TR/Unpacked.Gen

Résolu
Bonjour, peut t'on m'aider svp voila mon ordi rame et j'ai plein de pub apres avoir fait un scan complet avec avira il ma trouver >><TR/Unpacked.Gen j'ai telecharger hier avast et avast ma trouver 2 autre que j'ai mis en quarantaine mais tous les jours avira me donne ce trojan mci a vous xp>>internet explorer
Configuration: Windows XP
Internet Explorer 6.0

13 réponses

  1. Contributeur sécurité
    slt colles nous le rapport antivir

    puis

    colle un rapport hijackthis

    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

    manuel :

    https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

    Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

    ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

    Ensuite avec Explorer créer un dossier c:\hijackthis
    Décompresser Hijackthis dans ce dossier.
    C'est important pour les sauvegardes."
    0
    1. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 23:49:04, on 12/11/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\WINDOWS\System32\drivers\CDAC11BA.EXE
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\Spyware Doctor\pctsAuxs.exe
      C:\Program Files\Spyware Doctor\pctsSvc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Spyware Doctor\pctsTray.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\WINDOWS\System32\svchost.exe
      C:\program files\orange\media player\Media Player.exe
      C:\documents and settings\admin\local settings\application data\myewg.exe
      C:\PROGRA~1\Wanadoo\ComComp.exe
      C:\PROGRA~1\Wanadoo\Toaster.exe
      C:\PROGRA~1\Wanadoo\Inactivity.exe
      C:\PROGRA~1\Wanadoo\PollingModule.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\PROGRA~1\Wanadoo\Watch.exe
      C:\Program Files\Skype\Plugin Manager\skypePM.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://fr.rd.yahoo.com/customize/ie/defaults/sb/ymsgr6/fr/*http://www.yahoo.com/ext/search/search.html
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      R3 - URLSearchHook: Online_TV Toolbar - {40d1c3a7-4ffb-4443-b3a0-a64b2df7fc3b} - C:\Program Files\Online_TV\tbOnl1.dll
      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O2 - BHO: Online_TV Toolbar - {40d1c3a7-4ffb-4443-b3a0-a64b2df7fc3b} - C:\Program Files\Online_TV\tbOnl1.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
      O2 - BHO: XBTBPos00 - {DBD2C8C0-4DE1-412C-B6BB-25FB64CBA532} - C:\PROGRA~1\Axioma\ie\axioma.dll (file missing)
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: Online_TV Toolbar - {40d1c3a7-4ffb-4443-b3a0-a64b2df7fc3b} - C:\Program Files\Online_TV\tbOnl1.dll
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
      O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
      O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Gadwin PrintScreen 2.6] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKCU\..\Run: [OrangePlayer] c:\program files\orange\media player\Media Player.exe /systray
      O4 - HKCU\..\Run: [myewg] "c:\documents and settings\admin\local settings\application data\myewg.exe" myewg
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [OrangePlayer] c:\program files\orange\media player\Media Player.exe /systray (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb012YYFR_ZS
      O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
      O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
      O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
      O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
      O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
      O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093586293203
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab30149.cab
      O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} - https://download.sopcast.com/download/SOPCORE.CAB
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
      O16 - DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} (AdSignerLCContrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.0.cab
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab
      O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{E840A599-53FD-45AD-BC60-B9F9E7D0F2E9}: NameServer = 80.10.246.1,80.10.246.139
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
      O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
      0
  2. Contributeur sécurité
    slt

    vire spyware doctor si tu paye pas car pas terrible, vire avast car il ne faut garder qu'un seul antivirus sur un ordi

    ( pour virer avast: https://www.avast.com/fr-fr/uninstall-utility

    vire aussi ad aware car tu as la version 2007 alors que la version 2008 est sortie depuis une bonne année...

