Virus win32 rootkit gen trk

salut jetait infecter par un cheval de troie win32 navipotrj on ma donner des info je les ai jai refai un scan avc avas et il me trouve win32 rooktit gen rtk mon ordi e lent o demje sui sur vista aider moi je debute jene sai pa si jai bien fai tou ce kon ma conseiller merci
Configuration: Windows Vista
Firefox 2.0.0.17

117 réponses

Résumé de la discussion

Problème central : une machine sous Windows Vista est infectée par des Trojans Win32 NAVIPOTRJ et Win32 ROOKIT GEN RTK, provoquant lenteurs et difficultés de désinfection. Plusieurs conseils clés paraissent : l'usage d'outils comme Combofix et HijackThis, la vérification des entrées de démarrage et l'exécution en mode sans échec pour identifier et neutraliser les composants malveillants. Certains répondants suggèrent de privilégier des antivirus alternatifs et de désactiver temporairement les protections avant l'exécution d'outils spécifiques, puis de redémarrer en mode sans échec et de générer des rapports. D'autres évoquent des ressources et des guides sur les traitements antivirus, notamment des comparatifs Avast et Avira et des précautions pour éviter les erreurs courantes.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    riencomprisdecequeturacontes
    4
    1. Bonjour cher extraterrestre,

      Nous te souhaitons la bienvenue sur notre planete, nous somme desolé mais nous ne parlons pas votre language !

      Sans rire, le FRANCAIS CORRECT tu connais ?
      2
      1. Contributeur sécurité
        va sur ce site
        http://www.traducteur-sms.com/
        copie ton texte
        traduit
        puis copie/colle la traduction ici
        1
        1. Incroyable un traducteur pour illettré je rêve
          0
      2. Contributeur sécurité
        L'infection viens parfois avec ces programmes la:
        * Live-Player (live-player.com)
        * Go-astro
        * GoRecord
        * HotTVPlayer
        * MailSkinner
        * Messenger Skinner
        * Instant Access
        * InternetGameBox
        * Sudoplanet
        * games-desktop.com
        * WebMediaplayer

        dans ton cas, toolbar S&D montre bien que tu as toujours l'infection
        1
        1. Contributeur sécurité
          pour navilog1

          **si ça ne fonctionne pas,fais un clic droit dessus et dans le menu contextuel choisis "Exécuter en tant qu'administrateur".

          je suis vraiment nul en informatique

          mais tu sais comment fonctionne les fichiers .torrent...!!!
          1
          1. Contributeur sécurité
            bien,

            plus d'infection visible

            fais ceci

            relance Hijackthis (scan only) et coche ces lignes

            O4 - Global Startup: VPro520.lnk = ?
            O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
            O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
            O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
            O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll/206 (file missing)

            clic sur fic checked

            ensuite

            avast est un mauvais antivirus

            Pour moi, Antivir est beaucoup plus performant, c'est pourquoi, je te conseille TRES VIVEMENT de désinstaller Avast! et installer Antivir à la place : https://www.malekal.com/avira-free-security-antivirus-gratuit/

            Pour t'aider tu peux suivre ce lien : http://forum.malekal.com/ftopic4192.php

            - Après l'installation, mets le à jour - si ton firewall fait une alerte.. accepte la connexion.
            - Assure toi qu'Antivir est bien à jour, vérifie la date d'update.

            -- Redémarre en mode sans échec, pour cela, redémarre l'ordinateur, avant le logo Windows, tapote sur la touche F8, un menu va apparaître, choisis Mode sans échec et appuye sur la touche entrée du clavier.

            - Ouvre Antivir par le menu Démarrer / Programmes
            - Clique sur l'onglet Scanner.
            - Sélectionne "Manual Selection"
            - Sélectionne ton/tes disque(s)
            - Lance le scan - Mets en quarantaine tous les éléments détectés.
            - Une fois le scan terminé enregistre le rapport.

            Redémarre en mode normal.

            Poste le rapport ici.
            1
            1. merci pour tes conseilles mais antivir est un antivirus payant??
              0
          2. Contributeur sécurité
            tu piges que dalle en anglais,mais moi non plus!suffit de lire le lien que je t'ai filer et ca marche
            et si c'est pour avoir un antivirus qui bloque aucun virus!!!(avast est le plus mauvais antivirus qui existe avec norton et mac afee)
            la preuve,quand tu l'as installé,il a retiré 2 trojans que avast a laissé passer

            enfin bon,tes maître de ton pc

            revenons à nos moutons

            c'est pas moi qui vois rien c'est navilog1
            ceci dit ton log HJT est propre,l'infection a disparue

            fais ceci

            Télécharge Combofix sUBs : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
            et sauvegarde le sur ton bureau et pas ailleurs!

