Infesté par navipromo

Bonjour,
je viens de faire reinstallé mon ordi et voilà que je suis déjà infecté par 2 navipromo.bqx et l'autre je ne me rappelle plus. Enfin bref j'ai pas trop les moyens de le ramener maintenant et j'aimerais vraiement le desinfecté. Quelqu'un pourrait il m'aider. D'avance merci
Configuration: Windows XP
Internet Explorer 7.0

30 réponses

Résumé de la discussion

Une personne ayant réinstallé son ordinateur se retrouve infectée par deux malwares, dont navipromo.bqx, et cherche une désinfection efficace sous Windows XP et Internet Explorer 7. Des conseils portent sur l’utilisation de l’outil Navilog avec l’option 1 puis vérification, et sur l’éventualité de lancer l’option 2 seulement après avis, afin d’éviter une désinfection invalide. D’autres évoquent des scans avec des outils comme Bitdefender ou SiSoftware Sandra, et rapportent des difficultés lorsque certains programmes ne sont pas installés, ce qui peut compliquer l’obtention d’un nettoyage complet. En cas de doute, des échanges portent aussi sur le fait que des rapports navilog doivent être copiés et partagés pour évaluer correctement les infections et adapter l’étape suivante.

Bobot (l’IA à votre service)
  1. Salut virgoginie,

    "on fait ca quand le systeme est sain" , regarde là ligne 4 Si vous désactivez la Restauration du système, tous les points de restauration précédents seront supprimés., c'est pas grave...

    ca veut dire que l'antivirus me dit qu'il n'y a pas de menace mais il y en a une quand même ? , chaque logiciel à sa spécialité : antivirus contre les virus, vers...antispywares contre spy... mais aucun ne protège à 100% (ca n'existe pas, y a tjs des failles...)

    Le problème de ton PC n'est pas viral. C'est un spyware dont il faut forcer la desinstallation.

    Si Genproc dit qu'il y a un problème, c'est qu'il y en a un. Mais la réciproque est fausse : s'il dit qu'il n'y a pas de problème, il peut se tromper.
    => Faisons un BFU...

    Sinon j'arrive pas à inscrie bfu dans la racine.,
    Alors on va faire autrement :
    > Télécharge sur ton bureau (si c'est pas déjà fait) : Brute Force Uninstaller (= le programme) et le script bfu suivant : http://perso.orange.fr/Chercheur-perso/scripts/toolbar.bfu
    NB : pour télécharger le script toolbar.bfu (de Chercheur), clique droit sur le lien ci-dessus et choisis < Entregistrer la cible sous > ou quelque chose comme ça (Enregistrer la cible du lien sous, enregistrer sous...), puis enregistre le script sur le bureau.

    > Tu te retrouves avec : bfu (un fichier zip = une archive) et toolbar.bfu (un script bfu) sur le bureau.

    > Dezippe l'archive, pour celà clique droit dessus et choisis 'extraire ici' ou 'extraire vers..bureau'.
    Tu peux aussi ouvrir l'archive (double clic gauche) puis faire qlisser le fichier BFU.exe qu'elle contient sur ton bureau.
    NB : Si tu ne peux pas ouvrir l'archive c'est qu'il te manque un programme (winzip, winare..). Tu peux télécharger Izarc

    > Bon, sur ton bureau tu as donc bfu.exe (un programme) et toolbar.bfu (un script bfu)

    > Tu crée un nouveau dossier appelé BFU (clic droit sur le bureau => Nouveau dossier)

    > Tu mets les deux fichiers bfu.exe et toolbar.bfu dans le dossier BFU

    > Deplace ce dossier (Clic droit sur le dossier => couper) à la racine de C:/. Pour cela tu vas dans poste de travail puis double clique sur c:. Dans C:/ clique droit, puis choisis 'coller'. Le dossier BFU doit donc apparaître dans C:/. ( C:/BFU/ )

    > Maintenant le dossier est bien placé, tu peux continuer la procédure du poste 57.

    Oup's je dois être blonde,
    lol. Je pense pas que la couleur de tes cheveux soient la cause, mais bon sinon y a ça
    lol.

    Bon j'espère que ça va marcher...

    A+
    --
    0
    1. j'ai coché la case desactivé la restauration systeme,
      On fait ça quand le système est sain....

