Bitdefender ne répond plus

Bonjour,

Mon problème est que mon antivirus BitDefender total security 2009 s'est désactivé (depuis quelques semaines) et je ne peux plus l'activer. Lorsque je clique sur "activer", rien ne se passe...

Si quelqu'un peut m'aider, j'ai fait un scan hijackthis

Merci
Configuration: Windows Vista
Firefox 3.5.5

23 réponses

  1. salut pour avancer :

    ▶ Relance List&Kill'em comme tu as fait pour l'option 1 (soit en clic droit pour vista),

    mais cette fois-ci :

    ▶ choisis l'option 2 = Mode Destruction

    laisse travailler l'outil.

    en fin de scan un rapport s'ouvre

    ▶ colle le contenu dans ta reponse

    ▹ Redemarre ton PC.
    0
    1. Salut, Merci pour ces précisions. Voici le rapport - comme mon pc plante, je l'ai fait sous ms dos.

      List'em by g3n-h@ckm@n 1.1.4.1

      Thx to Chiquitine29.....& CCM team

      User : Di (Administrateurs) # PC-DE-DI
      Update on 09/12/2009 by g3n-h@ckm@n ::::: 17:00
      Start at: 22:43:20 | 10/12/2009
      Contact : g3n-h@ckm@n sur CCM

      Intel(R) Pentium(R) Dual CPU T2390 @ 1.86GHz
      Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
      Internet Explorer 8.0.6001.18828
      Windows Firewall Status : Disabled

      C:\ -> Disque fixe local | 100,6 Go (13,76 Go free) | NTFS
      D:\ -> Disque fixe local | 11,19 Go (2,32 Go free) [PRESARIO_RP] | NTFS
      E:\ -> Disque CD-ROM

      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

      C:\Windows\System32\smss.exe 380
      C:\Windows\system32\csrss.exe 520
      C:\Windows\system32\csrss.exe 556
      C:\Windows\system32\wininit.exe 564
      C:\Windows\system32\winlogon.exe 608
      C:\Windows\system32\services.exe 636
      C:\Windows\system32\lsass.exe 652
      C:\Windows\system32\lsm.exe 660
      C:\Windows\system32\svchost.exe 808
      C:\Windows\system32\svchost.exe 864
      C:\Windows\System32\svchost.exe 1004
      C:\Windows\system32\svchost.exe 1032
      C:\Windows\System32\svchost.exe 1056
      C:\Windows\system32\svchost.exe 1108
      C:\Windows\system32\svchost.exe 1128
      C:\Windows\system32\svchost.exe 1304
      C:\Windows\system32\svchost.exe 1408
      C:\Windows\Explorer.EXE 1740
      C:\Program Files\Windows Media Player\wmpnscfg.exe 120
      C:\Windows\system32\igfxsrvc.exe 1052
      C:\Users\Di\Desktop\List_Killem\List_Kill'em.scr 940
      C:\Windows\system32\cmd.exe 1524
      C:\Windows\system32\wbem\wmiprvse.exe 832
      C:\Users\Di\AppData\Local\Temp\E5AC.tmp\pv.exe 304

      ======================
      Keys "Run"
      ======================
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      LightScribe Control Panel REG_SZ C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
      ehTray.exe REG_SZ C:\Windows\ehome\ehTray.exe
      WMPNSCFG REG_SZ C:\Program Files\Windows Media Player\WMPNSCFG.exe
      SWF Live Preview REG_SZ C:\Program Files\Eltima Software\SWF Live Preview\swf_lp.exe
      swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\AdobeUpdater

