Win spyware secure m empoisonne!!!

Résolu
Bonjour,
je dois me débarassé de ce win syware secure mais j'ai besoin de vtre aide merci par avance
Configuration: Windows XP
Internet Explorer 7.0

11 réponses

  1. Contributeur
    Salut,

    cd \
    dir /a /s /o:n /b c:\*.navps.dat > %systemdrive%\resultat.txt
    dir /a /s /o:n /b c:\*.nav.dat >> %systemdrive%\resultat.txt
    dir "%LOCALAPPDATA%\Microsoft\*.dat" >> %systemdrive%\resultat.txt
    dir "%LOCALAPPDATA%\\Local\virtualstore\windows\system32\*.dat" >> %systemdrive%\resultat.txt
    notepad %systemdrive%\resultat.txt


    tu ouvres le bloc note et y copie et colle ce qu´il y a ci dessus en gras> puis > fichier > enregistrer sous > tu le nomes navi.bat

    type de fichier > tout.

    tu veux l´enregistrer sur ton bureau.

    une fois enregistré sur ton bureau > double click sur navi.bat > la fenetre cmd va s´ouvrir et faire une recherche, a la fin de la recherche le block note va s´ouvrir > copie et colle le contenu de resultat.txt ici stp

    @+
    0
    1. voilà j'ai fait ce que tu m as dit mais rien n apparait dans le fichier text , il est vierge!
      0
      1. Contributeur
        bon, merci ;)

        Fais un clic droit sur ce lien :
        http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
        Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
        Ensuite double clique sur navilog1.exe pour lancer l'installation.
        Une fois l'installation terminée, le fix s'exécutera automatiquement.
        (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

        Laisse-toi guider. Au menu principal, choisis 1 et valides.
        (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

        Patiente jusqu'au message :
        *** Analyse Termine le ..... ***
        Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
        Copie-colle l'intégralité dans une réponse. Referme le blocnote.
        Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

        @+
        0
        1. voilà le resultat

          !!! Postez ce rapport sur le forum pour le faire analyser !!!
          !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

          Outil exécuté depuis C:\Program Files\navilog1
          Session actuelle : "utilisateur"

          Mise à jour le 19.07.2008 à 20h00 par IL-MAFIOSO

          Microsoft Windows XP [version 5.1.2600]
          Internet Explorer : 7.0.5730.13
          Système de fichiers : NTFS

          Recherche executé en mode normal

          *** Recherche Programmes installés ***

          *** Recherche dossiers dans "C:\WINDOWS" ***

          *** Recherche dossiers dans "C:\Program Files" ***

          *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

          *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\utilisateur\applic~1" ***

          *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\utilisateur\locals~1\applic~1" ***

          *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\utilisateur\menudm~1\progra~1" ***

          *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***

          *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
          pour + d'infos : http://www.gmer.net

          Aucun Fichier Navipromo trouvé

          *** Recherche avec GenericNaviSearch ***
          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
          !!! A vérifier impérativement avant toute suppression manuelle !!!

          * Recherche dans "C:\WINDOWS\system32" *

          * Recherche dans "C:\Documents and Settings\utilisateur\locals~1\applic~1" *

          * Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

          *** Recherche fichiers ***

          *** Recherche clés spécifiques dans le Registre ***

          *** Module de Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Recherche nouveaux fichiers Instant Access :

          2)Recherche Heuristique :

          * Dans "C:\WINDOWS\system32" :

          * Dans "C:\Documents and Settings\utilisateur\locals~1\applic~1" :

          * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :

          3)Recherche Certificats :

          Certificat Egroup absent !
          Certificat Electronic-Group absent !
          Certificat OOO-Favorit absent !
          Certificat Sunny-Day-Design-Ltd absent !

          4)Recherche fichiers connus :

          *** Analyse terminée le 28/07/2008 à 18:42:53,84 ***
          0
          1. Contributeur
            Dans les deux rapports que tu m´as fourni il n´y pas trace de spwyare secure... (l´infection aurait du etre visible...)

            pour voir de plus pres :

            Télécharge HijackThis ici :

            -> http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

            Tutoriel d´instalation : (Merci a Balltrap34 pour cette réalisation)

            -> http://pageperso.aol.fr/balltrap34/Hijenr.gif

            Tutoriel d´utilisation (video) : (Merci a Balltrap34 pour cette réalisation)

            -> http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

            Post le rapport généré ici stp...

