AppData\Local\Microsoft" *

                * Recherche dans "C:\Users\Charlotte M‚landre\AppData\Local\virtualstore\windows\system32" *

                * Recherche dans "C:\Users\Charlotte M‚landre\AppData\Local" *

                Fichiers trouvés :

                caesqu.exe trouvé !
                caesqu.dat trouvé !
                caesqu_nav.dat trouvé !
                caesqu_navps.dat trouvé !

                *** Recherche fichiers ***

                C:\Windows\system32\nvs2.inf trouvé !

                *** Recherche clés spécifiques dans le Registre ***

                HKEY_CURRENT_USER\Software\Lanconfig trouvé !

                *** Module de Recherche complémentaire ***
                (Recherche fichiers spécifiques)

                1)Recherche nouveaux fichiers Instant Access :

                2)Recherche Heuristique :

                * Dans "C:\Windows\system32" :

                * Dans "C:\Users\Charlotte M‚landre\AppData\Local\Microsoft" :

                * Dans "C:\Users\Charlotte M‚landre\AppData\Local\virtualstore\windows\system32" :

                * Dans "C:\Users\Charlotte M‚landre\AppData\Local" :

                caesqu.dat trouvé !
                caesqu_nav.dat trouvé !
                caesqu_navps.dat trouvé !

                3)Recherche Certificats :

                Certificat Egroup trouvé !
                Certificat Electronic-Group trouvé !
                Certificat OOO-Favorit trouvé !
                Certificat Sunny-Day-Design-Ltd absent !

                4)Recherche fichiers connus :

                *** Analyse terminée le 16/06/2008 à 13:20:27,27 *
            4. Salut

              me voila a ta demande :

              Veille à ce que le contrôle des comptes utilisateurs (UAC) soit désactivé.
              Fais un Clic-droit sur le raccourci Navilog1 présent sur ton bureau et choisis "Exécuter en tant qu'administrateur".

              Au menu principal, Fais le choix 2

              Laisse toi guider et patiente.
              Le fix va t'informer qu'il va alors redémarrer ton PC
              Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
              Appuie sur une touche comme demandé.
              (si ton Pc ne redémarre pas automatiquement, fais-le toi-même)
              Au redémarrage de ton PC, choisis ta session habituelle si nécessaire.
              Patiente jusqu'au message :
              *** Nettoyage Termine le ..... ***
              Le blocnote va s'ouvrir.
              Sauvegarde le rapport de manière à le retrouver
              Referme le blocnote. Ton bureau va réapparaître
              Réactive le contrôle des comptes utilisateurs (UAC)

              PS:Si ton bureau ne réapparaît pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
              Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
              Tape explorer et valide. Cela te fera apparaître ton bureau
              1. Voici le rapport :

                Clean Navipromo version 3.5.8 commencé le 16/06/2008 à 13:49:11,31

                Outil exécuté depuis C:\Program Files\navilog1
                Session actuelle : "Charlotte Mélandre"

                Mise à jour le 06.06.2008 à 18h00 par IL-MAFIOSO

                Microsoft Windows Vista 6.0.6000
                Internet Explorer : 7.0.6000.16681
                Système de fichiers : NTFS

                Mode suppression automatique
                avec prise en charge résultats Catchme et GNS

                Nettoyage exécuté au redémarrage de l'ordinateur

                *** fsbl1.txt non trouvé ***
                (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                * Suppression dans "C:\Windows\System32" *

                * Suppression dans "C:\Users\Charlotte M‚landre\AppData\Local\Microsoft" *

                * Suppression dans "C:\Users\Charlotte M‚landre\AppData\Local\virtualstore\windows\system32" *

                * Suppression dans "C:\Users\Charlotte M‚landre\AppData\Local" *

                caesqu.exe trouvé !
                Copie caesqu.exe réalisée avec succès !
                caesqu.exe supprimé !

                caesqu.dat trouvé !
                Copie caesqu.dat réalisée avec succès !
                caesqu.dat supprimé !

                caesqu_nav.dat trouvé !
                Copie caesqu_nav.dat réalisée avec succès !
                caesqu_nav.dat supprimé !

                caesqu_navps.dat trouvé !
                Copie caesqu_navps.dat réalisée avec succès !
                caesqu_navps.dat supprimé !

