Virus PRCVIEWER

Bonjour à tous,
Mon anti-virus m'annonce un virus du nom prcviewer et je n'arrive pas à le supprimer
Pouvez-vous m'aider svp?

Voici le rapport hijackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:02:00, on 10/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\WINDOWS\SOINTGR.EXE
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Winamp\Winampa.exe
C:\WINDOWS\vsnpstd3.exe
c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Shareaza\Shareaza.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://outlook.live.com/owa/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://espanol.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ar.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://ar.search.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O4 - HKLM\..\Run: [SO5 Integrator Pass Two] C:\WINDOWS\SOINTGR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\WANADOO\GestMaj.exe EspaceWanadoo.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?af24441b40c74ff3918d81da1e388cb9
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?af24441b40c74ff3918d81da1e388cb9
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O20 - AppInit_DLLs: 58.dll
O23 - Service: McAfee Application Installer Cleanup (0063001189414835) (0063001189414835mcinstcleanup) - McAfee, Inc. - C:\WINDOWS\TEMP\006300~1.EXE
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\FICHIE~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Service SiteAdvisor (SiteAdvisor Service) - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

--
End of file - 10650 bytes

Merci d'avance!!
Configuration: Windows XP
Firefox 2.0.0.6

21 réponses

  1. Bonjour Nardino,

    J'ai fait le scan en ligne qui m'a annoncé aucun virus sur mon ordi.
    J'ai quand même supprimés tous les fichiers selectionnés pendant le scan et depuis les couleurs de mon ecran sont redevenues normales.

    Merci beaucoup pour ton aide!!!
    Ciao
    Estelle
    0
    1. Oui c'était pour ça, j'etais sur firefox. Je te donne les resultats des la fin du scan
      Merci
      0
      1. Bonsoir,
        Tu passes bien par Internet Explorer ?
        La plupart des scans en ligne nécessitent le recours aux activeX seulement disponibles sous Internet Explorer
        0
        1. Bonjour Nardino,
          Je n'arrive pas à faire le scan en ligne quand j'appuie sur "j'accepte" rien ne se passe!!!
          Je ne sais pas a quoi c'est du
          Que dois je faire?
          @ plus
          0
          1. Bonjour,
            J'ai lu sur un site entre temps que prcviewer était un faux positif de F-Secure, de même que Process.exe est détecté par beaucoup d'antivirus comme un processus dangereux.
            Mais il est légal dans Smitfraud.

            Pour ton problème d'écran fais un scan en ligne ici avec Internet Explorer:
            https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
            ! Kaspersky

            Et donnes les résultats.
            0
            1. Bonjour,
              Le spy a en effet disparu et je t'en remercie beaucoup!!
              Mais j'ai un autre problème et je pensais que les 2 étaient liés. Quand j'allume mon ordi tout se passe normalement mais apres qq minutes le fond noir de l'ecran devient rouge et je pense que c'est a cause d'un virus que j'avais sur ma clé USB et que j'ai autorisé par inadvertance!!!
              Est ce que je dois poster une nouvelle discussion pour ça?
              Merci @ plus
              0
              1. Bonjour,
                Très bien dans cd cas son compte va être vite réglé.
                Tu désactives la restauration système comme suit:
                http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20020830101856924
                Désactiver ou activer la Restauration du système de Windows XP

                Tu supprimes SmitFraudFix, qu'il faut de toutes manières recharger à chaque utilisation pour bénéficier des mises à jour régulières qui lui sont apportées.