            @+
            0
            1. ok ben voilà la suite :

              Logfile of HijackThis v1.99.1
              Scan saved at 18:48:02, on 28/07/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16674)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
              C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe
              C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\WINDOWS\ZSSnp211.exe
              C:\WINDOWS\Domino.exe
              C:\WINDOWS\soundman.exe
              C:\WINDOWS\system32\igfxtray.exe
              C:\WINDOWS\system32\hkcmd.exe
              C:\Program Files\Orange\Systray\SystrayApp.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
              C:\Program Files\MSN Messenger\msnmsgr.exe
              C:\Program Files\Orange\Launcher\Launcher.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\wspwprtc.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Orange\connectivity\connectivitymanager.exe
              C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
              C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
              C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\MSN Messenger\usnsvc.exe
              C:\WINDOWS\notepad.exe
              C:\Program Files\7-Zip\7zFM.exe
              C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\7zO4.tmp\HijackThis.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
              O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
              O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe"
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
              O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe
              O4 - HKLM\..\Run: [SoundMan] soundman.exe
              O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
              O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
              O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
              O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [s9201] "C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\wspwprtc.exe" /autorun
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O11 - Options group: [INTERNATIONAL] International*
              O15 - Trusted Zone: https://www.orange.fr/portail
              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
              O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
              O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
              O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
              O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
              O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
              O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
              0
              1. Contributeur
                ok il y a eu confusion sur l´infection, tu as winspyware protect, c´est pour cela que je ne l´ai pas vu avec mes outils ;)

                pour le supprimer :

                Télécharge combofix.exe (par sUBs) sur ton Bureau.

                -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                -> Double clique combofix.exe.
                -> Tape sur la touche 1 (Yes) pour démarrer le scan.
                -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                Avant d'utiliser ComboFix :

                -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

                -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

                Une fois fait, sur ton bureau double-clic sur Combofix.exe.

                - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

                /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

                - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

                - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

                -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

                -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

                -> Tutoriel https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                @+
                0
                1. bon voilà me revoilou et voici ce que tu m as demandé

                  ComboFix 08-07-27.6 - utilisateur 2008-07-28 19:01:55.1 - NTFSx86
                  Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.230 [GMT 2:00]
                  Endroit: C:\Documents and Settings\utilisateur\Bureau\ComboFix.exe
                  * Création d'un nouveau point de restauration

                  [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                  .

                  (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                  .

                  C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL
                  C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\BASE\vbase.bak
                  C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\BASE\vbase.dat
                  C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080720235941981.log
                  C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080721000352826.log
                  C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080721001525578.log
                  C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080721161642250.log
                  C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080726185707687.log
                  C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080726201752125.log
                  C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080728180509281.log
                  C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\wspwprtc.exe

                  .
                  ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-28 to 2008-07-28 ))))))))))))))))))))))))))))))))))))
                  .