    ________________

    tu es sinon effectivement infecté par un rootkit fais ceci:

    Fais un clic droit sur ce lien : (IL-MAFIOSO)
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
    Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Laisse-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
    Copie-colle l'intégralité dans une réponse. Referme le blocnote.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
    0
    1. slt mci pour l'aide j'ai viré avast et adware pour spyware doctor effectivement il sert pas a grand chose mais il se sert tous les an directement a ma banque loll donc je le paye a contre coeur et j'ai beuger 3fois ce soir meme pendant l'installation de navilog donc je vais recomencer mci encore
      0
      1. Search Navipromo version 3.6.9 commencé le 13/11/2008 à 20:16:43,28

        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
        !!! Postez ce rapport sur le forum pour le faire analyser !!!
        !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

        Outil exécuté depuis C:\Program Files\navilog1
        Session actuelle : "admin"

        Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO

        Microsoft Windows XP [version 5.1.2600]
        Internet Explorer : 6.0.2900.5512
        Système de fichiers : NTFS

        Recherche executé en mode normal

        *** Recherche Programmes installés ***

        Favorit
        Live-Player

        *** Recherche dossiers dans "C:\WINDOWS" ***

        *** Recherche dossiers dans "C:\Program Files" ***

        ...\Live-Player trouvé !

        *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

        ...\Live-Player trouvé !

        *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

        *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

        *** Recherche dossiers dans "C:\Documents and Settings\admin\applic~1" ***

        *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

        *** Recherche dossiers dans "C:\DOCUME~1\ALEXIA~1\applic~1" ***

        *** Recherche dossiers dans "C:\DOCUME~1\INVIT~1\applic~1" ***

        *** Recherche dossiers dans "C:\Documents and Settings\admin\locals~1\applic~1" ***

        ...\Live-Player trouvé !

        *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

        *** Recherche dossiers dans "C:\DOCUME~1\ALEXIA~1\locals~1\applic~1" ***

        *** Recherche dossiers dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" ***

        *** Recherche dossiers dans "C:\Documents and Settings\admin\menudm~1\progra~1" ***

        *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***

        *** Recherche dossiers dans "C:\DOCUME~1\ALEXIA~1\menudm~1\progra~1" ***

        *** Recherche dossiers dans "C:\DOCUME~1\INVIT~1\menudm~1\progra~1" ***

        *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
        pour + d'infos : http://www.gmer.net

        *** Recherche avec GenericNaviSearch ***
        !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
        !!! A vérifier impérativement avant toute suppression manuelle !!!

        * Recherche dans "C:\WINDOWS\system32" *

        * Recherche dans "C:\Documents and Settings\admin\locals~1\applic~1" *

        * Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

        * Recherche dans "C:\DOCUME~1\ALEXIA~1\locals~1\applic~1" *

        * Recherche dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" *

        *** Recherche fichiers ***

        *** Recherche clés spécifiques dans le Registre ***

        HKEY_CURRENT_USER\Software\Lanconfig trouvé !

        *** Module de Recherche complémentaire ***
        (Recherche fichiers spécifiques)

        1)Recherche nouveaux fichiers Instant Access :

        2)Recherche Heuristique :

        * Dans "C:\WINDOWS\system32" :

        rmaikptn_navps.dat trouvé !
        setqea_navps.dat trouvé !

        * Dans "C:\Documents and Settings\admin\locals~1\applic~1" :

        myewg.exe trouvé !
        myewg.dat trouvé !
        myewg_nav.dat trouvé !
        myewg_navps.dat trouvé !

        * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :

        * Dans "C:\DOCUME~1\ALEXIA~1\locals~1\applic~1" :

        * Dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" :

        3)Recherche Certificats :

        Certificat Egroup trouvé !
        Certificat Electronic-Group trouvé !
        Certificat Montorgueil absent !
        Certificat OOO-Favorit trouvé !
        Certificat Sunny-Day-Design-Ltd absent !

        4)Recherche fichiers connus :

        *** Analyse terminée le 13/11/2008 à 20:26:13,84 ***
        0
        1. Contributeur sécurité
          = Lance navilog1
          = Cette fois-ci choisi l'option 2
          = Navilog va faire le nettoyage.. patient jusqu'à ce qui soit marqué *** Nettoyage Termine le ..... ***
          = Un rapport va être génrer sur ton C:\ qui sera en option 2
          Note: le bureau disparaît

          = colle le contenu du rapport de navilog (qui est en option2)

          PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
          Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
          Tape explorer et valide. Celà te fera apparaitre ton bureau.