                *** Suppression dossiers dans "C:\Windows" ***

                *** Suppression dossiers dans "C:\Program Files" ***

                *** Suppression dossiers dans "C:\ProgramData" ***

                *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                *** Suppression dossiers dans c:\users\charlo~1\appdata\roaming\micros~1\windows\startm~1\programs ***

                *** Suppression dossiers dans "C:\Users\Charlotte M‚landre\AppData\Local\virtualstore\Program Files" ***

                *** Suppression dossiers dans "C:\Users\Charlotte M‚landre\AppData\Roaming" ***

                *** Suppression fichiers ***

                C:\Windows\system32\nvs2.inf supprimé !

                *** Suppression fichiers temporaires ***

                Nettoyage contenu C:\Windows\Temp effectué !
                Nettoyage contenu C:\Users\CHARLO~1\AppData\Local\Temp effectué !

                *** Traitement Recherche complémentaire ***
                (Recherche fichiers spécifiques)

                1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                2)Recherche, création sauvegardes et suppression Heuristique :

                * Dans "C:\Windows\system32" *

                * Dans "C:\Users\Charlotte M‚landre\AppData\Local\Microsoft" *

                * Dans "C:\Users\Charlotte M‚landre\AppData\Local\virtualstore\windows\system32" *

                * Dans "C:\Users\Charlotte M‚landre\AppData\Local" *

                *** Sauvegarde du Registre vers dossier Safebackup ***

                sauvegarde du Registre réalisée avec succès !

                *** Nettoyage Registre ***

                Nettoyage Registre Ok

                *** Certificats ***

                Certificat Egroup supprimé !
                Certificat Electronic-Group supprimé !
                Certificat OOO-Favorit supprimé !
                Certificat Sunny-Day-Design-Ltdt absent !

                *** Nettoyage terminé le 16/06/2008 à 13:54:02,16 ***
            5. refais un scan hijackthis et post le rapport stp
              1. Voilà le rapport :

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 00:00:37, on 16/06/2008
                Platform: Windows Vista (WinNT 6.00.1904)
                MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                Boot mode: Normal

                Running processes:
                C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
                C:\Windows\system32\taskeng.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\system32\taskeng.exe
                C:\Program Files\ASUS\ASUS Live Update\ALU.exe
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\Windows\System32\rundll32.exe
                C:\Windows\RtHDVCpl.exe
                C:\Program Files\Intel\Intel Matrix Storage Manager\IAANOTIF.EXE
                C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                C:\Windows\System32\rundll32.exe
                C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                C:\Program Files\ASUS\ATK Media\DMedia.exe
                C:\Windows\ASScrPro.exe
                C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
                C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                C:\Program Files\Windows Sidebar\sidebar.exe
                C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
                C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                C:\Program Files\Windows Media Player\wmpnscfg.exe
                C:\Users\Charlotte Mélandre\AppData\Local\caesqu.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                C:\Program Files\Infineon\Security Platform Software\PSDrt.exe
                C:\Program Files\Infineon\Security Platform Software\SpTna.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                C:\Program Files\Common Files\Teleca Shared\Generic.exe
                C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                C:\Windows\system32\wuauclt.exe
                C:\Windows\system32\conime.exe
                C:\Windows\explorer.exe
                C:\Program Files\Mozilla Firefox\firefox.exe
                C:\Windows\system32\SearchFilterHost.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                O1 - Hosts: ::1 localhost
                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O2 - BHO: ASUS Security Protect Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                O4 - HKLM\..\Run: [Skytel] Skytel.exe
                O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
                O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
                O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
                O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
                O4 - HKLM\..\Run: [IFXSPMGT] C:\Windows\system32\ifxspmgt.exe /NotifyLogon
                O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll,RegisterModule
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                O4 - HKCU\..\Run: [caesqu] c:\users\charlotte mélandre\appdata\local\caesqu.exe caesqu
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
                O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                O13 - Gopher Prefix:
                O16 - DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} (Module de délivrance de certificat MINEFI) - https://static.impots.gouv.fr/abos/static/securite/certdgi1.cab
                O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
                O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerVistaADP-1.1.cab
                O16 - DPF: {D3166EE4-3E00-46CA-8F62-8E01D2314A7F} - http://www.cig.canon-europe.com/ph/fr_FR/st/download/ddup/CNIMGUP_01_210102F.cab
                O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - https://www.photostation.fr/?404;http://www.photostation.fr:80/aurigma/ImageUploader4.cab
                O20 - AppInit_DLLs: APSHook.dll
                O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Windows\system32\ifxspmgt.exe
                O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Windows\system32\ifxtcs.exe
                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
                O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Windows\system32\IfxPsdSv.exe
                O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
            6. télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau.
              double-clique sur OTMoveIt.exe pour le lancer.
              copie la liste qui se trouve en gras ci-dessous,
              et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