                  2008-07-26 21:37 . 2008-07-28 18:43 <REP> d-------- C:\Program Files\Navilog1
                  2008-07-21 16:15 . 2008-07-21 16:15 268 --ah----- C:\sqmdata01.sqm
                  2008-07-21 16:15 . 2008-07-21 16:15 244 --ah----- C:\sqmnoopt01.sqm
                  2008-07-20 18:57 . 2008-07-20 21:19 38 --a------ C:\WINDOWS\avisplitter.INI
                  2008-07-18 21:53 . 2008-07-18 21:53 <REP> d-------- C:\Documents and Settings\utilisateur\Application Data\CyberLink
                  2008-07-12 16:10 . 2008-07-12 16:11 <REP> d-------- C:\Program Files\Google
                  2008-07-07 02:19 . 2008-04-23 06:16 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
                  2008-07-07 02:19 . 2007-04-17 11:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
                  2008-07-07 02:19 . 2007-03-08 07:10 1,048,576 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
                  2008-07-07 02:19 . 2008-04-23 06:16 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
                  2008-07-07 02:19 . 2008-04-23 06:16 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
                  2008-07-07 02:19 . 2008-04-23 06:16 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
                  2008-07-07 02:19 . 2008-04-23 06:16 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
                  2008-07-07 02:19 . 2008-04-23 06:16 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
                  2008-07-07 02:19 . 2008-04-22 09:39 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
                  2008-07-06 22:14 . 2008-07-06 22:14 <REP> d-------- C:\Program Files\SAGEM
                  2008-07-06 22:13 . 2008-07-06 22:13 <REP> d-------- C:\Program Files\Securitoo
                  2008-07-06 21:25 . 2008-07-06 21:29 <REP> d-------- C:\Program Files\Orange
                  2008-07-06 21:25 . 2008-07-06 21:25 <REP> d-------- C:\Program Files\Fichiers communs\France Telecom
                  2008-07-06 21:25 . 2003-03-19 06:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
                  2008-07-06 21:25 . 2006-03-01 19:53 94,208 --a------ C:\WINDOWS\system32\w32n50.dll
                  2008-07-06 21:25 . 2003-03-19 04:05 89,088 --a------ C:\WINDOWS\system32\atl71.dll
                  2008-07-06 21:25 . 2007-09-25 19:31 65,536 --a------ C:\WINDOWS\system32\Autodial2000.dll
                  2008-07-06 21:25 . 2003-09-23 11:38 34,688 --a------ C:\WINDOWS\system32\pcampr5.sys
                  2008-07-06 21:25 . 2006-03-01 19:53 32,128 --a------ C:\WINDOWS\system32\pcandis5.sys

                  .
                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2008-07-21 18:06 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\Azureus
                  2008-07-19 19:14 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\OpenOffice.org2
                  2008-07-08 02:07 --------- d-----w C:\Program Files\Fichiers communs\Adobe
                  2008-07-06 22:02 --------- d-----w C:\Program Files\Azureus
                  2008-07-06 20:14 --------- d--h--w C:\Program Files\InstallShield Installation Information
                  2008-06-25 16:19 --------- d-----w C:\Program Files\Analog Devices
                  2008-06-25 16:14 4,816 ----a-w C:\WINDOWS\system32\drivers\aeaudio.sys
                  2008-06-25 16:14 3,744 ----a-w C:\WINDOWS\system32\drivers\smsens.sys
                  2008-06-25 15:18 --------- d-----w C:\Program Files\Lavalys
                  2008-06-25 14:12 512,000 ----a-w C:\WINDOWS\system32\winlogon.exe
                  2008-06-21 10:46 --------- d-----w C:\Program Files\MSN Messenger
                  2008-06-20 17:47 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
                  2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
                  2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
                  2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
                  2008-06-17 18:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\ma-config.com
                  2008-06-15 16:01 --------- d-----w C:\Program Files\Realtek AC97
                  2008-06-15 16:01 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
                  2008-06-15 15:53 --------- d-----w C:\Program Files\ma-config.com
                  2008-06-14 23:13 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\Media Player Classic
                  2008-06-14 17:33 272,768 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
                  2008-06-13 21:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
                  2008-06-13 20:46 --------- d-----w C:\Program Files\Alice
                  2008-06-13 20:24 --------- d-----w C:\Program Files\Vimicro
                  2008-06-13 20:23 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\InstallShield
                  2008-06-12 11:03 --------- d-----w C:\Program Files\Avira
                  2008-06-12 11:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
                  2008-05-09 10:55 90,112 ----a-w C:\WINDOWS\system32\wshext.dll
                  2008-05-09 10:55 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll
                  2008-05-09 10:55 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll
                  2008-05-09 10:55 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll
                  2008-05-08 11:24 155,648 ----a-w C:\WINDOWS\system32\wscript.exe
                  2008-05-07 09:07 135,168 ----a-w C:\WINDOWS\system32\cscript.exe
                  2008-05-07 05:11 1,294,336 ----a-w C:\WINDOWS\system32\quartz.dll
                  .