          _______________

          puis remets un rapport hijackhtis et colle un rapport avec antivir que tu as et dis tes soucis actuels
          0
          1. Clean Navipromo version 3.6.9 commencé le 13/11/2008 à 21:13:21,06

            Outil exécuté depuis C:\Program Files\navilog1
            Session actuelle : "admin"

            Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO

            Microsoft Windows XP [version 5.1.2600]
            Internet Explorer : 6.0.2900.5512
            Système de fichiers : NTFS

            Mode suppression automatique
            avec prise en charge résultats Catchme et GNS

            Nettoyage exécuté au redémarrage de l'ordinateur

            *** fsbl1.txt non trouvé ***
            (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

            *** Suppression avec sauvegardes résultats GenericNaviSearch ***

            * Suppression dans "C:\WINDOWS\System32" *

            * Suppression dans "C:\Documents and Settings\admin\locals~1\applic~1" *

            * Suppression dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

            * Suppression dans "C:\DOCUME~1\ALEXIA~1\locals~1\applic~1" *

            * Suppression dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" *

            *** Suppression dossiers dans "C:\WINDOWS" ***

            *** Suppression dossiers dans "C:\Program Files" ***

            ...\Live-Player ...suppression...
            ...\Live-Player supprimé !

            *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

            ...\Live-Player ...suppression...
            ...\Live-Player supprimé !

            *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

            *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***

            *** Suppression dossiers dans "C:\Documents and Settings\admin\applic~1" ***

            *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

            *** Suppression dossiers dans "C:\DOCUME~1\ALEXIA~1\applic~1" ***

            *** Suppression dossiers dans "C:\DOCUME~1\INVIT~1\applic~1" ***

            *** Suppression dossiers dans "C:\Documents and Settings\admin\locals~1\applic~1" ***

            ...\Live-Player ...suppression...
            ...\Live-Player supprimé !

            *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

            *** Suppression dossiers dans "C:\DOCUME~1\ALEXIA~1\locals~1\applic~1" ***

            *** Suppression dossiers dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" ***

            *** Suppression dossiers dans "C:\Documents and Settings\admin\menudm~1\progra~1" ***

            *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***

            *** Suppression dossiers dans "C:\DOCUME~1\ALEXIA~1\menudm~1\progra~1" ***

            *** Suppression dossiers dans "C:\DOCUME~1\INVIT~1\menudm~1\progra~1" ***

            *** Suppression fichiers ***

            *** Suppression fichiers temporaires ***

            Nettoyage contenu C:\WINDOWS\Temp effectué !
            Nettoyage contenu C:\Documents and Settings\admin\locals~1\Temp effectué !

            *** Traitement Recherche complémentaire ***
            (Recherche fichiers spécifiques)

            1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

            2)Recherche, création sauvegardes et suppression Heuristique :

            * Dans "C:\WINDOWS\system32" *

            rmaikptn_navps.dat trouvé !
            Copie rmaikptn_navps.dat réalisée avec succès !
            rmaikptn_navps.dat supprimé !

            setqea_navps.dat trouvé !
            Copie setqea_navps.dat réalisée avec succès !
            setqea_navps.dat supprimé !

            * Dans "C:\Documents and Settings\admin\locals~1\applic~1" *

            myewg.exe trouvé !
            Copie myewg.exe réalisée avec succès !
            myewg.exe supprimé !

            myewg.dat trouvé !
            Copie myewg.dat réalisée avec succès !
            myewg.dat supprimé !

            myewg_nav.dat trouvé !
            Copie myewg_nav.dat réalisée avec succès !
            myewg_nav.dat supprimé !

            myewg_navps.dat trouvé !
            Copie myewg_navps.dat réalisée avec succès !
            myewg_navps.dat supprimé !

            C:\WINDOWS\prefetch\myewg*.pf trouvé !
            Copie C:\WINDOWS\prefetch\myewg*.pf réalisée avec succès !
            C:\WINDOWS\prefetch\myewg*.pf supprimé !

            * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

            * Dans "C:\DOCUME~1\ALEXIA~1\locals~1\applic~1" *

            * Dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" *

            *** Sauvegarde du Registre vers dossier Safebackup ***

            sauvegarde du Registre réalisée avec succès !

