Page d'accueil qui se bloque

Résolu
Bonjour,
Dès que je démarre internet explorer la page se bloque a moitié téléchargement et impossible de cliquer sur quoi que ce soit aucune toolbar ne fonctionne bref un bon plantage. Si je redémarre le pc internet refonctionnera correctement. Ce phénomène se produit régulièrement et c'est vraiment tres ch...
J'ai scanné mon pc avec spybot et avast et rien a signaler.
Voila aidez moi svp je sais vraiment pas quoi faire
N.B: je suis pas calé en informatique
merci d'avance
Configuration: Windows Vista
Internet Explorer 7.0

30 réponses

Résumé de la discussion

Problème sur Windows Vista avec Internet Explorer 7: les pages se chargent à moitié et le navigateur devient inactif jusqu’au redémarrage, puis Internet refonctionne brièvement et l’utilisateur n’est pas expert. Des analyses Spybot et Avast n’ont rien révélé, tandis que des réponses préconisent des nettoyages via des outils anti-malware et des rapports pour identifier barres d’outils et HijackThis. Plusieurs propositions recommandent des outils comme HijackThis, Malwarebytes et ComboFix, puis la suppression de logiciels indésirables, extensions et éléments suspectés dans le registre, afin d’éliminer les redirections et les pop-ups. Parallèlement, le fil signale des adwares variés et des démarrages à vérifier, et précise qu’un nettoyage approfondi peut nécessiter plusieurs rapports et redémarrages.

Bobot (l’IA à votre service)
  1. salut,

    Télécharge MalwareByte's Anti-Malware sur ton Bureau.
    Installe-le en double-cliquant sur le fichier Download_mbam-setup.exe.

    Une fois l'installation et la mise à jour effectuées, redémarre en mode sans échec.
    AIDE : Redémarrer en mode sans échec
    http://www.infos-du-net.com/forum/272325-11-tuto-demarrer-mode-echec

    * Exécute maintenant MalwareByte's Anti-Malware. Si cela n'est pas déjà fait, sélectionne "Exécuter un examen complet".
    * Afin de lancer la recherche, clic sur"Rechercher".
    * Une fois le scan terminé, une fenêtre s'ouvre, clic sur OK. Deux possibilités s'offrent à toi :

    -- si le programme n'a rien trouvé, appuie sur OK. Un rapport va apparaître, ferme-le.
    -- si des infections sont présentes, clic sur "Afficher les résultats" puis sur "Supprimer la sélection". Enregistre le rapport sur ton Bureau afin de le poster dans ta prochaine réponse.
    REMARQUE : Si MalwareByte's Anti-Malware a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok.
    0
    1. merci pour ton aide mais je peux pas faire ca maintenant je le ferais demain
      mais merci beaucoup de ta réponse
      0
      1. re,

        pas de soucis.

        on prendra notre temps.
        0
        1. salut
          voila le résultat

          Malwarebytes' Anti-Malware 1.24
          Version de la base de données: 1018
          Windows 6.0.6000

          16:50:56 03/08/2008
          mbam-log-8-3-2008 (16-50-43).txt

          Type de recherche: Examen complet (C:\|D:\|)
          Eléments examinés: 201549
          Temps écoulé: 43 minute(s), 25 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 11
          Valeur(s) du Registre infectée(s): 1
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 10
          Fichier(s) infecté(s): 31

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5f90c0e3-4c0a-4d54-a8ac-5afe6163a99e} (Adware.Starware) -> No action taken.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{1a93c934-025b-4c3a-b38e-9654a7003239} (Adware.Gamesbar) -> No action taken.
          HKEY_CLASSES_ROOT\oberontb.band (Adware.Gamesbar) -> No action taken.
          HKEY_CLASSES_ROOT\TypeLib\{ad76633e-e50d-4844-9e7f-4dfbc7c18467} (Adware.Gamesbar) -> No action taken.
          HKEY_CLASSES_ROOT\Interface\{ec1a2105-5621-440f-987d-27ef428131d9} (Adware.Gamesbar) -> No action taken.
          HKEY_CLASSES_ROOT\CLSID\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> No action taken.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> No action taken.
          HKEY_CLASSES_ROOT\oberontb.band.1 (Adware.Gamesbar) -> No action taken.
          HKEY_LOCAL_MACHINE\SOFTWARE\ParisHilton (Adware.NaviPromo) -> No action taken.
          HKEY_CURRENT_USER\SOFTWARE\ParisHilton (Adware.NaviPromo) -> No action taken.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WebMediaPlayer.exe (Adware.EGDAccess) -> No action taken.

          Valeur(s) du Registre infectée(s):
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> No action taken.

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          C:\Program Files\Starware370 (Adware.Starware) -> No action taken.
          C:\Program Files\Starware370\bin (Adware.Starware) -> No action taken.
          C:\Program Files\Starware370\icons (Adware.Starware) -> No action taken.
          C:\Program Files\WebMediaPlayer (Adware.EGDAccess) -> No action taken.
          C:\Program Files\WebMediaPlayer\resources (Adware.EGDAccess) -> No action taken.
          C:\Program Files\WebMediaPlayer\skins (Adware.EGDAccess) -> No action taken.
          C:\Program Files\WebMediaPlayer\updates (Adware.EGDAccess) -> No action taken.
          C:\ProgramData\Starware370 (Adware.Starware) -> No action taken.
          C:\ProgramData\Starware370\buttons (Adware.Starware) -> No action taken.
          C:\ProgramData\Starware370\contexts (Adware.Starware) -> No action taken.