            **Désactive les logiciels de protection** (Antivirus, Antispywares) puis :
            deconnecte toi d'internet,ferme tout les programmes

            Double-clique sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider.
            ne touche plus à rien, même pas ta souris!!
            Attends que combofix ait terminé, un rapport sera créé.

            Poste le rapport.

            1
            1. Nous aidons les gens poli et correct qui savent ecrire et parler leur langue !! mais tu n'as pas l'air de connaitre le Francais alors tempi, si tu ne trouve aucune aide ici, ne t'etonnes pas !
              0
              1. donc ok je dissai jai choper un win32 navipo trj hier on ma donnai des conseille pour le supp sur le forum jai essayer mai jai relancer un scan avec avast et il me trouve win32 roofkit gen trk donc je ne sai pa si jai bien fait la desinfection ou c est un autre virus ki persiste aider je debute jai vista
                0
                1. C'est pas joli joli !!

                  Bon allez je te prend en charge (avec toi chimay8 si tu veux) parceque si on attends de toi un language correct la semaine prochaine on y est encore !!

                  *******************************

                  - http://www.trendsecure.com/portal/fr/_download/HJTInstall.exe Télécharge HiJackThis] de Merijn sur ton bureau.

                  - Double-clic sur HijackThis

                  - Génère un rapport en suivant ces indications :
                  - Exécute le et clique sur Do a scan and save log file.
                  - Le rapport s'ouvre sur le Bloc-Note

                  - Colle le rapport ici, pour cela :
                  - Menu Edition / Selectionner Tout
                  - Menu Edition / copier
                  - Ici dans un nouveau message : clic droit / coller

                  Aide : N'hésite pas à consulter l'aide HiJackThis
                  0
                  1. ok merci a toi mai je decouvre se forum desole je vai suiver les info que tu ma donner
                    0
                2. Il est comprehensible et agreable de voir un nouvel utilisateur sur ce forum mais ca n'excuse pas ton ecriture, si plus tard tu envoies un C.V en SMS, t'auras beau en envoyer 115, il t'en reviendra aucun ! Alors, regarde nous comme chef d'entreprise et ecris-nous correctement, c'est une marque de respect !

                  0
                  1. ok merci , ta toua fait raison jetait envoyer le rapport je te remerci de bien vouloir m aider
                    0
                3. je te poste le rapport cetait bien de sa la dont tu me parle Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 09:10:32, on 28/10/2008
                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                  MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\hp\support\hpsysdrv.exe
                  C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                  C:\Windows\RtHDVCpl.exe
                  C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                  C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\BitComet\BitComet.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
                  C:\Windows\system32\schtasks.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Windows\VPro520.exe
                  C:\Users\hp\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Users\hp\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
                  C:\Windows\System32\mobsync.exe
                  C:\Program Files\Windows Media Player\wmplayer.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                  C:\Windows\system32\wbem\unsecapp.exe
                  C:\hp\kbd\kbd.exe
                  C:\Windows\system32\conime.exe
                  C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
                  C:\Program Files\Alwil Software\Avast4\ashChest.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                  O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: The Pirate Bay Toolbar - {a33fa729-d155-4b23-842b-2c665ecabdb6} - C:\Program Files\The_Pirate_Bay\tbThe_.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O3 - Toolbar: The Pirate Bay Toolbar - {a33fa729-d155-4b23-842b-2c665ecabdb6} - C:\Program Files\The_Pirate_Bay\tbThe_.dll
                  O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                  O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
                  O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                  O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
                  O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
                  O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Windows\TEMP\E_S59F2.tmp" /EF "HKCU"
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
                  O4 - HKCU\..\Run: [mygmkog] "c:\users\hp\appdata\local\mygmkog.exe" mygmkog
                  O4 - HKCU\..\Run: [kiuckwm] "c:\users\hp\appdata\local\kiuckwm.exe" kiuckwm
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - Startup: Outil de notification Live Search.lnk = C:\Users\hp\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
                  O4 - Global Startup: VPro520.lnk = ?
                  O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                  O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                  O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                  O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll/206 (file missing)
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O13 - Gopher Prefix:
                  O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/VistaMSNPUpldfr-fr.cab
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\Windows\system32\ezNTSvc.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                  O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                  O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                  O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                  0
                  1. -Telecharge Toolbar s&d--> https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

                    -Suis ce tuto jusqu'a l'option 1--> https://www.malekal.com/adwcleaner-supprimer-virus-adwares-pup/

                    -Poste le rapport de l'option 1 avant de continuer.