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      Apoint REG_SZ C:\Program Files\Apoint2K\Apoint.exe
      IAAnotif REG_SZ "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
      QPService REG_SZ "C:\Program Files\HP\QuickPlay\QPService.exe"
      QlbCtrl REG_EXPAND_SZ %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
      UCam_Menu REG_SZ "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
      Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      HP Health Check Scheduler REG_SZ [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
      hpWirelessAssistant REG_SZ C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
      IgfxTray REG_SZ C:\Windows\system32\igfxtray.exe
      HotKeysCmds REG_SZ C:\Windows\system32\hkcmd.exe
      Persistence REG_SZ C:\Windows\system32\igfxpers.exe
      HP Software Update REG_SZ C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
      DellNSCST_GRNCH REG_SZ "C:\Program Files\Dell\Dell Laser MFP 1815\NetworkScan\DNSCST.exe" /HIDEUI
      Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      BitDefender Antiphishing Helper REG_SZ "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"
      BDAgent REG_SZ "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
      SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

      =====================
      Other Keys
      =====================
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
      ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
      ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
      EnableInstallerDetection REG_DWORD 1 (0x1)
      EnableLUA REG_DWORD 1 (0x1)
      EnableSecureUIAPaths REG_DWORD 1 (0x1)
      EnableVirtualization REG_DWORD 1 (0x1)
      PromptOnSecureDesktop REG_DWORD 1 (0x1)
      ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
      dontdisplaylastusername REG_DWORD 0 (0x0)
      legalnoticecaption REG_SZ
      legalnoticetext REG_SZ
      scforceoption REG_DWORD 0 (0x0)
      shutdownwithoutlogon REG_DWORD 1 (0x1)
      undockwithoutlogon REG_DWORD 1 (0x1)
      FilterAdministratorToken REG_DWORD 0 (0x0)
      EnableUIADesktopToggle REG_DWORD 0 (0x0)

      ===============
      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
      NoDriveTypeAutoRun REG_BINARY 95000000

      ===============
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
      BindDirectlyToPropertySetStorage REG_DWORD 0 (0x0)

      ===============
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      AppInit_DLLS REG_SZ

      ===============
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]

      ===============
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

      ===============
      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
      C:\Program Files\BitTorrent\bittorrent.exe REG_SZ C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

      ===============
      BHO :
      ======
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

      ================
      Internet Explorer :
      ================
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
      Start Page REG_SZ https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
      Start Page REG_SZ https://www.google.fr/?gws_rd=ssl

      ========
      Services
      ========
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

      Ndisuio : 0x3
      EapHost : 0x3
      Wlansvc : 0x2
      SharedAccess : 0x3
      windefend : 0x2
      wuauserv : 0x2
      wscsvc : 0x2

      =========

      =======
      Drive :
      =======

      D‚fragmenteur de disque Windows
      Copyright (c) 2006 Microsoft Corp.

      Rapport d'analyse pour le volume C:

      Taille du volume = 101 Go
      Espace libre = 13.76 Go
      tendue d'espace libre la plus grande = 1.99 Go
      Pourcentage de fragmentation des fichiers = 2 %

      Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

      Il n'est pas n‚cessaire de d‚fragmenter ce volume.