      Peux tu refaires la manip. en utilisant le lien du poste 72 ?
      0
      1. "on fait ca quand le systeme est sain" ca veut dire que l'antivirus me dit qu'il n'y a pas de menace mais il y en a une quand même ?
        Sinon j'arrive pas à inscrie bfu dans la racine. Je ne comprend pas cette manip. Oup's je dois être blonde. Dsl
        0
    2. OK,

      c'est bon là c'est sûr :

      http://perso.orange.fr/Chercheur-perso/scripts/toolbar.bfu

      Sinon aller cliquer droit, puis enregistrer la cible sous.. sur le lien du poste 48.
      0
      1. Contributeur sécurité
        ca marche!!
        0
    3. Non OK,
      Je vois...en effet ça marche pas...
      Avec Firefox, ca va...
      Je regarde si c'est possible depuis IE...
      --
      0
      1. Si ca marche sous IE...

        Faut insister (comme quoi IE..) : le premier ça foire (si rien arrive au bout de 2-3 sec.), faut fermer la fenêtre.
        Juste après ça marche..
        non ?
        --
        0
        1. ok j'essaie, mais j'ai coché la case desactivé la restauration systeme puis j'ai laissé faire - redemarrer - fait un scan avec bitdefender et là il ne ma rien trouvé mais je trouve que l'ordi est bizzare. Là la case est décoché ais-je fait une betise
          0
      2. Mrd..
        Et sous fox ? (CLIC DROIT hein ???)
        --
        0
        1. Contributeur sécurité
          je n'ai pas fox!
          0
        2. @jfkpresidentAlors retour au poste 60,
          lol
          --
          0
      3. Contributeur sécurité
        sous IE "page introuvable"!!
        0
        1. Si ca marche pas alors installe firefox,

          Je te conseille dans faire ton navigateur par defaut....regarde là (en rouge!)
          --
          0
          1. Contributeur sécurité
            salut a vous deux
            pour DllD :obligation d'installer firefox?
            0
          2. @jfkpresidentSalut jfk,

            Bin non, mais IE merde souvent...
            Si t'as IE est ce que t'as essayé ? chez toi ça marche ?
            0
          3. Contributeur sécurité
            @Utilisateur anonymepour brute force ca marche par contre pour ca:http://perso.orange.fr/Chercheur-perso/scripts/toolbar.bfu.
            "PAGE INTROUVABLE"
            0
          4. @jfkpresidentsous quoi IE ou firefox ?

            Et, tu fais bien un clic droit puis enregistrer la cible sous ?
            0
        2. Re,

          > Télécharge sur ton bureau : Brute Force Uninstaller (= le programme) et le script bfu suivant : http://perso.orange.fr/Chercheur-perso/scripts/toolbar.bfu.
          NB : pour télécharger le script toolbar.bfu (de Chercheur), clique droit sur le lien ci-dessus et choisis < Entregistrer la cible sous > ou quelque chose comme ça (Enregistrer la cible du lien sous, enregistrer sous...), puis enregistre le script sur le bureau.
          0
          1. je n'arrive pas à télécharger le script. orange me dit que l'adresse est fausse ce qui fait que quand je télécharge bfu je n'ai pas la toolbar.bfu donc ne peut pas faire le programme en mode sans echec. Maintenant 6 files contaminé. Jusqu'au ca va aller ?
            0
        3. Bon bah voilà....
          0
          1. Contributeur sécurité
            coucou MP
            0
          2. oui, plus de mail, je suis obligés de passer par ootlook express sinon je ne vois pas ce que vous me répondez
            0
          3. @virgoginieRe,
            tu passais par quoi avant pour les mails ? (web, msn ?)
            --
            0
          4. @Utilisateur anonymej'ai résolue mon problème de messagerie mais pas celui de 'navipromo'
            0
          5. @virgoginieOK, je vais t'envoyer une recette pour forcer la désinstallation de la crasse cet PM
            0
        4. Re,
          JFK, si t'es encore là....

          > Essaye d'installer Antivir : ouvre ce lien, lis le tuto, télécharge Antivir.
          Tu peux aussi télecharger Antivir ICI.