              C:\Users\Charlotte Mélandre\AppData\Local\caesqu.exe
              c:\users\charlotte mélandre\appdata\local\caesqu.exe caesqu


              clique sur MoveIt! pour lancer la suppression.
              le résultat apparaitra dans le cadre "Results".
              clique sur Exit pour fermer.
              poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

              il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
              1. voilà :

                RESULTS

                File/Folder C:\Users\Charlotte Mélandre\AppData\Local\caesqu.exe not found.
                File/Folder c:\users\charlotte mélandre\appdata\local\caesqu.exe caesqu not found.

                OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 06162008_152608
            7. Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

              -> Double clique combofix.exe.
              -> Tape sur la touche 1 (Yes) pour démarrer le scan.
              -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

              NOTE : Le rapport se trouve également ici : C:\Combofix.txt

              Avant d'utiliser ComboFix :

              -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

              -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

              Une fois fait, sur ton bureau double-clic sur Combofix.exe.

              - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

              /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

              - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

              - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

              -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

              -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

              -> Tutoriel https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

              1. Alors là j'ai été obligée de prendre un autre ordi car le scan a été lancé puis il était indiqué :
                Supression des fichiers :
                C/programfiles/p4p/bookmark-ini et
                C/programfiles/p4p

                Terminée étpae 1... jusque 41

                Ensuite plus rien pendant un moment, ensuite la fenêtre s'est fermée...

                Maintenant je n'ai que l'image de fond sur mon ordi et plus de boutons !!!

                Que dois-je faire ?

                Merci d'avance !
            8. -> Redémarre en mode sans échec :

              Comment redémarrer en mode sans echec?

              Tu redemarre le pc et tapote la touche F8 des le début de l allumage sans t´arrêter.
              Une fenêtre sur fond noir va s’ouvrir, tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
              Une fois sur le bureau si il n y a pas toutes les couleurs et autres c´est normal!
              Ps : si F8 ne marche pas utilise la touche F5.

              -> Tuto : http://forum.telecharger.01net.com/forum/

              une fois en mode sans echec rééxécute combofix

              pui sredémarre le pc et envoi le rapport stp
              1. ComboFix 08-06-15.4 - Charlotte Mélandre 2008-06-16 16:12:42.2 - NTFSx86 MINIMAL
                Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.2644 [GMT 2:00]
                Endroit: C:\Users\Charlotte Mélandre\Desktop\ComboFix.exe
                .

                (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                ---- Previous Run -------
                .
                C:\Program Files\p4p
                C:\Program Files\p4p\Bookmark.ini

                .
                ((((((((((((((((((((((((((((( Fichiers créés 2008-05-16 to 2008-06-16 ))))))))))))))))))))))))))))))))))))
                .