      ==========
      Programs
      ==========

      Activation Assistant for the 2007 Microsoft Office suites
      Adobe
      AIM6
      Apoint2K
      Atheros
      Audacity 1.3 Beta (Unicode)
      Axure
      Belkin
      BitDefender
      BitTorrent
      Bonjour
      Common Files
      CONEXANT
      CyberLink
      DELL
      desktop.ini
      DivX
      DNA
      EarMaster Pro 5
      Electronic Arts
      Elo TouchSystems
      EloTouchSystems
      Eltima Software
      eMule
      Fichiers communs
      FileZilla FTP Client
      Fit3DLiveDecathlon
      Futuroscope La Rencontre
      GlassesDirectMirror
      Google
      Hewlett-Packard
      Hp
      HP Games
      HPQ
      InstallShield Installation Information
      Intel
      Internet Explorer
      Inventel
      Java
      Malwarebytes' Anti-Malware
      McAfee Security Scan
      Microsoft
      Microsoft Games
      Microsoft Office
      Microsoft Silverlight
      Microsoft Visual Studio
      Microsoft Visual Studio 8
      Microsoft Works
      Microsoft.NET
      Movie Maker
      Mozilla Firefox
      MSBuild
      MSXML 4.0
      muvee Technologies
      M‚thode de Guitare - DEMO Volume I
      M‚thode de Guitare - DEMO Volume I82
      Navilog1
      NetWaiting
      Nokia
      Online Services
      Opera
      PC Connectivity Solution
      PDFCreator
      PhotoFiltre
      RaybanMirror
      Realtek
      Reference Assemblies
      RegCure
      Securitoo
      Skype
      Symantec
      Uninstall Information
      VideoLAN
      Viewpoint
      Wanadoo
      Winamp
      Windows Calendar
      Windows Collaboration
      Windows Defender
      Windows Journal
      Windows Live
      Windows Live SkyDrive
      Windows Mail
      Windows Media Player
      Windows NT
      Windows Photo Gallery
      Windows Portable Devices
      Windows Sidebar
      WinRAR

      ¤¤¤¤¤¤¤¤¤¤ Files/folders :

      C:\Program Files\Mozilla FireFox\Components\AskSearch.js
      C:\Windows\system32\logs
      C:\Windows\system32\x64

      ¤¤¤¤¤¤¤¤¤¤ Keys :

      HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar "{66886C4D-B307-4ECA-A228-52CA9B9851A4}"
      "HKCU\software\microsoft\internet explorer\searchscopes\{CF739809-1C6C-47C0-85B9-569DBB141420}"
      HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
      HKLM\Software\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}

      =========
      Rootkits
      =========

      catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2009-12-10 22:48:42
      Windows 6.0.6002 Service Pack 2 NTFS

      scanning hidden processes ...

      scanning hidden services & system hive ...

      scanning hidden registry entries ...

      scanning hidden files ...

      scan completed successfully
      hidden processes: 0
      hidden services: 0
      hidden files: 0

      Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

      device: opened successfully
      user: MBR read successfully
      kernel: MBR read successfully
      user & kernel MBR OK

      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
      0
      1. Le RSIT sert à diagnostiquer ton PC pour visualiser les processus et fichiers système pour me permettre d'en déduire si oui ou non tu est infecté.

        Pour Listkill'em c'est un programme conçus par Gen-Hackman (que je salut au passage) il servira à neutraliser quelques infections qui se loge chez toi.

        1
        1. Ok je vais faire ça ce soir, mais comme mon pc se bloque j'espère que ça se fera sans trop de problèmes.

          Au fait j'ai 2 questions (si tu as un peu de temps pour y répondre rapido) : qu'est ça t'as "révélé" le RIST ? et à quoi ça sert le List&Kill'em ?

          Merci :)
          0
          1. Rebonjour, j'ai juste changer de pseudo ;))

            Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent

            ▶ Télécharge List&Kill'em et enregistre le sur ton bureau

            ▶ dezippe-le , (clic droit/ extraire.....)

            Il ne necessite pas d'installation

            ▶double clic (clic droit "executer en tant qu'administrateur" pour Vista) pour lancer le scan

            choisis la langue puis choisis l'option 1 = Mode Recherche

            ▶laisse travailler l'outil

            ▶Poste le contenu du rapport qui s'ouvre

            1
            1. Salut,
              Voici le rapport RIST. Est-ce qu'il te faut le info.txt ?
              J'ai un nouveau problème sur mon PC (depuis ces derniers jours), je ne sais pas si c'est lié aux dernières manip que j'ai fait mais en gros, au bout de quelques minutes après avoir démarrer, mon PC se bloque (quelque soit ce que je fais) je suis obligée de le forcer à s'éteindre en appuyant longtemps sur la touche d'arret, car rien ne répond et Ctrl+Alt+Suppr ne fonctionne pas non plus...