          Fichier(s) infecté(s):
          C:\Users\romain\Local Settings\Application Data\nupsgw_navps.dat (Adware.Navipromo) -> No action taken.
          C:\Users\romain\Local Settings\Application Data\nupsgw_nav.dat (Adware.Navipromo) -> No action taken.
          C:\Users\romain\Local Settings\Application Data\nupsgw.dat (Adware.Navipromo) -> No action taken.
          C:\Program Files\GamesBar\oberontb.dll (Adware.Gamesbar) -> No action taken.
          C:\Program Files\Starware370\brand.bmp (Adware.Starware) -> No action taken.
          C:\Program Files\Starware370\Starware370Config.xml (Adware.Starware) -> No action taken.
          C:\Program Files\Starware370\Starware370Uninstall.exe (Adware.Starware) -> No action taken.
          C:\Program Files\Starware370\icons\star_16.ico (Adware.Starware) -> No action taken.
          C:\Program Files\WebMediaPlayer\Conditions générales.url (Adware.EGDAccess) -> No action taken.
          C:\Program Files\WebMediaPlayer\Confidentialité.url (Adware.EGDAccess) -> No action taken.
          C:\Program Files\WebMediaPlayer\sqlite3.dll (Adware.EGDAccess) -> No action taken.
          C:\Program Files\WebMediaPlayer\WebMediaPlayer.exe (Adware.EGDAccess) -> No action taken.
          C:\Program Files\WebMediaPlayer\Website.url (Adware.EGDAccess) -> No action taken.
          C:\Program Files\WebMediaPlayer\resources\languages_v2.xml (Adware.EGDAccess) -> No action taken.
          C:\Program Files\WebMediaPlayer\resources\webmedias (Adware.EGDAccess) -> No action taken.
          C:\Program Files\WebMediaPlayer\skins\classic.skn (Adware.EGDAccess) -> No action taken.
          C:\ProgramData\Starware370\buttons\563_button_1b_def.bmp (Adware.Starware) -> No action taken.
          C:\ProgramData\Starware370\buttons\563_button_1b_over.bmp (Adware.Starware) -> No action taken.
          C:\ProgramData\Starware370\buttons\572_button_1b_def.bmp (Adware.Starware) -> No action taken.
          C:\ProgramData\Starware370\buttons\572_button_1b_over.bmp (Adware.Starware) -> No action taken.
          C:\ProgramData\Starware370\buttons\573_button_1b_def.bmp (Adware.Starware) -> No action taken.
          C:\ProgramData\Starware370\buttons\573_button_1b_over.bmp (Adware.Starware) -> No action taken.
          C:\ProgramData\Starware370\buttons\FindIt.bmp (Adware.Starware) -> No action taken.
          C:\ProgramData\Starware370\buttons\FindItHot.bmp (Adware.Starware) -> No action taken.
          C:\ProgramData\Starware370\buttons\findithotxp.png (Adware.Starware) -> No action taken.
          C:\ProgramData\Starware370\buttons\finditxp.png (Adware.Starware) -> No action taken.
          C:\ProgramData\Starware370\buttons\logo.bmp (Adware.Starware) -> No action taken.
          C:\ProgramData\Starware370\buttons\logoxp.bmp (Adware.Starware) -> No action taken.
          C:\ProgramData\Starware370\contexts\error.xml (Adware.Starware) -> No action taken.
          C:\ProgramData\Starware370\contexts\related.xml (Adware.Starware) -> No action taken.
          C:\ProgramData\Starware370\contexts\travel.xml (Adware.Starware) -> No action taken.
          0
          1. salut,

            il me faut le deuxième rapport.

            si des infections sont présentes, clic sur "Afficher les résultats" puis sur "Supprimer la sélection". Enregistre le rapport sur ton Bureau afin de le poster dans ta prochaine réponse.

            c'est pour me rassurer pour voir si ils sont vraiment éliminé de ton PC.
            0
            1. bah je n'ai que ce rapport la
              j'ai du louper une étape...
              0
              1. il faut que tu ouvre malwarebyte's anti malware que tu ailles dans quarantaine et que tu supprime le tout .
                ensuite il va te faire un rapport tu me l'envoi.
                0
                1. voila si je me suis pas trompé c'est ca

                  Malwarebytes' Anti-Malware 1.24
                  Version de la base de données: 1018
                  Windows 6.0.6000

                  16:51:02 03/08/2008
                  mbam-log-8-3-2008 (16-51-02).txt

                  Type de recherche: Examen complet (C:\|D:\|)
                  Eléments examinés: 201549
                  Temps écoulé: 43 minute(s), 25 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 11
                  Valeur(s) du Registre infectée(s): 1
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 10
                  Fichier(s) infecté(s): 31

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5f90c0e3-4c0a-4d54-a8ac-5afe6163a99e} (Adware.Starware) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{1a93c934-025b-4c3a-b38e-9654a7003239} (Adware.Gamesbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\oberontb.band (Adware.Gamesbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\TypeLib\{ad76633e-e50d-4844-9e7f-4dfbc7c18467} (Adware.Gamesbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{ec1a2105-5621-440f-987d-27ef428131d9} (Adware.Gamesbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\oberontb.band.1 (Adware.Gamesbar) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\ParisHilton (Adware.NaviPromo) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\ParisHilton (Adware.NaviPromo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WebMediaPlayer.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.