            *** Nettoyage Registre ***

            Nettoyage Registre Ok

            *** Certificats ***

            Certificat Egroup supprimé !
            Certificat Electronic-Group supprimé !
            Certificat Montorgueil absent !
            Certificat OOO-Favorit supprimé !
            Certificat Sunny-Day-Design-Ltdt absent !

            *** Nettoyage terminé le 13/11/2008 à 21:22:10,31 ***
            0
            1. Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 21:29:04, on 13/11/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              C:\WINDOWS\System32\drivers\CDAC11BA.EXE
              C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              C:\Program Files\Spyware Doctor\pctsAuxs.exe
              C:\Program Files\Spyware Doctor\pctsSvc.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\System32\alg.exe
              C:\Program Files\Spyware Doctor\pctsTray.exe
              C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\Program Files\Skype\Phone\Skype.exe
              C:\program files\orange\media player\Media Player.exe
              C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
              C:\PROGRA~1\Wanadoo\ComComp.exe
              C:\PROGRA~1\Wanadoo\Toaster.exe
              C:\PROGRA~1\Wanadoo\Inactivity.exe
              C:\PROGRA~1\Wanadoo\PollingModule.exe
              C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
              C:\Program Files\Skype\Plugin Manager\skypePM.exe
              C:\PROGRA~1\Wanadoo\Watch.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
              C:\WINDOWS\System32\wbem\wmiprvse.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://fr.rd.yahoo.com/customize/ie/defaults/sb/ymsgr6/fr/*http://www.yahoo.com/ext/search/search.html
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
              R3 - URLSearchHook: Online_TV Toolbar - {40d1c3a7-4ffb-4443-b3a0-a64b2df7fc3b} - C:\Program Files\Online_TV\tbOnl1.dll
              O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
              O2 - BHO: Online_TV Toolbar - {40d1c3a7-4ffb-4443-b3a0-a64b2df7fc3b} - C:\Program Files\Online_TV\tbOnl1.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
              O2 - BHO: XBTBPos00 - {DBD2C8C0-4DE1-412C-B6BB-25FB64CBA532} - C:\PROGRA~1\Axioma\ie\axioma.dll (file missing)
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O3 - Toolbar: Online_TV Toolbar - {40d1c3a7-4ffb-4443-b3a0-a64b2df7fc3b} - C:\Program Files\Online_TV\tbOnl1.dll
              O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
              O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
              O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
              O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
              O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [Gadwin PrintScreen 2.6] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
              O4 - HKCU\..\Run: [OrangePlayer] c:\program files\orange\media player\Media Player.exe /systray
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\Run: [OrangePlayer] c:\program files\orange\media player\Media Player.exe /systray (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
              O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb012YYFR_ZS
              O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
              O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
              O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
              O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
              O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
              O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
              O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
              O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093586293203
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab30149.cab
              O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} - https://download.sopcast.com/download/SOPCORE.CAB
              O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
              O16 - DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} (AdSignerLCContrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.0.cab
              O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab
              O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{E840A599-53FD-45AD-BC60-B9F9E7D0F2E9}: NameServer = 80.10.246.1,80.10.246.139
              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
              O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
              O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
              O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
              0
              1. un grand merci pour la rapidité et l'efficacité je crois que mon probleme est resolu >>voici le rapport de avira

                Avira AntiVir Personal
                Report file date: jeudi 13 novembre 2008 21:31

                Scanning for 1034249 virus strains and unwanted programs.