                Tu redémarres

                Tu réactives la restauration système.
                Ton spy aura disparu
                0
                1. Et voila les Détails pour l'emplacement de PrcViewer d'apres McAfee:

                  C:\WINDOWS\system32\Process.exe,
                  C:\System Volume Information\_restore{EB2F6B2A-D8DE-4421-BF4F-B6013E815398}-\RP607\A0135540.exe,
                  C:\System Volume Information\_restore{EB2F6B2A-D8DE-4421-BF4F-B6013E815398}-\RP607\A0135527.exe,
                  C:\System Volume Information\_restore{EB2F6B2A-D8DE-4421-BF4F-B6013E815398}-\RP607\A0135512.exe,
                  C:\System Volume Information\_restore{EB2F6B2A-D8DE-4421-BF4F-B6013E815398}-\RP607\A0135498.exe,
                  C:\System Volume Information\_restore{EB2F6B2A-D8DE-4421-BF4F-B6013E815398}-\RP596\A0132879.exe,
                  C:\System Volume Information\_restore{EB2F6B2A-D8DE-4421-BF4F-B6013E815398}-\RP596\A0132878.exe,
                  C:\Program Files\Navilog1\Process.exe, C:\Documents and settings\Bureau\SmitfraudFix.exe

                  @ plus
                  0
                  1. Bonjour Nardino,

                    Voila le rapport et je vais rechercher avec mon antivirus l'emplacement ou se trouve prcviewer:

                    SmitFraudFix v2.195

                    Rapport fait à 11:51:52,38, 13/09/2007
                    Executé à partir de C:\Documents and Settings\Utilisateur\Bureau\SmitfraudFix
                    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                    Le type du système de fichiers est FAT32
                    Fix executé en mode normal

                    »»»»»»»»»»»»»»»»»»»»»»»» Process

                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                    C:\WINDOWS\SOINTGR.EXE
                    C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
                    C:\WINDOWS\vsnpstd.exe
                    C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
                    C:\Program Files\QuickTime\qttask.exe
                    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                    C:\WINDOWS\system32\rundll32.exe
                    C:\WINDOWS\vsnpstd3.exe
                    c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe
                    C:\Program Files\McAfee\MSK\MskAgent.exe
                    C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
                    C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                    C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
                    C:\Program Files\MSN Messenger\msnmsgr.exe
                    c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe
                    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                    C:\Program Files\3M\PSNLite\PsnLite.exe
                    C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
                    C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
                    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                    C:\Program Files\McAfee\MPF\MPFSrv.exe
                    C:\PROGRA~1\3M\PSNLite\PSNGive.exe
                    C:\PROGRA~1\McAfee\MPS\mps.exe
                    C:\Program Files\McAfee\MSK\MskSrver.exe
                    C:\Program Files\SiteAdvisor\6172\SAService.exe
                    C:\WINDOWS\system32\slserv.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\McAfee\MPS\mpsevh.exe
                    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
                    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\WINDOWS\system32\cmd.exe

                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Utilisateur

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Utilisateur\Application Data

                    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\UTILIS~1\FAVORIS

                    »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                    "Source"="About:Home"
                    "SubscribedURL"="About:Home"
                    "FriendlyName"="Ma page d'accueil"

                    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                    "AppInit_DLLs"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    "System"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                    Description: Carte Fast Ethernet PCI 900 SiS - Miniport d'ordonnancement de paquets
                    DNS Server Search Order: 212.27.53.252
                    DNS Server Search Order: 212.27.54.252

                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{4348CED9-0C03-444E-A05F-1724051A945D}: DhcpNameServer=212.27.53.252 212.27.54.252
                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{4348CED9-0C03-444E-A05F-1724051A945D}: DhcpNameServer=212.27.53.252 212.27.54.252
                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{4348CED9-0C03-444E-A05F-1724051A945D}: DhcpNameServer=212.27.53.252 212.27.54.252
                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.53.252 212.27.54.252
                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.53.252 212.27.54.252
                    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=212.27.53.252 212.27.54.252

                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Fin

                    Merci et @ plus
                    Estelle
                    0
                    1. Bonjour.
                      Tes rapports sont exempts de trace d'infection.
                      Peux-tu me dire dans quel fichier se trouve ce fameux Prcviewer, qui semble être un faux-positif de MacAfee ?
                      As-tu SmitfraudFix sur ton pc par exemple ?
                      0
                      1. Voila le rapport :