                Pas de nouveau fichier créé dans cet espace de temps

                .
                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2008-06-16 14:10 2,621,440 --sha-w C:\Users\Charlotte Mélandre\NTUSER.DAT
                2008-06-16 14:10 2,621,440 --sha-w C:\Users\Charlotte Mélandre\NTUSER.DAT
                2008-06-16 14:09 45,056 ----a-w C:\Windows\System32\acovcnt.exe
                2008-06-16 12:29 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
                2008-06-16 11:54 --------- d-----w C:\Program Files\Navilog1
                2008-06-16 10:13 --------- d-----w C:\Users\Charlotte Mélandre\AppData\Roaming\Malwarebytes
                2008-06-16 10:13 --------- d-----w C:\ProgramData\Malwarebytes
                2008-06-15 22:00 --------- d-----w C:\Program Files\Trend Micro
                2008-06-14 16:04 --------- d-----w C:\Users\Charlotte Mélandre\AppData\Roaming\ZoomBrowser EX
                2008-06-14 16:04 --------- d-----w C:\ProgramData\ZoomBrowser
                2008-06-12 07:55 --------- d-----w C:\Program Files\Windows Mail
                2008-06-11 15:10 29,074 ----a-w C:\Users\Charlotte Mélandre\AppData\Roaming\nvModes.dat
                2008-06-10 17:02 34,296 ----a-w C:\Windows\system32\drivers\mbamcatchme.sys
                2008-06-10 17:02 15,864 ----a-w C:\Windows\system32\drivers\mbam.sys
                2008-06-09 18:53 --------- d-----w C:\ProgramData\Symantec
                2008-06-09 18:53 --------- d-----w C:\Program Files\Common Files\Symantec Shared
                2008-06-09 18:20 --------- d-----w C:\Program Files\Symantec
                2008-06-08 08:54 --------- d--h--w C:\Program Files\InstallShield Installation Information
                2008-06-08 08:54 --------- d-----w C:\ProgramData\BVRP Software
                2008-06-08 08:54 --------- d-----w C:\Program Files\Happyneuron
                2008-06-08 08:54 --------- d-----w C:\Program Files\BVRP Software
                2008-05-27 18:34 --------- d-----w C:\Program Files\Alwil Software
                2008-05-25 22:34 --------- d-----w C:\Program Files\Photo Station
                2008-05-15 17:40 --------- d-----w C:\ProgramData\Microsoft Help
                2008-05-15 17:35 --------- d-----w C:\Users\Charlotte Mélandre\AppData\Roaming\Teleca
                2008-05-14 12:00 --------- d-----w C:\Program Files\Sony
                2008-05-14 11:33 --------- d-----w C:\Users\Charlotte Mélandre\AppData\Roaming\Sony Ericsson
                2008-05-14 11:33 --------- d-----w C:\ProgramData\Teleca
                2008-05-14 11:33 --------- d-----w C:\ProgramData\Sony Ericsson
                2008-05-14 11:33 --------- d-----w C:\Program Files\Sony Ericsson
                2008-05-14 11:33 --------- d-----w C:\Program Files\Common Files\Teleca Shared
                2008-05-14 11:33 --------- d-----w C:\Program Files\Common Files\Sony Ericsson Shared
                2008-05-13 21:11 --------- d-----w C:\Users\Charlotte Mélandre\AppData\Roaming\HP
                2008-05-10 03:30 14,848 ----a-w C:\Windows\System32\wshrm.dll
                2008-05-10 01:21 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys
                2008-04-29 03:50 181,760 ----a-w C:\Windows\System32\fsquirt.exe
                2008-04-29 01:42 29,184 ----a-w C:\Windows\system32\drivers\BTHUSB.SYS
                2008-04-29 01:42 220,160 ----a-w C:\Windows\system32\drivers\bthport.sys
                2008-04-29 01:42 19,456 ----a-w C:\Windows\system32\drivers\bthenum.sys
                2008-04-26 08:02 1,327,104 ----a-w C:\Windows\System32\quartz.dll
                2008-04-25 04:23 826,368 ----a-w C:\Windows\System32\wininet.dll
                2008-04-25 04:23 56,320 ----a-w C:\Windows\System32\iesetup.dll
                2008-04-25 04:23 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
                2008-04-25 04:22 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
                2008-04-23 04:27 428,032 ----a-w C:\Windows\System32\EncDec.dll
                2008-04-23 04:27 292,352 ----a-w C:\Windows\System32\psisdecd.dll
                2008-04-23 04:27 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
                2008-04-16 08:36 --------- d-----w C:\Program Files\Windows Live
                2008-01-28 20:47 174 --sha-w C:\Program Files\desktop.ini
                .

                ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                REGEDIT4
                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-02-27 16:30 1232896]
                "WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 14:34 2159104 C:\Windows\System32\oobefldr.dll]
                "LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-06-20 13:49 451872]
                "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-03-24 00:00 171448]
                "MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
                "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 14:36 201728]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-12-05 12:17 86016]
                "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-12-05 12:17 8534560]
                "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-12-05 12:17 81920]
                "RtHDVCpl"="RtHDVCpl.exe" [2007-08-27 07:10 4702208 C:\Windows\RtHDVCpl.exe]
                "Skytel"="Skytel.exe" [2007-08-03 07:22 1826816 C:\Windows\SkyTel.exe]
                "IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-10-24 04:02 178712]
                "IaNvSrv"="C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe" [2007-10-24 04:02 33304]
                "SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-24 19:31 630784]
                "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-02 23:24 857648]
                "ATKMEDIA"="C:\Program Files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 18:27 61440]
                "ASUS Camera ScreenSaver"="C:\Windows\ASScrProlog.exe" [2008-01-28 23:44 37232]
                "ASUS Screen Saver Protector"="C:\Windows\ASScrPro.exe" [2008-01-28 23:44 33136]
                "IFXSPMGT"="C:\Windows\system32\ifxspmgt.exe" [2007-02-26 05:29 677408]
                "CognizanceTS"="C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll" [2003-12-21 23:11 17920]
                "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 16:57 153136]
                "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-09 17:18 185896]
                "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 21:52 49152]
                "Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-06-13 08:16 528384]

                C:\Users\Charlotte M‚landre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                OneNote 2007 - Capture d'‚cran et lancement.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 05:45:42 101784]

                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
                Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-03-26 23:24:07 113664]
                Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 01:01:50 734872]
                HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 21:40:10 210520]
                Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 02:48:20 40048]

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                "AppInit_DLLs"=APSHook.dll

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                "vidc.i420"= vdrcodec.dll
                "VIDC.MJPG"= Pvmjpg30.dll

                [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                "UacDisableNotify"=dword:00000001
                "InternetSettingsDisableNotify"=dword:00000001
                "AutoUpdateDisableNotify"=dword:00000001

                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                "DisableMonitoring"=dword:00000001

                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                "DisableMonitoring"=dword:00000001

                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                "DisableMonitoring"=dword:00000001