                    ***************************************

                    -Telecharge MBAM--> http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                    -Suis ce tuto--> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

                    -Execute un scan complet en mode sans echec

                    -Supprime tout ce qu'il te trouve (liste en rouge)-->clique sur "supprimer la selection"

                    -Poste le rapport.

                    0
                    1. merci je t envoi le rapport dit moi ce que tu en pense pour moi c est compliquer merci
                      -----------\\ ToolBar S&D 1.2.4 XP/Vista

                      Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                      X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU E2140 @ 1.60GHz )
                      BIOS : BIOS Date: 08/24/07 19:54:45 Ver: 08.00.13
                      USER : hp ( Administrator )
                      BOOT : Normal boot
                      Antivirus : avast! antivirus 4.8.1229 [VPS 081027-1] 4.8.1229 (Activated)
                      C:\ (Local Disk) - NTFS - Total:365 Go (Free:260 Go)
                      D:\ (Local Disk) - NTFS - Total:7 Go (Free:0 Go)
                      E:\ (CD or DVD)
                      F:\ (USB)
                      G:\ (USB)
                      H:\ (USB)
                      I:\ (USB)

                      "C:\ToolBar SD" ( MAJ : 27-10-2008|09:25 )
                      Option : [1] ( 28/10/2008| 9:25 )

                      [ UAC => 1 ]

                      -----------\\ Recherche de Fichiers / Dossiers ...

                      C:\Windows\iun6002.exe

                      -----------\\ [..\Internet Explorer\Main]

                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                      "Local Page"="C:\\Windows\\system32\\blank.htm"
                      "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                      "Start Page"="http://google/"
                      "Search Bar"="https://actus.sfr.fr"
                      "Url"="http://www.microsoft.com/athome/community/rss.xml"
                      "Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
                      "Url"="http://www.microsoft.com/atwork/community/rss.xml"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                      "Start Page"="https://fr.yahoo.com/"
                      "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                      "Default_Search_URL"="https://actus.sfr.fr"
                      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

                      --------------------\\ Recherche d'autres infections

                      C:\Program Files\Live-Player
                      C:\Program Files\Live-Player\data
                      C:\Program Files\Live-Player\live-player.exe
                      C:\Program Files\Live-Player\SkinCrafterDll.dll
                      C:\Program Files\Live-Player\skins
                      C:\Program Files\Live-Player\sqlite3.dll
                      C:\Program Files\Live-Player\uninst.exe
                      C:\Users\hp\AppData\Local\live-player
                      C:\Users\hp\AppData\Local\live-player\flv.swf
                      C:\Users\hp\AppData\Local\live-player\liveplayer.s3db
                      C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Live-Player
                      C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Live-Player\Conditions g‚n‚rales.url
                      C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Live-Player\Confidentialit‚.url
                      C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Live-Player\D‚sinstaller.lnk
                      C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Live-Player\Live-Player.lnk
                      C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Live-Player\Website.url
                      [b]==> EGDACCESS <==/b

                      --------------------\\ Cracks & Keygens ..

                      C:\Users\hp\Desktop\nero\Nero 7 Ultra Edition Enhanced 7.5.9.0 Keygen.exe

                      [ UAC => 1 ]

                      1 - "C:\ToolBar SD\TB_1.txt" - 28/10/2008| 9:25 - Option : [1]

                      -----------\\ Fin du rapport a 9:25:21,36
                      0
                  2. plusieurs infections -->( Navipromo, toolbar infectieuse, patch infecté) :

                    -Telecharge Navilog1--> http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

                    -Suis ce tuto jusqu'a l'option 1--> https://forums.cnetfrance.fr

                    -Poste le rapport.

                    *******************

                    -Relance toolbar s&d

                    -Desactive tes protections residentes (antivirus, antispyware )

                    -Execute l'option 2

                    -Poste le rapport.

                    *******************

                    -Laisse tes logiciels de protection desactivés (Antivirus, Antispywares) puis :

                    -Télécharge Combofix sUBs : http://download.bleepingcomputer.com/sUBs/ComboFix.execombofix.exe
                    et sauvegarde le sur ton bureau et pas ailleurs!

                    -Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider.

                    -Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.

                    -Copie/colle un nouveau rapport HiJackThis avec.

                    -Reactive tes protections residentes !!

                    0
                    1. le lien que tu ma poster je lai fait hier mais j avais toujours un virus peut etre que j ai mal fai une manip merci de maider
                      0
                      1. Contributeur sécurité
                        voir poste 14 ***doublons***
                        0
                        1. j ai installer navilog quand je mai f est entre navilog se ferme peut on l ouvrir d une autre maniere
                          0
                          1. je n arrive pas a renter dans navilog comment faire merci
                            0
                            • 1
                            • 2
                            • 3
                            • 4
                            • 5
                            • 6