          > télécharge GenProc http://www.alt-shift-return.org/Info/Fichiers/GenProc.zip sur ton bureau
          0
          1. Contributeur sécurité
            je suis encore la .
            fais ce que te dit dlld post 45 et je jetterai un coup d'oeil sur les rapports;
            0
          2. re, je n'ai plus accés à ma messagerie mais je vous envoie le rapport antivir

            AntiVir PersonalEdition Classic
            Report file date: mercredi 12 décembre 2007 17:02

            Scanning for 971385 virus strains and unwanted programs.

            Licensed to: Avira AntiVir PersonalEdition Classic
            Serial number: 0000149996-ADJIE-0001
            Platform: Windows XP
            Windows version: (Service Pack 2) [5.1.2600]
            Username: SYSTEM
            Computer name: PCBUREAU

            Version information:
            BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
            AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
            AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
            LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
            LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
            ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
            ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 14:26:55
            ANTIVIR2.VDF : 7.0.1.30 1575424 Bytes 30/11/2007 16:00:48
            ANTIVIR3.VDF : 7.0.1.80 214528 Bytes 12/12/2007 16:00:48
            AVEWIN32.DLL : 7.6.0.40 3064320 Bytes 12/12/2007 16:00:49
            AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
            AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
            AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
            AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 08:46:00
            AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
            AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
            AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
            NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
            RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
            RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
            SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

            Configuration settings for the scan:
            Jobname..........................: Complete system scan
            Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
            Logging..........................: low
            Primary action...................: interactive
            Secondary action.................: ignore
            Scan master boot sector..........: off
            Scan boot sector.................: on
            Boot sectors.....................: C:,
            Scan memory......................: on
            Process scan.....................: on
            Scan registry....................: on
            Search for rootkits..............: off
            Scan all files...................: Intelligent file selection
            Scan archives....................: on
            Recursion depth..................: 20
            Smart extensions.................: on
            Macro heuristic..................: on
            File heuristic...................: medium

            Start of the scan: mercredi 12 décembre 2007 17:02

            The scan of running processes will be started
            Scan process 'avscan.exe' - '1' Module(s) have been scanned
            Scan process 'avcenter.exe' - '1' Module(s) have been scanned
            Scan process 'sched.exe' - '1' Module(s) have been scanned
            Scan process 'avgnt.exe' - '1' Module(s) have been scanned
            Scan process 'avguard.exe' - '1' Module(s) have been scanned
            Scan process 'iexplore.exe' - '1' Module(s) have been scanned
            Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
            Scan process 'emule.exe' - '1' Module(s) have been scanned
            Scan process 'Watch.exe' - '1' Module(s) have been scanned
            Scan process 'ALERTM~1.EXE' - '1' Module(s) have been scanned
            Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
            Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
            Scan process 'Toaster.exe' - '1' Module(s) have been scanned
            Scan process 'ComComp.exe' - '1' Module(s) have been scanned
            Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
            Scan process 'NMIndexStoreSvr.exe' - '1' Module(s) have been scanned
            Scan process 'alg.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '0' Module(s) have been scanned
            Scan process 'NMIndexingService.exe' - '1' Module(s) have been scanned
            Scan process 'GoogleUpdater.exe' - '1' Module(s) have been scanned
            Scan process 'BTTray.exe' - '1' Module(s) have been scanned
            Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
            Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
            Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
            Scan process 'NMBgMonitor.exe' - '1' Module(s) have been scanned
            Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
            Scan process 'zlclient.exe' - '0' Module(s) have been scanned
            Scan process 'bdagent.exe' - '1' Module(s) have been scanned
            Scan process 'avgas.exe' - '1' Module(s) have been scanned
            Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
            Scan process 'rundll32.exe' - '1' Module(s) have been scanned
            Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
            Scan process 'livesrv.exe' - '0' Module(s) have been scanned
            Scan process 'vsserv.exe' - '0' Module(s) have been scanned
            Scan process 'xcommsvr.exe' - '0' Module(s) have been scanned
            Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
            Scan process 'SDTrayApp.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'explorer.exe' - '1' Module(s) have been scanned
            Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
            Scan process 'swdsvc.exe' - '1' Module(s) have been scanned
            Scan process 'svcntaux.exe' - '1' Module(s) have been scanned
            Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
            Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
            Scan process 'guard.exe' - '0' Module(s) have been scanned
            Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
            Scan process 'vsmon.exe' - '0' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'btwdins.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'MsMpEng.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
            Scan process 'lsass.exe' - '1' Module(s) have been scanned
            Scan process 'services.exe' - '1' Module(s) have been scanned
            Scan process 'winlogon.exe' - '1' Module(s) have been scanned
            Scan process 'csrss.exe' - '1' Module(s) have been scanned
            Scan process 'smss.exe' - '1' Module(s) have been scanned
            53 processes with 53 modules were scanned

            Start scanning boot sectors:
            Boot sector 'C:\'
            [NOTE] No virus was found!