                Licensed to: Avira AntiVir PersonalEdition Classic
                Serial number: 0000149996-ADJIE-0001
                Platform: Windows XP
                Windows version: (Service Pack 3) [5.1.2600]
                Boot mode: Normally booted
                Username: SYSTEM
                Computer name: ADMIN-YKVPBE7RS

                Version information:
                BUILD.DAT : 8.2.0.336 16933 Bytes 30/10/2008 11:40:00
                AVSCAN.EXE : 8.1.4.7 315649 Bytes 18/07/2008 11:31:00
                AVSCAN.DLL : 8.1.4.0 40705 Bytes 18/07/2008 11:31:00
                LUKE.DLL : 8.1.4.5 164097 Bytes 18/07/2008 11:31:00
                LUKERES.DLL : 8.1.4.0 12033 Bytes 18/07/2008 11:31:00
                ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 13:17:44
                ANTIVIR1.VDF : 7.1.0.56 411136 Bytes 09/11/2008 01:02:53
                ANTIVIR2.VDF : 7.1.0.57 2048 Bytes 09/11/2008 01:02:54
                ANTIVIR3.VDF : 7.1.0.83 190976 Bytes 13/11/2008 18:48:53
                Engineversion : 8.2.0.31
                AEVDF.DLL : 8.1.0.6 102772 Bytes 15/10/2008 17:44:42
                AESCRIPT.DLL : 8.1.1.15 332156 Bytes 12/11/2008 18:10:38
                AESCN.DLL : 8.1.1.5 123251 Bytes 08/11/2008 18:45:36
                AERDL.DLL : 8.1.1.3 438645 Bytes 08/11/2008 18:45:35
                AEPACK.DLL : 8.1.3.4 393591 Bytes 12/11/2008 18:10:35
                AEOFFICE.DLL : 8.1.0.30 196986 Bytes 08/11/2008 18:45:34
                AEHEUR.DLL : 8.1.0.71 1487222 Bytes 08/11/2008 18:45:33
                AEHELP.DLL : 8.1.1.3 119157 Bytes 08/11/2008 18:45:32
                AEGEN.DLL : 8.1.1.0 319859 Bytes 08/11/2008 18:45:31
                AEEMU.DLL : 8.1.0.9 393588 Bytes 15/10/2008 17:44:37
                AECORE.DLL : 8.1.4.1 172405 Bytes 08/11/2008 18:45:30
                AEBB.DLL : 8.1.0.3 53618 Bytes 15/10/2008 17:44:35
                AVWINLL.DLL : 1.0.0.12 15105 Bytes 18/07/2008 11:31:00
                AVPREF.DLL : 8.0.2.0 38657 Bytes 18/07/2008 11:31:00
                AVREP.DLL : 8.0.0.2 98344 Bytes 31/07/2008 18:21:15
                AVREG.DLL : 8.0.0.1 33537 Bytes 18/07/2008 11:31:00
                AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 18/07/2008 11:31:00
                SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                SMTPLIB.DLL : 1.2.0.23 28929 Bytes 18/07/2008 11:31:01
                NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 18/07/2008 11:30:55
                RCTEXT.DLL : 8.0.52.0 86273 Bytes 18/07/2008 11:30:55

                Configuration settings for the scan:
                Jobname..........................: Complete system scan
                Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                Logging..........................: low
                Primary action...................: interactive
                Secondary action.................: ignore
                Scan master boot sector..........: on
                Scan boot sector.................: on
                Boot sectors.....................: C:,
                Process scan.....................: on
                Scan registry....................: on
                Search for rootkits..............: off
                Scan all files...................: Intelligent file selection
                Scan archives....................: on
                Recursion depth..................: 20
                Smart extensions.................: on
                Macro heuristic..................: on
                File heuristic...................: medium

                Start of the scan: jeudi 13 novembre 2008 21:31

                The scan of running processes will be started
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                Scan process 'Watch.exe' - '1' Module(s) have been scanned
                Scan process 'skypePM.exe' - '1' Module(s) have been scanned
                Scan process 'ALERTM~1.EXE' - '1' Module(s) have been scanned
                Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
                Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
                Scan process 'Toaster.exe' - '1' Module(s) have been scanned
                Scan process 'ComComp.exe' - '1' Module(s) have been scanned
                Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
                Scan process 'Media Player.exe' - '1' Module(s) have been scanned
                Scan process 'Skype.exe' - '1' Module(s) have been scanned
                Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
                Scan process 'PrintScreen.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                Scan process 'qttask.exe' - '1' Module(s) have been scanned
                Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
                Scan process 'pctsTray.exe' - '1' Module(s) have been scanned
                Scan process 'alg.exe' - '1' Module(s) have been scanned
                Scan process 'explorer.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'pctsSvc.exe' - '1' Module(s) have been scanned
                Scan process 'pctsAuxs.exe' - '1' Module(s) have been scanned
                Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
                Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
                Scan process 'CDAC11BA.EXE' - '1' Module(s) have been scanned
                Scan process 'guard.exe' - '1' Module(s) have been scanned
                Scan process 'avguard.exe' - '1' Module(s) have been scanned
                Scan process 'sched.exe' - '1' Module(s) have been scanned
                Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'lsass.exe' - '1' Module(s) have been scanned
                Scan process 'services.exe' - '1' Module(s) have been scanned
                Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'smss.exe' - '1' Module(s) have been scanned
                42 processes with 42 modules were scanned