                        Search Navipromo version 3.0.1 commencé le 12/09/2007 à 14:33:26,25

                        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                        !!! Poster ce rapport sur le forum pour le faire analyser !!!
                        !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

                        Fix lancé depuis C:\Program Files\navilog1
                        Mise a jour le 08.09.2007 a 21h00 by IL-MAFIOSO

                        Microsoft Windows XP [version 5.1.2600]
                        Internet Explorer : 6.0.2900.2180

                        *** Recherche Programmes installes ***

                        *** Recherche dossiers dans C:\WINDOWS ***

                        *** Recherche dossiers dans C:\Program Files ***

                        *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

                        *** Recherche dossiers dans C:\Documents and Settings\Utilisateur\Application Data ***

                        *** Recherche avec BlackLight Engine/F-secure ***
                        BlackLight Engine est un produit de F-secure, pour + d'infos :
                        https://www.f-secure.com/en

                        F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
                        ======================================

                        Copyright 2005-2006 F-Secure Corporation. All rights reserved.
                        This is a beta version. It will expire on 1st of October, 2007.
                        Version information: 2.2.1064.

                        [+] Started on 09/12/07 at 14:33:35.
                        [+] Initializing ...
                        [+] Starting scan, press Ctrl-C to abort.
                        [+] Scanning for hidden items ..................................
                        [+] Scan complete.
                        [+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
                        [+] Exited on 09/12/07 at 14:36:31 (return code = 0).

                        *** Recherche avec GenericNaviSearch ***
                        !!! Tous Ces résultats peuvent révéler des fichiers légitimes !!!
                        !!! A verifier impérativement avant toute suppression manuelle !!!

                        * Scan C:\WINDOWS\system32 *

                        Fichiers trouvés :

                        Aucun Fichier trouvé !

                        Fichiers suspects :

                        Aucun Fichier suspect trouvé !

                        *** Recherche fichiers ***

                        *** Recherche cles registre ***

                        *** Module de Recherche complémentaire ***
                        (Recherche fichiers spécifiques)

                        1)Recherche fichiers connus:

                        2)Recherche Heuristique :

                        3)Recherche Certificats :

                        Certificat Egroup absent !

                        *** Analyse Terminé le 12/09/2007 à 14:37:12,19 ***
                        0
                        1. Bonjour.
                          Il n'y a aucun danger avec navilog.
                          Pour être certain que le scan est bon, refais-le en désactivant ton antivirus pendant ce temps.
                          0
                          1. J'ai desinstaller navilog1 et voila ce que m'affiche l'antivirus quand j'essaie de le reinstaller :

                            "McAfee a automatiquement empêché un programme potentiellement indésirable de se propager dans votre ordinateur.

                            Détails
                            Nom: PrcViewer

                            Plus d'informations
                            Les programmes potentiellement indésirables comprennent des logiciels espions, publicitaires et d'autres programmes qui peuvent engendrer des risques pour la sécurité et la confidentialité des données de votre ordinateur ou de vos informations personnelles. Vous les téléchargez souvent sans le vouloir avec un autre programme.

                            Processus: C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\is-JHAEG.tmp\is-38FOL.tmp
                            Nom du processus: Setup/Uninstall
                            Chemin d'accès du fichier : C:\Program Files\Navilog1\is-CPTOA.tmp

                            Si vous ne reconnaissez pas ce programme potentiellement indésirable, McAfee vous recommande de le supprimer. Si vous le reconnaissez, indiquez qu'il s'agit d'un programme autorisé et relancez le programme qui a déclenché l'alerte."

                            Je l'ai supprimer mais du coup je ne peux pas utiliser le logiciel navilog1
                            Au secour qu'est ce que je dois faire?
                            0
                            1. Bonjour,
                              Je suis perplexe et j'ai eu un message d'alerte de mon antivirus en installant navilog1 sur mon ordi.
                              Malgrès l'alerte j'ai autorisé pour que l'installation s'effectue correctement et en regardant les evenements recents je viens de voir qu'il s'agit du virus prcviewer!!!
                              Je viens de supprimer l'autorisation. Peut etre que ça a faussé le rapport, c'est vraiment étrange!!