                  ------- Sigcheck -------

                  2008-06-25 16:12 512000 8d71f28deb37cc9c2e344095d8bfe1ee C:\WINDOWS\system32\winlogon.exe
                  .
                  ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  REGEDIT4
                  *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:34 15360]
                  "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]
                  "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
                  "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-07-12 16:11 171448]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-10-18 17:58 1185264]
                  "AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-10-18 18:02 1961576]
                  "Acronis Scheduler2 Service"="C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe" [2006-10-17 11:47 87584]
                  "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-18 21:23 266497]
                  "ZSSnp211"="C:\WINDOWS\ZSSnp211.exe" [2007-04-06 11:06 57344]
                  "Domino"="C:\WINDOWS\Domino.exe" [2006-08-18 16:58 49152]
                  "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-21 16:48 155648]
                  "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-21 16:44 126976]
                  "SystrayORAHSS"="C:\Program Files\Orange\Systray\SystrayApp.exe" [2007-09-25 20:08 94208]
                  "ORAHSSSessionManager"="C:\Program Files\Orange\SessionManager\SessionManager.exe" [2007-09-25 19:10 102400]
                  "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
                  "SoundMan"="soundman.exe" [2002-03-21 11:23 46592 C:\WINDOWS\soundman.exe]

                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                  "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-13 19:34 15360]

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                  "VIDC.YV12"= yv12vfw.dll

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                  Authentication Packages REG_MULTI_SZ msv1_0 relog_ap

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
                  --a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
                  --a------ 2007-06-01 10:21 153136 C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
                  --a------ 2006-12-05 22:55 54832 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
                  --a------ 2007-03-01 15:57 153136 C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
                  --------- 2006-11-23 15:10 56928 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
                  "RichVideo"=2 (0x2)
                  "NMIndexingService"=3 (0x3)

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                  "AntiVirusDisableNotify"=dword:00000001

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                  "EnableFirewall"= 0 (0x0)

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                  "%windir%\\system32\\sessmgr.exe"=
                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                  "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
                  "C:\\Program Files\\MSN Messenger\\livecall.exe"=
                  "C:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"=

                  S3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys [2004-08-19 17:53]
                  S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-06-14 10:13]
                  .
                  - - - - ORPHANS REMOVED - - - -

                  HKCU-Run-s9201 - C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\wspwprtc.exe

                  .
                  ------- Supplementary Scan -------
                  .
                  R0 -: HKCU-Main,Start Page = about:blank

                  O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_0_1_0.cab
                  C:\WINDOWS\Downloaded Program Files\hardwaredetection.inf

                  **************************************************************************

                  catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2008-07-28 19:06:28
                  Windows 5.1.2600 Service Pack 3 NTFS

                  Balayage processus cach‚s ...

                  Balayage cach‚ autostart entries ...

                  Balayage des fichiers cach‚s ...

                  Scan termin‚ avec succŠs
                  Les fichiers cach‚s: 0

                  **************************************************************************
                  .
                  ------------------------ Other Running Processes ------------------------
                  .
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\[u]0[/u]\FTRTSVC.exe
                  C:\Program Files\Orange\Launcher\Launcher.exe
                  C:\Program Files\Fichiers communs\France Telecom\Shared Modules\AlertModule\[u]0[/u]\AlertModule.exe
                  C:\Program Files\Orange\Deskboard\Deskboard.exe
                  C:\Program Files\Orange\Connectivity\ConnectivityManager.exe
                  C:\Program Files\Orange\Connectivity\corecom\CoreCom.exe
                  C:\Program Files\Orange\Connectivity\corecom\OraConfigRecover.exe
                  C:\Program Files\Fichiers communs\France Telecom\Shared Modules\FTCOMModule\[u]0[/u]\FTCOMModule.exe
                  C:\WINDOWS\system32\wscntfy.exe
                  .
                  **************************************************************************
                  .
                  Temps d'accomplissement: 2008-07-28 19:10:31 - machine was rebooted
                  ComboFix-quarantined-files.txt 2008-07-28 17:10:23

                  Pre-Run: 26,873,208,832 octets libres
                  Post-Run: 26,926,542,848 octets libres

                  183 --- E O F --- 2008-07-09 14:15:07
                  0
                  1. Contributeur
                    ok

                    on dirait que ce n´est plus qu´un mauvais souvenir ;)

                    post un nouveau rapport hijack this stp

                    @+
                    0
                    1. yes yes yes merciiiiiiiiiiiiiiiiiiiiiiiiiii!