                Starting master boot sector scan:
                Master boot sector HD0
                [INFO] No virus was found!
                Master boot sector HD1
                [INFO] No virus was found!
                [WARNING] System error [21]: Le périphérique n'est pas prêt.

                Start scanning boot sectors:
                Boot sector 'C:\'
                [INFO] No virus was found!

                Starting to scan the registry.
                The registry was scanned ( '51' files ).

                Starting the file scan:

                Begin scan in 'C:\'
                C:\pagefile.sys
                [WARNING] The file could not be opened!

                End of the scan: jeudi 13 novembre 2008 22:32
                Used time: 1:01:13 Hour(s)

                The scan has been done completely.

                7186 Scanning directories
                369642 Files were scanned
                0 viruses and/or unwanted programs were found
                0 Files were classified as suspicious:
                0 files were deleted
                0 files were repaired
                0 files were moved to quarantine
                0 files were renamed
                1 Files cannot be scanned
                369641 Files not concerned
                2687 Archives were scanned
                2 Warnings
                0 Notes
                0
                1. Contributeur sécurité
                  ok

                  rq: pour eviter cela il faut que tu configure antivir pour qu'il cherche les rootkit lors du scan

                  car dans ton rapport on voit que la recherche des rootkits est désactivée :
                  Search for rootkits..............: off

                  sinon

                  pour virer ce qui a été utilisé

                  Télécharge ToolsCleaner sur ton bureau.
                  --> http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
                  # Clique sur Recherche et laisse le scan agir ...
                  # Clique sur Suppression pour finaliser.
                  # Tu peux, si tu le souhaites, te servir des Options facultatives.
                  # Clique sur Quitter pour obtenir le rapport.
                  # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                  ps : pas besoin de m´envoyer le rapport si tout a ete supprimé

                  sinon:
                  0
                  1. Contributeur sécurité
                    pour protéger gratos ton ordi

                    http://www.commentcamarche.net/telecharger/logiciel 4 securite

                    mettre un antivirus

                    AVAST en français ou ANTIVIR (en anglais mais très efficace)
                    https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
                    -------------
                    des anti-espions :
                    MalwareByte's Anti-Malware + SPYBOT +/- si tea timer non active de spybot:
                    WINDOWS DEFENDER ou SPYWARE TERMINATOR

                    +
                    SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

                    Rq : spybot et ad-aware ont sorti de nouvelles versions cette année vérifiez que vous avez la dernière version
                    --------
                    un pare feu :
                    celui de (Windows) ou mieux Online armor ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit) ou COMODO

                    http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall
                    https://www.01net.com/telecharger/windows/Securite/firewall/fiches/39911.html
                    https://forum.pcastuces.com/sujet.asp?f=25&s=35606
                    https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
                    https://manuelsdaide.com/contact/
                    http://www.open-files.com/forum/index.php?showtopic=29277
                    http://www.commentcamarche.net/telecharger/telecharger 157 zonealarm

                    -----------
                    CCLEANER pour effacer les traces de surf
                    ---------
                    naviguer avec firefox ou safari ou opera et non internet explorer plus touché par les virus
                    http://www.mozilla-europe.org/fr/products/firefox/
                    0
                    1. mci j'ai reconfigurer avira et utiliser pc tools qui a tout suprimer donc tout a l'air de bien aller mci je vais encore voir pour un pare feu merci
                      0
                      1. Contributeur sécurité
                        ok bonne suite
                        0