                  Valeur(s) du Registre infectée(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  C:\Program Files\Starware370 (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\Program Files\Starware370\bin (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\Program Files\Starware370\icons (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\Program Files\WebMediaPlayer (Adware.EGDAccess) -> Quarantined and deleted successfully.
                  C:\Program Files\WebMediaPlayer\resources (Adware.EGDAccess) -> Quarantined and deleted successfully.
                  C:\Program Files\WebMediaPlayer\skins (Adware.EGDAccess) -> Quarantined and deleted successfully.
                  C:\Program Files\WebMediaPlayer\updates (Adware.EGDAccess) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370 (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370\buttons (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370\contexts (Adware.Starware) -> Quarantined and deleted successfully.

                  Fichier(s) infecté(s):
                  C:\Users\romain\Local Settings\Application Data\nupsgw_navps.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
                  C:\Users\romain\Local Settings\Application Data\nupsgw_nav.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
                  C:\Users\romain\Local Settings\Application Data\nupsgw.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
                  C:\Program Files\GamesBar\oberontb.dll (Adware.Gamesbar) -> Quarantined and deleted successfully.
                  C:\Program Files\Starware370\brand.bmp (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\Program Files\Starware370\Starware370Config.xml (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\Program Files\Starware370\Starware370Uninstall.exe (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\Program Files\Starware370\icons\star_16.ico (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\Program Files\WebMediaPlayer\Conditions générales.url (Adware.EGDAccess) -> Quarantined and deleted successfully.
                  C:\Program Files\WebMediaPlayer\Confidentialité.url (Adware.EGDAccess) -> Quarantined and deleted successfully.
                  C:\Program Files\WebMediaPlayer\sqlite3.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
                  C:\Program Files\WebMediaPlayer\WebMediaPlayer.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
                  C:\Program Files\WebMediaPlayer\Website.url (Adware.EGDAccess) -> Quarantined and deleted successfully.
                  C:\Program Files\WebMediaPlayer\resources\languages_v2.xml (Adware.EGDAccess) -> Quarantined and deleted successfully.
                  C:\Program Files\WebMediaPlayer\resources\webmedias (Adware.EGDAccess) -> Quarantined and deleted successfully.
                  C:\Program Files\WebMediaPlayer\skins\classic.skn (Adware.EGDAccess) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370\buttons\563_button_1b_def.bmp (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370\buttons\563_button_1b_over.bmp (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370\buttons\572_button_1b_def.bmp (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370\buttons\572_button_1b_over.bmp (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370\buttons\573_button_1b_def.bmp (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370\buttons\573_button_1b_over.bmp (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370\buttons\FindIt.bmp (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370\buttons\FindItHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370\buttons\findithotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370\buttons\finditxp.png (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370\buttons\logo.bmp (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370\buttons\logoxp.bmp (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370\contexts\error.xml (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370\contexts\related.xml (Adware.Starware) -> Quarantined and deleted successfully.
                  C:\ProgramData\Starware370\contexts\travel.xml (Adware.Starware) -> Quarantined and deleted successfully.
                  0
                  1. maintenant ,

                    télécharge Hijackthis sur ton bureau.

                    * Double clique sur HJTInstall.exe pour lancer l'installation.
                    * Clique sur Install.
                    * Double clique sur le raccourci d'HijackThis qui vient d'être créé pour le lancer. (Clique droit -> lancer en tant qu'admin si sous Vista)
                    * Accepte la licence en cliquant sur Yes.
                    * Clique sur "Do a system scan and save a logfile".
                    * Poste ici[ le rapport généré.

                    Note : Le rapport se trouve également ici : C:\Program Files\Trend Micro\Hijackthis\Hijackthis.log
                    0
                    1. ok merci beaucoup pour ta réponse je ferai ca demain car la je men vais
                      je le posterai demain soir
                      encore merci tu me sauve
                      0
                      1. salut. voila le rapport

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 12:25:45, on 04/08/2008
                        Platform: Windows Vista (WinNT 6.00.1904)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                        Boot mode: Normal