                              Qu'en pensez vous? Merci de votre aide
                              0
                              1. Search Navipromo version 3.0.1 commencé le 12/09/2007 à 11:48:29,04

                                !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                                !!! Poster ce rapport sur le forum pour le faire analyser !!!
                                !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

                                Fix lancé depuis C:\Program Files\navilog1
                                Mise a jour le 08.09.2007 a 21h00 by IL-MAFIOSO

                                Microsoft Windows XP [version 5.1.2600]
                                Internet Explorer : 6.0.2900.2180

                                *** Recherche Programmes installes ***

                                *** Recherche dossiers dans C:\WINDOWS ***

                                *** Recherche dossiers dans C:\Program Files ***

                                *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

                                *** Recherche dossiers dans C:\Documents and Settings\Utilisateur\Application Data ***

                                *** Recherche avec BlackLight Engine/F-secure ***
                                BlackLight Engine est un produit de F-secure, pour + d'infos :
                                https://www.f-secure.com/en

                                F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
                                ======================================

                                Copyright 2005-2006 F-Secure Corporation. All rights reserved.
                                This is a beta version. It will expire on 1st of October, 2007.
                                Version information: 2.2.1064.

                                [+] Started on 09/12/07 at 11:48:35.
                                [+] Initializing ...
                                [+] Starting scan, press Ctrl-C to abort.
                                [+] Scanning for hidden items ..............................
                                [+] Scan complete.
                                [+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
                                [+] Exited on 09/12/07 at 11:50:25 (return code = 0).

                                *** Recherche avec GenericNaviSearch ***
                                !!! Tous Ces résultats peuvent révéler des fichiers légitimes !!!
                                !!! A verifier impérativement avant toute suppression manuelle !!!

                                * Scan C:\WINDOWS\system32 *

                                Fichiers trouvés :

                                Aucun Fichier trouvé !

                                Fichiers suspects :

                                Aucun Fichier suspect trouvé !

                                *** Recherche fichiers ***

                                *** Recherche cles registre ***

                                *** Module de Recherche complémentaire ***
                                (Recherche fichiers spécifiques)

                                1)Recherche fichiers connus:

                                2)Recherche Heuristique :

                                3)Recherche Certificats :

                                Certificat Egroup absent !

                                *** Analyse Terminé le 12/09/2007 à 11:51:24,25 ***
                                0
                                1. Bonsoir,
                                  Télécharge Navifix de Il-Mafioso :
                                  http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

                                  Installe-le en cliquant sur le fichier Navilog1.exe

                                  Ouvre le dossier créé dans Program files et clique sur Navilog1.bat
                                  Dans la fenêtre DOS clique sur F pour être en français et Entrée.
                                  Au menu principal suivant, choisis 1 et valide par Entrée.
                                  [b]Ne fais pas le choix 2,3 ou 4 sans mon avis.[/b]
                                  Patiente jusqu'au message : *** Analyse Termine le ..... ***
                                  Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
                                  Copie-colle l'intégralité dans ta prochaine réponse. Referme le blocnote.
                                  Il sera sauvegardé dans le dossier sous fixnavi.txt.
                                  0
                                  1. J'ai supprimé le dossier et refait le scan et prcviewer est toujours là!!
                                    0
                                    1. Bonjour.
                                      Supprime le dossier EtRemover et tout ce qu'il contient.
                                      Refais ton scan antivirus qui devrait être vierge cette fois.
                                      0
                                      1. Bonjour,

                                        J'ai suivi vos conseils et ETremover a trouvé des fichiers prcviewer. A la question "etes vous sur?" g répondu "oui" est ce que j'ai bien fait?
                                        Ensuite apres avoir redemarrer l'ordinateur, j'ai refait le scan avec mon antivirus et le virus est toujours là!