              Logfile of random's system information tool 1.06 (written by random/random)
              Run by Di at 2009-12-09 22:13:09
              Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
              System drive C: has 12 GB (12%) free of 103 GB
              Total RAM: 2037 MB (51% free)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 22:13:55, on 09/12/2009
              Platform: Windows Vista SP2 (WinNT 6.00.1906)
              MSIE: Internet Explorer v8.00 (8.00.6001.18828)
              Boot mode: Normal

              Running processes:
              C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Program Files\Apoint2K\Apoint.exe
              C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
              C:\Program Files\Hp\QuickPlay\QPService.exe
              C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
              C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
              C:\Windows\System32\igfxtray.exe
              C:\Windows\System32\hkcmd.exe
              C:\Windows\System32\igfxpers.exe
              C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
              C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
              C:\Windows\ehome\ehtray.exe
              C:\Program Files\Windows Media Player\wmpnscfg.exe
              C:\Program Files\Eltima Software\SWF Live Preview\swf_lp.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\Windows\System32\mobsync.exe
              C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\Apoint2K\ApMsgFwd.exe
              C:\Windows\system32\igfxsrvc.exe
              C:\Windows\ehome\ehmsas.exe
              C:\Program Files\Apoint2K\Apntex.exe
              C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
              C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
              C:\Users\Di\Desktop\RSIT.exe
              C:\Users\Di\Downloads\Di.exe
              C:\Windows\system32\SearchProtocolHost.exe
              C:\Windows\system32\SearchFilterHost.exe
              C:\Windows\system32\wuauclt.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.144:53
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              O1 - Hosts: ::1 localhost
              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
              O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
              O3 - Toolbar: (no name) - {66886C4D-B307-4ECA-A228-52CA9B9851A4} - (no file)
              O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\IEToolbar.dll
              O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
              O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
              O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
              O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
              O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
              O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
              O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
              O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
              O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
              O4 - HKLM\..\Run: [DellNSCST_GRNCH] "C:\Program Files\Dell\Dell Laser MFP 1815\NetworkScan\DNSCST.exe" /HIDEUI
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"
              O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
              O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKCU\..\Run: [SWF Live Preview] C:\Program Files\Eltima Software\SWF Live Preview\swf_lp.exe
              O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
              O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
              O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
              O13 - Gopher Prefix:
              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
              O23 - Service: BitDefender Serveur Arrakis (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe
              O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
              O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
              O23 - Service: EloSystemService - Elo Touchsystems - C:\Windows\system32\EloSrvce.exe
              O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
              O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
              O23 - Service: Service Google Update (gupdate1ca0659d0db58ee) (gupdate1ca0659d0db58ee) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
              O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
              O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
              O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
              O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
              O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
              O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
              O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
              0
              1. Refait nous un RSIT stp ..
                0
                1. Bon alors voilà en espérant qu'il sagit du bon fichier (cleannavi.txt - j'ai pas trouvé de fichier fixnavi.txt)

                  Fix Navipromo version 4.0.5 commencé le 08/12/2009 17:36:12,88

                  !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                  !!! Postez ce rapport sur le forum pour le faire analyser !!!

                  Outil exécuté depuis C:\Program Files\navilog1

                  Mise à jour le 10.11.2009 à 18h00 par IL-MAFIOSO

                  Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6002 ) Service Pack 2
                  X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU T2390 @ 1.86GHz )
                  BIOS : Default System BIOS
                  USER : Di ( Administrator )
                  BOOT : Normal boot

                  C:\ (Local Disk) - NTFS - Total:100 Go (Free:12 Go)
                  D:\ (Local Disk) - NTFS - Total:11 Go (Free:2 Go)
                  E:\ (CD or DVD)

                  Recherche executée en mode normal

                  [b]Aucune Infection Navipromo/Egdaccess trouvée/b

                  *** Scan terminé 08/12/2009 17:37:16,12 ***
                  0
                  1. Si il répond plus, il a peut être changé de n° . . .
                    ok je sort désolé pour la blague pourrit a 1h13 du mat!
                    0
                    1. Contributeur sécurité
                      Bonsoir,

                      Dia 031 si tu as exécuté navilog normalement tu doit avoir un rapport qui se trouve là :

                      ▶un rapport : fixnavi.txt dans ==> C:
                      0
                      1. C'est quoi cette chose ?o0
                        0
                        1. Voici le rapport navilog.