                        Running processes:
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\Explorer.EXE
                        C:\Windows\system32\taskeng.exe
                        C:\Program Files\Hercules\DualPix Exchange\CamService.exe
                        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                        C:\Windows\RtHDVCpl.exe
                        C:\Program Files\QuickTime\qttask.exe
                        C:\Program Files\CyberLink\PowerCinema\PCMService.exe
                        C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                        C:\hp\support\hpsysdrv.exe
                        C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
                        C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                        C:\Windows\vsnp2uvc.exe
                        C:\Windows\System32\hkcmd.exe
                        C:\Windows\System32\igfxpers.exe
                        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                        C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Windows\system32\igfxsrvc.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
                        C:\Windows\system32\wbem\unsecapp.exe
                        C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
                        C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
                        C:\Program Files\Internet Explorer\ieuser.exe
                        C:\Windows\system32\conime.exe
                        C:\Windows\system32\wuauclt.exe
                        C:\Windows\system32\SearchFilterHost.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer optimisé pour MSN
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        O1 - Hosts: ::1 localhost
                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Zango - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Zango\bin\10.3.36.0\HostIE.dll (file missing)
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O3 - Toolbar: Zango - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Zango\bin\10.3.36.0\HostIE.dll (file missing)
                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
                        O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                        O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
                        O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                        O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
                        O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                        O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                        O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
                        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                        O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        O4 - HKCU\..\RunOnce: [SpybotDeletingB208] command /c del "C:\Program Files\Everest Poker\casino.exe"
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
                        O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
                        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
                        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                        O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                        O9 - Extra button: Groom - {66F83792-DAE1-4823-8F20-ADA94B33A4FF} - C:\Program Files\Toox\Groom\Groom.exe (HKCU)
                        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                        O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                        O13 - Gopher Prefix:
                        O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqemea/downloads/sysinfo.cab
                        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-fr.cab
                        O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                        O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://gamenextfr.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
                        O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
                        O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
                        O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                        O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                        O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                        O23 - Service: EBP - Pervasive.SQL Workgroup (Pervasive.SQL Workgroup) - Unknown owner - C:\PVSW\Bin\WGE_SRV.EXE
                        O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                        O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                        O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                        O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
                        O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                        0
                        1. salut,

                          1) Affiche les fichiers et dossiers cachés …
                          Pour ce faire, tu vas dans un dossier, par ex. "Mes Images".
                          Ensuite, clique sur > Outils > Options des dossiers ...
                          clique sur l' onglet « Affichage » et ...
                          coche ---> Afficher les fichiers et dossiers cachés
                          décoche > Masquer les extensions des fichiers dont le type est connu
                          décoche > Masquer les fichiers protégés du système d' exploitation (recommandé).
                          « Appliquer » et « OK ».

                          2) Désactive toute protection résidente ( antivirus…) !

                          Déconnecte-toi d’internet, ferme tous les programmes en cours et laisse combofix travailler : ne fais donc pas autre chose en même temps !

                          Télécharge Combofix de sUBs :
                          http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                          Sauvegarde le sur ton bureau et pas ailleurs !
                          Redémarre en mode sans échecs : aide ici >>> http://forum.telecharger.01net.com/forum/high-tech/SECURITE/Securite/redemarrer-mode-echec-sujet_1526_1.htm
                          http://forum.telecharger.01net.com/forum/ [...] ges-1.html
                          /!\ Ne jamais redémarrer en mode sans échec via msconfig ! /!\

                          Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider, laisse toi guider.
                          Attends que combofix ait terminé, un rapport sera créé. Poste le rapport. Il se trouve ici : C:\Combofix.txt

                          3) Copie/colle un nouveau rapport HiJackThis avec.
                          0
                          1. Salut
                            Je trove pas ce que tu me dis de faire: outils et option des dossiers.
                            A moins que je sois totalement aveugle ca n'y est pas. désolé
                            donc comment je peux faire?
                            merci
                            0
                            1. salut
                              voila le rapport combofix
                              par contre spybot s'est manifesté durant le travail de combofix. j'ai autorisé 2 modif de registre sinon ca continuait pas. je sais pas si c'est grave

                              ComboFix 08-08-09.06 - romain 2008-08-10 17:32:48.1 - NTFSx86 MINIMAL
                              Microsoft® Windows Vista™ Édition Familiale Basique 6.0.6000.0.1252.1.1036.18.669 [GMT 2:00]
                              Endroit: C:\Users\romain\Desktop\ComboFix.exe
                              .

                              (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                              .

                              C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer
                              C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\Conditions générales.lnk
                              C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\Confidentialité.lnk
                              C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\Website.lnk
                              C:\PROGRA~2\Microsoft\Network\Downloader\qmgr0.dat
                              C:\PROGRA~2\Microsoft\Network\Downloader\qmgr1.dat
                              C:\Users\romain\AppData\Local\nupsgw_navup.dat
                              C:\Users\romain\AppData\Roaming\macromedia\Flash Player\#SharedObjects\87CK88LX\interclick.com
                              C:\Users\romain\AppData\Roaming\macromedia\Flash Player\#SharedObjects\87CK88LX\interclick.com\ud.sol
                              C:\Users\romain\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
                              C:\Users\romain\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
                              C:\Windows\system32\cfx32.ocx
                              C:\Windows\system32\x64

                              ----- BITS: Possible sites infectés -----

                              http://images.metaservices.microsoft.com:80
                              .
                              ((((((((((((((((((((((((((((( Fichiers créés 2008-07-10 to 2008-08-10 ))))))))))))))))))))))))))))))))))))
                              .