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
                "{CD2D4E01-BEEA-4BA4-970C-3B46F737B610}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
                "{6FAA3B93-4C29-4886-8177-80A83348B101}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
                "{6DDC7C45-6932-44CE-83A0-1967844E3D6E}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
                "{19FE354E-B03F-4644-92A0-704E7663F7A5}"= UDP:C:\Program Files\Pinnacle\Studio 11\programs\RM.exe:Render Manager
                "{85E2F9CF-2B17-4CFD-93EE-6833352CD0F2}"= TCP:C:\Program Files\Pinnacle\Studio 11\programs\RM.exe:Render Manager
                "{E4C7B32E-C6DD-4955-9290-9B9A9334B514}"= UDP:C:\Program Files\Pinnacle\Studio 11\programs\Studio.exe:Studio
                "{6F8D5346-C857-4061-8582-A9B65F6ED754}"= TCP:C:\Program Files\Pinnacle\Studio 11\programs\Studio.exe:Studio
                "{E5BA7FFF-8522-4B5D-B3F1-6D8C10D9332F}"= UDP:C:\Program Files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe:PMSRegisterFile
                "{EE038533-14CB-4643-A2E7-4F17887E9F66}"= TCP:C:\Program Files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe:PMSRegisterFile
                "{119D51BE-A1A9-4F7E-9EF9-974F9342F2E7}"= UDP:C:\Program Files\Pinnacle\Studio 11\programs\umi.exe:umi
                "{DA9C8037-6E16-4A39-A341-77804678A612}"= TCP:C:\Program Files\Pinnacle\Studio 11\programs\umi.exe:umi
                "{762960B8-E9AD-4F81-9894-AC38C010EC1F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
                "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

                R0 iaNvStor;Intel(R) Turbo Memory Controller;C:\Windows\system32\DRIVERS\iaNvStor.sys [2007-10-02 13:53]
                R0 lullaby;lullaby;C:\Windows\system32\DRIVERS\lullaby.sys [2007-09-27 01:03]
                R1 PersonalSecureDrive;PersonalSecureDrive;C:\Windows\system32\drivers\psd.sys [2007-01-23 14:07]
                S1 ItSDisk;ItSDisk;C:\Windows\system32\Drivers\ItSDisk.sys [2006-05-16 19:13]
                S2 ASBroker;Courtier de session de connexion;C:\Windows\System32\svchost.exe [2006-11-02 11:45]
                S2 ASChannel;Canal de communication local;C:\Windows\System32\svchost.exe [2006-11-02 11:45]
                S3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;C:\Windows\system32\DRIVERS\l160x86.sys [2007-10-31 13:55]
                S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\Windows\system32\DRIVERS\fbxusb32.sys [2004-10-20 17:23]
                S3 MBAMCatchMe;MBAMCatchMe;C:\Windows\system32\drivers\mbamcatchme.sys [2008-06-10 19:02]
                S3 s816bus;Sony Ericsson Device 816 driver (WDM);C:\Windows\system32\DRIVERS\s816bus.sys [2007-06-19 09:51]
                S3 s816mdfl;Sony Ericsson Device 816 USB WMC Modem Filter;C:\Windows\system32\DRIVERS\s816mdfl.sys [2007-06-19 09:51]
                S3 s816mdm;Sony Ericsson Device 816 USB WMC Modem Driver;C:\Windows\system32\DRIVERS\s816mdm.sys [2007-06-19 09:51]
                S3 s816mgmt;Sony Ericsson Device 816 USB WMC Device Management Drivers (WDM);C:\Windows\system32\DRIVERS\s816mgmt.sys [2007-06-19 09:51]
                S3 s816nd5;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (NDIS);C:\Windows\system32\DRIVERS\s816nd5.sys [2007-06-19 09:51]
                S3 s816obex;Sony Ericsson Device 816 USB WMC OBEX Interface;C:\Windows\system32\DRIVERS\s816obex.sys [2007-06-19 09:51]
                S3 s816unic;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (WDM);C:\Windows\system32\DRIVERS\s816unic.sys [2007-06-19 09:51]

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                bthsvcs REG_MULTI_SZ BthServ
                GPSvcGroup REG_MULTI_SZ GPSvc
                Cognizance REG_MULTI_SZ ASBroker ASChannel
                HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
                hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
                \shell\AutoRun\command - wd_windows_tools\WDEULA.exe

                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{64f3f80a-e61a-11dc-8586-001de0662c57}]
                \shell\AutoRun\command - G:\LaunchU3.exe