                          DebugFile Navilog1 07/12/2009 19:57:53,50

                          Language French selected
                          Check OS
                          OS is Vista
                          Taking DelphPaths 07/12/2009 19:58:12,34
                          DelphPaths Ok 07/12/2009 19:58:12,79
                          C:\Program Files\navilog1\process.exe missing 07/12/2009 19:58:47,49
                          All Files presents 07/12/2009 19:58:47,56
                          Ch1 began 07/12/2009 at 19:59:20,99
                          Scan SF1 07/12/2009 19:59:21,05
                          End SF1 07/12/2009 19:59:21,11
                          Scan SF2 07/12/2009 19:59:21,13
                          End SF2 07/12/2009 19:59:21,18
                          Scan SF3 07/12/2009 19:59:21,19
                          End SF3 07/12/2009 19:59:21,25
                          Scan SF4 07/12/2009 19:59:21,26
                          End SF4 07/12/2009 19:59:21,33
                          Scan SF5 07/12/2009 19:59:21,34
                          End SF5 07/12/2009 19:59:21,39
                          Scan SFV1 07/12/2009 19:59:21,41
                          End SFV1 07/12/2009 19:59:30,38
                          Scan SFV2 07/12/2009 19:59:30,41
                          End SFV2 07/12/2009 19:59:34,29
                          Start SFiles 07/12/2009 19:59:34,35
                          End SFiles 07/12/2009 19:59:34,76
                          Start SReg 07/12/2009 19:59:34,81
                          End SReg 07/12/2009 19:59:42,18
                          Start Sheur 07/12/2009 19:59:42,20
                          End Sheur 07/12/2009 20:00:11,72
                          Start SCert 07/12/2009 20:00:11,74
                          End SCert 07/12/2009 20:00:16,03
                          Ch1 finished 07/12/2009 20:00:16,08
                          Language French selected
                          Check OS
                          OS is Vista
                          Taking DelphPaths
                          DelphPaths Ok
                          Cleanning stage on reboot 07/12/2009 20:11:21,60
                          Start SSF1 07/12/2009 20:11:43,49
                          End SSF1 07/12/2009 20:11:43,55
                          Start SSF2 07/12/2009 20:11:43,56
                          End SSF2 07/12/2009 20:11:43,67
                          Start SSF3 07/12/2009 20:11:43,67
                          End SSF3 07/12/2009 20:11:43,84
                          Start SSFV1 07/12/2009 20:11:43,86
                          End SSFV1 07/12/2009 20:11:51,39
                          Start SSFV2 07/12/2009 20:11:51,43
                          End SSFV2 07/12/2009 20:11:53,95
                          Start SSFiles 07/12/2009 20:11:53,97
                          End SSFiles 07/12/2009 20:11:54,66
                          Start SSHeur 07/12/2009 20:11:54,67
                          End SSHeur 07/12/2009 20:13:27,57
                          Start SSTemp 07/12/2009 20:13:27,58
                          End SSTemp 07/12/2009 20:13:49,56
                          Start CleanReg 07/12/2009 20:13:49,58
                          End CleanReg 07/12/2009 20:13:50,67
                          Start SSCert 07/12/2009 20:13:50,67
                          End SSCert 07/12/2009 20:14:02,04
                          Start Xtra 07/12/2009 20:14:02,09
                          End Xtra 07/12/2009 20:14:04,65
                          Ch234 finished 07/12/2009 20:14:04,67
                          0
                          1. Contributeur sécurité
                            dia.031, tu eux faire ce qu'à mis helper mask c'est à dire navilog.
                            0
                            1. Télécharge Navilog1 depuis-ce lien

                              ▶ Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
                              ▶ Ensuite double clique sur navilog1.exe pour lancer l'installation.