                              Pas de nouveau fichier créé dans cet espace de temps

                              .
                              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              2008-08-10 15:27 --------- d-----w C:\Users\romain\AppData\Roaming\OpenOffice.org2
                              2008-08-10 15:15 --------- d-----w C:\Program Files\SolidWorks
                              2008-08-10 15:15 --------- d-----w C:\Program Files\Common Files\SolidWorks Shared
                              2008-08-10 09:51 2,621,440 --sha-w C:\Users\clément\NTUSER.DAT
                              2008-08-10 09:51 2,621,440 --sha-w C:\Users\clément\NTUSER.DAT
                              2008-08-07 11:06 584 ----a-w C:\Users\romain\AppData\Roaming\wklnhst.dat
                              2008-08-05 19:00 --------- d-----w C:\Users\romain\AppData\Roaming\LimeWire
                              2008-08-04 17:35 --------- d-----w C:\Program Files\adslTV
                              2008-08-04 10:25 --------- d-----w C:\Program Files\Trend Micro
                              2008-08-03 14:51 --------- d-----w C:\Program Files\GamesBar
                              2008-08-03 13:55 --------- d-----w C:\Users\romain\AppData\Roaming\Malwarebytes
                              2008-08-03 13:55 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
                              2008-08-03 13:55 --------- d-----w C:\PROGRA~2\Malwarebytes
                              2008-07-30 18:07 38,472 ----a-w C:\Windows\system32\drivers\mbamswissarmy.sys
                              2008-07-30 18:07 17,144 ----a-w C:\Windows\system32\drivers\mbam.sys
                              2008-07-30 07:40 --------- d-----w C:\PROGRA~2\GamesBar
                              2008-07-20 18:06 --------- d-----w C:\Users\romain\AppData\Roaming\Image Zone Express
                              2008-07-20 17:52 --------- d-----w C:\Users\romain\AppData\Roaming\Printer Info Cache
                              2008-07-19 14:36 51,280 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
                              2008-07-19 13:56 --------- d-----w C:\Program Files\Java
                              2008-07-18 18:39 587,264 ----a-w C:\Windows\WLXPGSS.SCR
                              2008-07-14 20:17 --------- d-----w C:\Program Files\Gamenext
                              2008-07-13 08:40 --------- d---a-w C:\PROGRA~2\TEMP
                              2008-07-11 08:05 --------- d-----w C:\PROGRA~2\Sandlot Games
                              2008-07-11 08:04 --------- d-----w C:\Program Files\Common Files\Oberon Media
                              2008-07-10 19:28 --------- d-----w C:\Users\romain\AppData\Roaming\GARMIN
                              2008-07-10 19:24 --------- d-----w C:\Program Files\Garmin GPS Plugin
                              2008-07-10 09:54 174 --sha-w C:\Program Files\desktop.ini
                              2008-07-10 09:46 --------- d-----w C:\Program Files\Windows Mail
                              2008-06-28 20:00 --------- d-----w C:\PROGRA~2\BOONTY
                              2008-06-28 19:59 --------- d-----w C:\Program Files\Common Files\BOONTY Shared
                              2008-06-28 19:59 --------- d-----w C:\Program Files\BoontyGames
                              2008-06-27 22:11 --------- d-----w C:\Users\romain\AppData\Roaming\U3
                              2008-06-26 00:34 7,964,672 ----a-w C:\Windows\System32\NlsLexicons0024.dll
                              2008-06-26 00:33 9,892,864 ----a-w C:\Windows\System32\NlsLexicons000a.dll
                              2008-06-21 08:46 --------- d-----w C:\Program Files\Common Files\Symantec Shared
                              2008-05-10 03:30 14,848 ----a-w C:\Windows\System32\wshrm.dll
                              2006-08-31 23:21 12,667,974 ----a-w C:\Users\Public\virtualdj.exe
                              .

                              ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              .
                              REGEDIT4
                              *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 00:54 1232896]
                              "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 12:34 5724184]
                              "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 18:15 221184]
                              "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

                              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                              "SpybotDeletingB208"="command" [X]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
                              "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-25 17:58 98304]
                              "PCMService"="C:\Program Files\CyberLink\PowerCinema\PCMService.exe" [2006-11-28 15:09 151552]
                              "OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2006-11-20 13:34 155648]
                              "hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 15:42 65536]
                              "HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-12-10 21:52 49152]
                              "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22 517768]
                              "snp2uvc"="C:\Windows\vsnp2uvc.exe" [2007-03-12 18:49 569344]
                              "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-01-02 18:07 141848]
                              "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-01-02 18:06 166424]
                              "Persistence"="C:\Windows\system32\igfxpers.exe" [2008-01-02 18:07 133656]
                              "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-03-08 07:13 185896]
                              "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 16:38 78008]
                              "DPService"="C:\Program Files\HP\DVDPlay\DPService.exe" [2007-12-18 14:18 90112]
                              "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09 63712]
                              "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
                              "RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 12:26 4874240 C:\Windows\RtHDVCpl.exe]

                              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                              "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]

                              C:\Users\romain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                              OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 22:57:56 393216]

                              C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
                              HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-01-02 21:40:10 210520]

                              C:\Users\romain\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\
                              OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 22:57:56 393216]

                              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
                              "LogonHoursAction"= 2 (0x2)
                              "DontDisplayLogonHoursWarnings"= 1 (0x1)