                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a238aed3-f50b-11dc-8ba8-0007cb0000ff}]
                \shell\AutoRun\command - wd_windows_tools\WDEULA.exe

                *Newly Created Service* - ECACHE

                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
                "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
                .
                Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
                "2008-06-15 19:38:11 C:\Windows\Tasks\User_Feed_Synchronization-{1E091C79-8A7B-4949-9D58-E24964E156D0}.job"
                - C:\Windows\system32\msfeedssync.exe
                "2008-04-14 14:33:48 C:\Windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
                - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
                .
                **************************************************************************

                catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-06-16 16:14:49
                Windows 6.0.6000 NTFS

                Balayage processus cachés ...

                Balayage caché autostart entries ...

                Balayage des fichiers cachés ...

                Scan terminé avec succès
                Les fichiers cachés: 0

                **************************************************************************
                .
                Temps d'accomplissement: 2008-06-16 16:15:07
                ComboFix-quarantined-files.txt 2008-06-16 14:15:05

                Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
                Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.

                189 --- E O F --- 2008-06-15 09:21:48
            9. refais un scan hijackthis et post le rapport stp
              1. Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 00:00:37, on 16/06/2008
                Platform: Windows Vista (WinNT 6.00.1904)
                MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                Boot mode: Normal

                Running processes:
                C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
                C:\Windows\system32\taskeng.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\system32\taskeng.exe
                C:\Program Files\ASUS\ASUS Live Update\ALU.exe
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\Windows\System32\rundll32.exe
                C:\Windows\RtHDVCpl.exe
                C:\Program Files\Intel\Intel Matrix Storage Manager\IAANOTIF.EXE
                C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                C:\Windows\System32\rundll32.exe
                C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                C:\Program Files\ASUS\ATK Media\DMedia.exe
                C:\Windows\ASScrPro.exe
                C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
                C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                C:\Program Files\Windows Sidebar\sidebar.exe
                C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
                C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                C:\Program Files\Windows Media Player\wmpnscfg.exe
                C:\Users\Charlotte Mélandre\AppData\Local\caesqu.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                C:\Program Files\Infineon\Security Platform Software\PSDrt.exe
                C:\Program Files\Infineon\Security Platform Software\SpTna.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                C:\Program Files\Common Files\Teleca Shared\Generic.exe
                C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                C:\Windows\system32\wuauclt.exe
                C:\Windows\system32\conime.exe
                C:\Windows\explorer.exe
                C:\Program Files\Mozilla Firefox\firefox.exe
                C:\Windows\system32\SearchFilterHost.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                O1 - Hosts: ::1 localhost
                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O2 - BHO: ASUS Security Protect Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                O4 - HKLM\..\Run: [Skytel] Skytel.exe
                O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
                O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
                O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
                O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
                O4 - HKLM\..\Run: [IFXSPMGT] C:\Windows\system32\ifxspmgt.exe /NotifyLogon
                O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll,RegisterModule
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                O4 - HKCU\..\Run: [caesqu] c:\users\charlotte mélandre\appdata\local\caesqu.exe caesqu
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
                O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                O13 - Gopher Prefix:
                O16 - DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} (Module de délivrance de certificat MINEFI) - https://static.impots.gouv.fr/abos/static/securite/certdgi1.cab
                O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
                O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerVistaADP-1.1.cab
                O16 - DPF: {D3166EE4-3E00-46CA-8F62-8E01D2314A7F} - http://www.cig.canon-europe.com/ph/fr_FR/st/download/ddup/CNIMGUP_01_210102F.cab
                O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - https://www.photostation.fr/?404;http://www.photostation.fr:80/aurigma/ImageUploader4.cab
                O20 - AppInit_DLLs: APSHook.dll
                O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Windows\system32\ifxspmgt.exe
                O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Windows\system32\ifxtcs.exe
                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
                O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Windows\system32\IfxPsdSv.exe
                O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
            • 1
            • 2