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 19:28:44, on 28/07/2008
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
                      C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe
                      C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                      C:\WINDOWS\ZSSnp211.exe
                      C:\WINDOWS\Domino.exe
                      C:\WINDOWS\soundman.exe
                      C:\WINDOWS\system32\igfxtray.exe
                      C:\WINDOWS\system32\hkcmd.exe
                      C:\Program Files\Orange\Systray\SystrayApp.exe
                      C:\Program Files\Orange\Launcher\Launcher.exe
                      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\MSN Messenger\msnmsgr.exe
                      C:\Program Files\Messenger\msmsgs.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                      C:\Program Files\Orange\connectivity\connectivitymanager.exe
                      C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
                      C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
                      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\wscntfy.exe
                      C:\WINDOWS\explorer.exe
                      C:\Program Files\MSN Messenger\usnsvc.exe
                      C:\Program Files\Internet Explorer\IEXPLORE.EXE
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                      O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
                      O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
                      O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe"
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                      O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
                      O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe
                      O4 - HKLM\..\Run: [SoundMan] soundman.exe
                      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                      O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
                      O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O15 - Trusted Zone: https://www.orange.fr/portail
                      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                      O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
                      O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                      0
                      1. Contributeur
                        ;-)

                        a l´aide de hijack this coche et fix les lignes ci dessous :

                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                        O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/...
                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/s­wflash.cab

                        puis pour de securité et pour eviter ce genre de probleme notament :

                        tu veux un par feu :

                        Comodo 3 pro :

                        http://www.commentcamarche.net/telecharger/telecharger 34055041 comodo firewall pro

                        tuto : https://www.malekal.com/tutorial-comodo-firewall/

                        ou

                        Online armor :

                        http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall

                        tuto : https://www.malekal.com/tutorial-online-armor-free/

                        ps : avant installation de online armor ou comodo desactive le hips de spybot :

                        Désactive le Tea-Timer de Spybot en passant par les options de Spybot: une fois dans le logiciel, il faut aller dans le menu "Mode" => coche "Mode avancé" => "Outils"(en bas de page)=> "Résident" => et tu décoches cette case: "Résident Teatimer" . Tu ne dois plus voir l'icône du Tea- Timer dans la barre de tâches!

                        apres installl regarde que le par feu windows est bien desactivé :)
                        puis :

                        anti spyware :

                        spywareblaster :

                        http://www.brightfort.com/spywareblaster.html

                        c´est un resident, il suffit de le mettre a jour de temps en temps car la version gratuite ne le fait pas toute seul , une fois installé et mis a jour tu mets toutes les protections sur "enable"

                        tuto : https://www.malekal.com/tutorial-spywareblaster/

                        pourquoi ne pas surfer avec firefox? = plus sur, tout en gardant ie 7.0 pour les mises a jour windows car impossible a effectuer sous firefox

                        http://www.mozilla-europe.org/fr/

                        plugins : ad block plus, no script ect...

                        https://www.hugedomains.com/domain_profile.cfm?d=geckozone&e=org

                        puis pour supprimer l´espion de france telecomme :

                        demarrer / executer tape sc stop FTRTSVC puis valide par ok

                        demarrer/ executer tape sc delete FTRTSVC puis valide par ok"

                        pour supprimer les outils utilisés :

                        Télécharge ToolsCleaner sur ton bureau.
                        --> http://www.commentcamarche.net/telecharger/telechargement 34055291 toolsclean(...)
                        # Clique sur Recherche et laisse le scan agir ...
                        # Clique sur Suppression pour finaliser.
                        # Tu peux, si tu le souhaites, te servir des Options facultatives.
                        # Clique sur Quitter pour obtenir le rapport.
                        # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
                        ps : pas la peine de me poster le rapport si tu voie que tout a ete supprimé...
                        supprime aussi navi.bat

                        voila`

                        bye`
                        0