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                              "DisableMonitoring"=dword:00000001

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                              "DisableMonitoring"=dword:00000001

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                              "DisableMonitoring"=dword:00000001

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
                              "AntiVirusOverride"=dword:00000001

                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
                              "{D90DA199-FB16-47D5-B13E-FB5CFCBE9268}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
                              "{F4A509D2-677B-4B92-8B80-897EB56A3F7D}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
                              "{B3336506-8AED-4D66-8E48-34FFCDCF1A60}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
                              "{214350CB-48AB-4400-8E3A-F6E740C01411}"= UDP:C:\PVSW\Bin\w3dbsmgr.exe:Database Service Manager
                              "{88935AF2-BB17-4F68-91B9-462BC1D4A79F}"= TCP:C:\PVSW\Bin\w3dbsmgr.exe:Database Service Manager
                              "{410A5D6D-3ECB-45FE-B21D-9D11DBAF85C4}"= UDP:C:\PVSW\Bin\w3dbsmgr.exe:Database Service Manager
                              "{E15DE59C-8DA8-46CB-A90E-B41CF97D1739}"= TCP:C:\PVSW\Bin\w3dbsmgr.exe:Database Service Manager
                              "{2797916F-537F-4718-8275-0C8213FB65F6}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
                              "{5D933DA3-6E57-415F-91DD-CA11E74E3324}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
                              "{E510068A-D726-41EC-BB56-FFD36B3D13A2}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
                              "{569AE117-F626-4DED-8E06-7E5CCA880A33}"= C:\Program Files\HP\DVDPlay\DVDPlay.exe:DVD Play
                              "{F84A4D84-0BF8-468C-8CE9-FCF258A52B76}"= C:\Program Files\HP\DVDPlay\DPService.exe:DVD Play Resident Program
                              "{607BEBC5-4EB5-4E05-B0E7-AEF37C03A552}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
                              "{55438D6A-641D-468D-AC37-4884C871A659}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
                              "TCP Query User{CC9F6F02-D9E5-431C-A3D4-BDAF96898D46}C:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:C:\program files\sopcast\adv\sopadver.exe:SopCast Adver
                              "UDP Query User{9B6E5459-B62B-4C4B-BD41-2C8757822809}C:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:C:\program files\sopcast\adv\sopadver.exe:SopCast Adver
                              "TCP Query User{130732FA-F7E4-4C4E-8595-ED8742612E20}C:\\program files\\sopcast\\sopcast.exe"= UDP:C:\program files\sopcast\sopcast.exe:SopCast Main Application
                              "UDP Query User{07688243-354A-4185-99B6-94AC04DF89D2}C:\\program files\\sopcast\\sopcast.exe"= TCP:C:\program files\sopcast\sopcast.exe:SopCast Main Application
                              "TCP Query User{F9A1BDAA-BB2F-4FB5-9338-65B86F0611D4}C:\\program files\\adsltv\\adsltv.exe"= UDP:C:\program files\adsltv\adsltv.exe:adsltv
                              "UDP Query User{921B66F8-9962-4825-9EDD-78B5EAD69248}C:\\program files\\adsltv\\adsltv.exe"= TCP:C:\program files\adsltv\adsltv.exe:adsltv
                              "TCP Query User{62F64EB8-D0D4-4270-A9B4-C4F2F17CB5DC}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
                              "UDP Query User{47C75415-8022-428D-9D12-69C0AC887A65}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule

                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
                              "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

                              S1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-07-19 16:35]
                              S2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 16:37]
                              S2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-07-19 16:36]
                              S2 Pervasive.SQL Workgroup;EBP - Pervasive.SQL Workgroup;C:\PVSW\Bin\WGE_SRV.EXE [2006-12-07 16:08]
                              S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
                              S3 Boonty Games;Boonty Games;C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe [2008-06-28 21:59]
                              S3 camfilt2;camfilt2;C:\Windows\system32\Drivers\camfilt2.sys [2007-05-29 12:23]
                              S3 UsbSagCom;Mobile Device Full USB Driver;C:\Windows\system32\DRIVERS\UsbSagCom.sys [2007-06-29 15:20]

                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                              LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
                              HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
                              hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

                              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0f32fba9-8d37-11dc-b458-001921d9da49}]
                              \shell\verb1\command - J:\desktop.exe

                              *Newly Created Service* - CATCHME
                              *Newly Created Service* - ECACHE
                              .
                              .
                              ------- Supplementary Scan -------
                              .
                              R1 -: HKCU-SearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
                              O8 -: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                              O8 -: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites

                              O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} - hxxp://gamenextfr.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab
                              C:\Windows\Downloaded Program Files\OberonGameHost_dbg.inf
                              C:\Windows\Downloaded Program Files\OberonGameHost.dll

                              **************************************************************************

                              catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                              Rootkit scan 2008-08-10 17:38:10
                              Windows 6.0.6000 NTFS

                              Balayage processus cachés ...

                              Balayage caché autostart entries ...

                              Balayage des fichiers cachés ...