                                        Avant d'envoyer le 1er message, et en plus de mon antivirus, j'ai utilisé spybot et AVG antispyware.

                                        Et voici maintenant le nouveau rapport hijack this:

                                        Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 12:12:08, on 11/09/2007
                                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\WINDOWS\System32\smss.exe
                                        C:\WINDOWS\system32\winlogon.exe
                                        C:\WINDOWS\system32\services.exe
                                        C:\WINDOWS\system32\lsass.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\WINDOWS\system32\spoolsv.exe
                                        C:\WINDOWS\Explorer.EXE
                                        C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                                        C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
                                        C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                                        c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe
                                        C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                                        C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
                                        c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
                                        c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe
                                        C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                                        C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                                        C:\Program Files\McAfee\MPF\MPFSrv.exe
                                        C:\WINDOWS\SOINTGR.EXE
                                        C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
                                        C:\WINDOWS\vsnpstd.exe
                                        C:\Program Files\QuickTime\qttask.exe
                                        C:\WINDOWS\system32\rundll32.exe
                                        C:\WINDOWS\vsnpstd3.exe
                                        C:\Program Files\McAfee\MSK\MskAgent.exe
                                        C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
                                        C:\PROGRA~1\McAfee\MPS\mps.exe
                                        C:\WINDOWS\system32\ctfmon.exe
                                        C:\Program Files\McAfee\MSK\MskSrver.exe
                                        C:\Program Files\MSN Messenger\msnmsgr.exe
                                        C:\Program Files\SiteAdvisor\6172\SAService.exe
                                        C:\WINDOWS\system32\slserv.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\Program Files\3M\PSNLite\PsnLite.exe
                                        C:\Program Files\McAfee\MPS\mpsevh.exe
                                        C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
                                        C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
                                        C:\PROGRA~1\3M\PSNLite\PSNGive.exe
                                        C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
                                        c:\PROGRA~1\mcafee.com\agent\mcagent.exe
                                        C:\Program Files\McAfee\MSC\mcshell.exe
                                        c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
                                        C:\Program Files\Mozilla Firefox\firefox.exe
                                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://outlook.live.com/owa/
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://espanol.yahoo.com/
                                        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ar.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://ar.search.yahoo.com/
                                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
                                        O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
                                        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                        O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                                        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
                                        O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
                                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                        O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                                        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
                                        O4 - HKLM\..\Run: [SO5 Integrator Pass Two] C:\WINDOWS\SOINTGR.EXE
                                        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
                                        O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
                                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                        O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                                        O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
                                        O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
                                        O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
                                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                        O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\WANADOO\GestMaj.exe EspaceWanadoo.exe
                                        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                        O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
                                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                                        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                                        O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                                        O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
                                        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                                        O4 - Global Startup: BTTray.lnk = ?
                                        O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
                                        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                        O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
                                        O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?af24441b40c74ff3918d81da1e388cb9
                                        O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?af24441b40c74ff3918d81da1e388cb9
                                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
                                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
                                        O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
                                        O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
                                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
                                        O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
                                        O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                                        O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\FICHIE~1\McAfee\EmProxy\emproxy.exe
                                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                        O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
                                        O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
                                        O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                                        O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe
                                        O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                                        O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
                                        O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
                                        O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe
                                        O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                                        O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                                        O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
                                        O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
                                        O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
                                        O23 - Service: Service SiteAdvisor (SiteAdvisor Service) - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe
                                        O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                                        0
                                        1. Bonsoir stellalo,

                                          coche la ligne
                                          O20 - AppInit_DLLs: 58.dll

                                          fixe l'objet avec hijack this
                                          qu'as tu fais comme autres analyse mise a part celui de ton anti virus?

                                          courage

                                          la cox
                                          0
                                          • 1
                                          • 2