                              Une fois l'installation terminée, le fix s'exécutera automatiquement.

                              ▶ Au menu principal, Fais le choix 1 >> Recherche / suppression automatique

                              Patiente jusqu'au message :
                              *** Analyse Termine le ..... ***

                              >>>>> Le fix peut durer une dizaine de minutes ;)

                              ▶ Appuie sur une touche le bloc note va s'ouvrir.

                              ▶ Copie-colle le rapport ici.

                              0
                              1. Aussi, juste une reflexion sur l'antivirus bitdefender, je ne trouve pas ça trop normal d'acheter un antivirus et de voir que j'ai quand meme des éléments infectés dans mon ordinateur... à se demander si ça me protège réellement bien.

                                A+
                                0
                                1. Re,

                                  Helper-Mask, Malwarebytes. Comme dit, j'ai installé et lancé Malwarebytes qui a trouvé 5 éléments infectés. Ci-joint le rapport.

                                  Malwarebytes' Anti-Malware 1.42
                                  Version de la base de données: 3300
                                  Windows 6.0.6002 Service Pack 2
                                  Internet Explorer 8.0.6001.18828

                                  05/12/2009 21:30:36
                                  mbam-log-2009-12-05 (21-30-36).txt

                                  Type de recherche: Examen complet (C:\|D:\|)
                                  Eléments examinés: 329874
                                  Temps écoulé: 2 hour(s), 37 minute(s), 12 second(s)

                                  Processus mémoire infecté(s): 0
                                  Module(s) mémoire infecté(s): 0
                                  Clé(s) du Registre infectée(s): 3
                                  Valeur(s) du Registre infectée(s): 1
                                  Elément(s) de données du Registre infecté(s): 0
                                  Dossier(s) infecté(s): 0
                                  Fichier(s) infecté(s): 1

                                  Processus mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Module(s) mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Clé(s) du Registre infectée(s):
                                  HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\SOFTWARE\OOO (Malware.Trace) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\OOO (Rogue.LivePlayer) -> Quarantined and deleted successfully.

                                  Valeur(s) du Registre infectée(s):
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\eemwa (Trojan.Agent.H) -> Quarantined and deleted successfully.

                                  Elément(s) de données du Registre infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Dossier(s) infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Fichier(s) infecté(s):
                                  C:\Users\Di\Downloads\Moovida_setup.exe (Adware.NaviPromo) -> Quarantined and deleted successfully.
                                  0
                                  1. Contributeur sécurité
                                    non helper mask c'est un navilog d'abord qu'il faut faire, ensuite voir comment supprimer ça C:\Windows\tasks\RegCure Program Check.job, C:\Windows\tasks\RegCure.job et seulement après faire malwarebyte's. Malwarebyte's ce fait toujours à la fin quand on a vraiment tout désinfecté.
                                    0
                                    1. Salut,

                                      Par rapport à mon problème de départ avec BitDefender, j'ai écris au support Bitdefender qui m'a envoyé 2 liens pour télécharger des fichiers. L'un pour désinstaller le BDF 2009 que j'avais, et l'autre pour installer la dernière verions 2010. Depuis que je l'ai installé il y'a qques jours, il ne semble plus y avoir de problèmes, l'antivirus est et reste actif.

                                      Ensuite par rapport à ta remarque pimprenelle27, j'ai refais un scan et je constate que j'ai toujours les lignes que tu as relevé...
                                      Du coup que me conseilles-tu ?

                                      Merci à vous.
                                      Dia
                                      0
                                  2. Merci Pimprenelle j'exécute un Navilog après ce qui suit.
                                    0
                                    • 1
                                    • 2