                              Scan terminé avec succès
                              Les fichiers cachés: 0

                              **************************************************************************
                              .
                              Temps d'accomplissement: 2008-08-10 17:40:20
                              ComboFix-quarantined-files.txt 2008-08-10 15:39:51

                              Pre-Run: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
                              Post-Run: 153,743,757,312 octets libres

                              182 --- E O F --- 2008-08-08 13:21:32
                              0
                              1. et voila le rapport Hitjackthis

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 12:25:45, on 04/08/2008
                                Platform: Windows Vista (WinNT 6.00.1904)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                                Boot mode: Normal

                                Running processes:
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\Explorer.EXE
                                C:\Windows\system32\taskeng.exe
                                C:\Program Files\Hercules\DualPix Exchange\CamService.exe
                                C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                                C:\Windows\RtHDVCpl.exe
                                C:\Program Files\QuickTime\qttask.exe
                                C:\Program Files\CyberLink\PowerCinema\PCMService.exe
                                C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                                C:\hp\support\hpsysdrv.exe
                                C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
                                C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                C:\Windows\vsnp2uvc.exe
                                C:\Windows\System32\hkcmd.exe
                                C:\Windows\System32\igfxpers.exe
                                C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                                C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
                                C:\Program Files\Windows Sidebar\sidebar.exe
                                C:\Windows\system32\igfxsrvc.exe
                                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
                                C:\Windows\system32\wbem\unsecapp.exe
                                C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
                                C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
                                C:\Program Files\Windows Sidebar\sidebar.exe
                                C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
                                C:\Program Files\Internet Explorer\ieuser.exe
                                C:\Windows\system32\conime.exe
                                C:\Windows\system32\wuauclt.exe
                                C:\Windows\system32\SearchFilterHost.exe
                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer optimisé pour MSN
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                O1 - Hosts: ::1 localhost
                                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                O2 - BHO: Zango - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Zango\bin\10.3.36.0\HostIE.dll (file missing)
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                O3 - Toolbar: Zango - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Zango\bin\10.3.36.0\HostIE.dll (file missing)
                                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
                                O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                                O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
                                O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                                O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
                                O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
                                O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
                                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                                O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                O4 - HKCU\..\RunOnce: [SpybotDeletingB208] command /c del "C:\Program Files\Everest Poker\casino.exe"
                                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
                                O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
                                O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
                                O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
                                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
                                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                O9 - Extra button: Groom - {66F83792-DAE1-4823-8F20-ADA94B33A4FF} - C:\Program Files\Toox\Groom\Groom.exe (HKCU)
                                O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                O13 - Gopher Prefix:
                                O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqemea/downloads/sysinfo.cab
                                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-fr.cab
                                O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                                O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://gamenextfr.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab
                                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
                                O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
                                O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
                                O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                O23 - Service: EBP - Pervasive.SQL Workgroup (Pervasive.SQL Workgroup) - Unknown owner - C:\PVSW\Bin\WGE_SRV.EXE
                                O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
                                O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                                0
                                1. re,

                                  Télécharge Navilog (de Il-Mafioso)
                                  http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

                                  Enregistre-le sur ton Bureau.
                                  Installe-le en double cliquant sur navilog.exe.
                                  Une fois l'installation terminée, l'utilitaire s'exécutera automatiquement.
                                  (Si ce n'est pas le cas, double clique sur le raccourci présent sur le Bureau)

                                  Une fois l'installation terminée, fais un clic droit sur le raccourci navilog1 puis choisis "Exécuter en tant qu'administrateur". ( Pour Vista)


                                  Laisse-toi guider par l'utilitaire. Choisis l'option 1 puis valide.
                                  ! N'utilise pas l'option 2,3 et 4 sans notre accord !
                                  Patiente jusqu'à l'apparition de ce message :
                                  "*** Analyse Termine le ..... ***"
                                  Appuie sur une touche comme demandé. Le Bloc-notes va s'ouvrir. Poste le rapport ici.

                                  Le rapport se trouve ici :C:\fixnavi.txt
                                  0
                                  1. salut
                                    voici le rapport navilog

                                    Search Navipromo version 3.6.3 commencé le 11/08/2008 à 18:36:44,82

                                    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                                    !!! Postez ce rapport sur le forum pour le faire analyser !!!
                                    !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                                    Outil exécuté depuis C:\Program Files\navilog1
                                    Session actuelle : "romain"

                                    Mise à jour le 09.08.2008 à 18h00 par IL-MAFIOSO

                                    Microsoft Windows Vista 6.0.6000
                                    Internet Explorer : 7.0.6000.16681
                                    Système de fichiers : NTFS

                                    Recherche executé en mode normal

                                    *** Recherche Programmes installés ***

                                    *** Recherche dossiers dans "C:\Windows" ***

                                    *** Recherche dossiers dans "C:\Program Files" ***

                                    *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                                    *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

                                    *** Recherche dossiers dans "C:\ProgramData" ***

                                    *** Recherche dossiers dans "c:\users\romain\appdata\roaming\micros~1\windows\startm~1\programs" ***

                                    *** Recherche dossiers dans "C:\Users\romain\AppData\Local\virtualstore\Program Files" ***

                                    *** Recherche dossiers dans "C:\Users\annie\AppData\Local\virtualstore\Program Files" ***

                                    *** Recherche dossiers dans "C:\Users\CLMENT~1\AppData\Local\virtualstore\Program Files" ***

                                    *** Recherche dossiers dans "C:\Users\julien\AppData\Local\virtualstore\Program Files" ***

                                    *** Recherche dossiers dans "C:\Users\romain\AppData\Roaming" ***

                                    *** Recherche dossiers dans "C:\Users\annie\appdata\roaming" ***

                                    *** Recherche dossiers dans "C:\Users\CLMENT~1\appdata\roaming" ***

                                    *** Recherche dossiers dans "C:\Users\julien\appdata\roaming" ***

                                    *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                                    pour + d'infos : http://www.gmer.net

                                    *** Recherche avec GenericNaviSearch ***
                                    !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                                    !!! A vérifier impérativement avant toute suppression manuelle !!!

                                    * Recherche dans "C:\Windows\system32" *

                                    * Recherche dans "C:\Users\romain\AppData\Local\Microsoft" *

                                    * Recherche dans "C:\Users\romain\AppData\Local\virtualstore\windows\system32" *

                                    * Recherche dans "C:\Users\romain\AppData\Local" *

                                    * Recherche dans "C:\Users\annie\AppData\Local" *

                                    * Recherche dans "C:\Users\CLMENT~1\AppData\Local" *

                                    * Recherche dans "C:\Users\julien\AppData\Local" *

                                    *** Recherche fichiers ***

                                    *** Recherche clés spécifiques dans le Registre ***

                                    *** Module de Recherche complémentaire ***
                                    (Recherche fichiers spécifiques)

                                    1)Recherche nouveaux fichiers Instant Access :

                                    2)Recherche Heuristique :

                                    * Dans "C:\Windows\system32" :

                                    * Dans "C:\Users\romain\AppData\Local\Microsoft" :

                                    * Dans "C:\Users\romain\AppData\Local\virtualstore\windows\system32" :

                                    * Dans "C:\Users\romain\AppData\Local" :

                                    * Dans "C:\Users\annie\AppData\Local" :

                                    * Dans "C:\Users\CLMENT~1\AppData\Local" :

                                    * Dans "C:\Users\julien\AppData\Local" :

                                    3)Recherche Certificats :

                                    Certificat Egroup absent !
                                    Certificat Electronic-Group trouvé !
                                    Certificat Montorgueil absent !
                                    Certificat OOO-Favorit trouvé !
                                    Certificat Sunny-Day-Design-Ltd absent !

                                    4)Recherche fichiers connus :

                                    *** Analyse terminée le 11/08/2008 à 18:52:18,57 ***
                                    0
                                2. Re,

                                  Double clique sur le raccourci de navilog1.
                                  Option 2 puis valide. (entrée)
                                  Laisse toi guider.
                                  Ton ordinateur va redémarrer, sinon fais le manuellement.

                                  Ton bureau va disparaître.

                                  Patiente jusqu'à l'apparition de ce message :
                                  "*** Nettoyage Termine le ..... ***"

                                  Appuie sur une touche comme demandé, le Bloc-notes va s'ouvrir.
                                  Sauvegarde le rapport.
                                  Referme le Bloc-notes. Ton bureau va maintenant réapparaître.

                                  Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
                                  Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "Nouvelle tâche (exécuter)"
                                  Tapes explorer et valide. Cela te fera apparaitre ton bureau

                                  Démarrer -> panneau de configuration -> options internet
                                  Clique sur l'onglet "Contenu" puis onglet "Certificats" et si tu trouves ceci, en particulier dans "éditeurs approuvés" :

                                  Montorgueil ; VIP

                                  ~~> Supprime-les si présents ! (pas les autres) <~~

                                  Poste le rapport sauvegardé auparavant (C:\cleannavi.txt)
                                  Ainsi qu'un nouveau rapport Hijackthis.
                                  ;)

                                  +++++++++++

                                  Les programmes suivants installent cette infection :

                                  * Go-astro
                                  * GoRecord
                                  * HotTVPlayer
                                  * MailSkinner
                                  * Messenger Skinner
                                  * Instant Access
                                  * InternetGameBox
                                  * sudoplanet
                                  * Webmediaplayer : sauf celui provenant du site suivant > http://www.azertysite.new.fr/
                                  * Sur le site www.games-desktop.com (Ne pas aller dessus!)

                                  0
                                  1. salut
                                    Navilog1 ne veut pas se lancer
                                    je choisis la langue puis entree et puis rien ne se passe la fenetre disparait
                                    qu'est ce qui se passe??
                                    merci
                                    -1
                                    1. Contributeur sécurité
                                      Bonjour

                                      Sous Vista,tu dois désactiver l' UAC...

                                      Désactive le contrôle des comptes utilisateurs
                                      (tu le réactiveras après ta désinfection):

                                      * Va dans démarrer puis panneau de configuration
                                      * Double Clique sur l'icône "Comptes d'utilisateurs"
                                      * Clique ensuite sur désactiver et valide.

                                      Lance navilog par un clic droit pour choisir de le faire en tant qu'administrateur.
                                      -1
                                    2. @toptitbalok merci beaucoup
                                      -1
                                  • 1
                                  • 2