            Starting to scan the registry.
            The registry was scanned ( '29' files ).

            Starting the file scan:

            Begin scan in 'C:\'
            C:\pagefile.sys
            [WARNING] The file could not be opened!
            C:\Program Files\Navilog1\Backupnavi\ognvfnfmue.exe
            [DETECTION] Is the Trojan horse TR/Dropper.Gen
            [INFO] The file was deleted!
            C:\System Volume Information\_restore{09B1298D-ED77-4BB7-A8E9-8BCE24EA457C}\RP39\A0006949.exe
            [DETECTION] Is the Trojan horse TR/Dropper.Gen
            [INFO] The file was moved to '47900c87.qua'!
            C:\System Volume Information\_restore{09B1298D-ED77-4BB7-A8E9-8BCE24EA457C}\RP55\A0010866.exe
            [DETECTION] Is the Trojan horse TR/Dropper.Gen
            [INFO] The file was moved to '47900d1f.qua'!

            End of the scan: mercredi 12 décembre 2007 18:03
            Used time: 1:00:44 min

            The scan has been done completely.

            2703 Scanning directories
            60445 Files were scanned
            3 viruses and/or unwanted programs were found
            0 Files were classified as suspicious:
            1 files were deleted
            0 files were repaired
            2 files were moved to quarantine
            0 files were renamed
            1 Files cannot be scanned
            60442 Files not concerned
            852 Archives were scanned
            1 Warnings
            1 Notes
            0
          3. et voici lRapport GenProc 0.72 [1] effectué le 12/12/2007 à 18:11:18,31 - SystemRoot = C:\WINDOWS

            Dans CCleaner, clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. C'est tout.

            # Etape 1/ Télécharge :

            - Brute Force Uninstaller http://www.merijn.org/files/bfu.zip et décompresse-le dans un dossier propre à lui (C:\BFU)
            * Fais un clic droit de souris sur ce lien : http://perso.orange.fr/Chercheur-perso/scripts/toolbar.bfu
            et choisis "Enregistrer sous" (dans IE c'est "Enregistrer le lien sous..")
            afin de télécharger toolbar.bfu (de Chercheur), Type "Tous les fichiers". Sauvegarde dans le dossier créé (C:\BFU)

            ***** Copie ce qui suit dans un fichier texte et redémarre en mode sans échec comme indiqué ici https://docs.microsoft.com/en-us/?mfr=true (choisis ta session courante "laurence") *****

            # Etape 2/

            * Démarre le "Brute Force Uninstaller" en double-cliquant sur BFU.exe.
            Clique sur le petit dossier jaune, à la droite de la boîte "Scriptline to execute", et double-clique sur : Toolbar.bfu
            - Dans la boîte "Scriptline to execute", tu devrais maintenant voir ceci : C:\BFU\Toolbar.bfu
            Clique sur "Execute" et laisse-le faire son travail.
            Attendre que "Complete script execution" apparaîsse et clique sur OK. Clique exit pour fermer le programme BFU.
            Recommence encore une fois.

            # Etape 3/

            Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.

            # Etape 4/

            Redémarre normalement et poste :
            - Un nouveau rapport HijackThis, toutes fenêtres et applications fermées http://www.trendsecure.com/portal/en-US/threat_analytics/HiJackThis.exe ;

            Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
            e rapport genproc
            0
          4. @virgoginieje n'ai rien compris à ce dernier message. N'empêche que je n'ai plus accés à ma messagerie. Je suis en panique,
            0
        5. Bonsoir,
          comment se comporte le PC?
          A+
          --
          0
          1. bonjour,
            il y a un leger mieux mais bitdefender me dit que maintenant il y 5 fichiers infestés par navipromo.
            0
        6. Re,

          pour info
          0
          1. bonjour et encore merci pour ton aide je ne faire que ceci, mais bon voici mon rapport hijackthis après avoir suivie toutes tes consignes
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 10:51:39, on 11/12/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16544)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Defender\MsMpEng.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
            C:\WINDOWS\System32\FTRTSVC.exe
            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            C:\Program Files\Spyware Doctor\svcntaux.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Spyware Doctor\swdsvc.exe
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\WINDOWS\system32\RunDll32.exe
            C:\Program Files\Spyware Doctor\SDTrayApp.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe
            C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
            C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
            C:\WINDOWS\system32\svchost.exe
            C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
            C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\WINDOWS\system32\wdfmgr.exe
            C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
            C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
            C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
            C:\Program Files\Google\Google Updater\GoogleUpdater.exe
            C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
            C:\PROGRA~1\Wanadoo\ComComp.exe
            C:\PROGRA~1\Wanadoo\Toaster.exe
            C:\PROGRA~1\Wanadoo\Inactivity.exe
            C:\PROGRA~1\Wanadoo\PollingModule.exe
            C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
            C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
            C:\WINDOWS\System32\alg.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\PROGRA~1\Wanadoo\Watch.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
            O2 - BHO: (no name) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
            O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
            O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
            O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
            O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe" /minimized
            O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
            O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
            O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: AVG Anti-Spyware 7.5
            O4 - Global Startup: BTTray.lnk = ?
            O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
            O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
            O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
            O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
            O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
            O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
            O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\Win32\RpcDataSrv.exe
            O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\RpcSandraSrv.exe
            O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
            O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
            O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
            0
        7. En effet mais l'ordi semble sain,
          0
          1. oui, toujours - analyser avec bitdefender
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 22:53:29, on 10/12/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16544)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Defender\MsMpEng.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
            C:\WINDOWS\System32\FTRTSVC.exe
            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            C:\Program Files\Spyware Doctor\svcntaux.exe
            C:\Program Files\Spyware Doctor\swdsvc.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\wdfmgr.exe
            C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
            C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\alg.exe
            C:\Program Files\Spyware Doctor\SDTrayApp.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\WINDOWS\system32\RunDll32.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe
            C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
            C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
            C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
            C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
            C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
            C:\Program Files\Google\Google Updater\GoogleUpdater.exe
            C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
            C:\PROGRA~1\Wanadoo\ComComp.exe
            C:\PROGRA~1\Wanadoo\Toaster.exe
            C:\PROGRA~1\Wanadoo\Inactivity.exe
            C:\PROGRA~1\Wanadoo\PollingModule.exe
            C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
            C:\PROGRA~1\Wanadoo\Watch.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\WINDOWS\system32\msiexec.exe
            C:\Program Files\Windows Live\installer\WLSetupSvc.exe
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
            R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
            R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
            O2 - BHO: (no name) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O3 - Toolbar: (no name) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - (no file)
            O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
            O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
            O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
            O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
            O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
            O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe" /minimized
            O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
            O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
            O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: AVG Anti-Spyware 7.5
            O4 - Global Startup: BTTray.lnk = ?
            O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
            O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
            O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
            O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
            O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
            O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
            O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\Win32\RpcDataSrv.exe
            O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\RpcSandraSrv.exe
            O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
            O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
            O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
            0
        8. Contributeur sécurité
          une fois de plus pas tres bavard ce rapport
          0
          1. Bonsoir, bonsoir.....

            peux-tu refaire le poste 2 stp.

            télécharge navilog:http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
            fais l'option 1 puis copie/colle ton rapport ici
            ne fais pas l'option 2 sans avis!
            0
            1. Search Navipromo version 3.3.6 commencé le 10/12/2007 à 22:13:24,59

              !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
              !!! Postez ce rapport sur le forum pour le faire analyser !!!
              !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

              Outil exécuté depuis C:\Program Files\navilog1
              Mise à jour le 14.11.2007 à 18h00 par IL-MAFIOSO

              Microsoft Windows XP [version 5.1.2600]
              Internet Explorer : 7.0.5730.13

              *** Recherche Programmes installés ***

              *** Recherche dossiers dans C:\WINDOWS ***

              *** Recherche dossiers dans C:\Program Files ***

              *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

              *** Recherche dossiers dans C:\Documents and Settings\laurence\Application Data ***

              *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

              *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
              pour + d'infos : http://www.gmer.net

              Aucun fichier trouvé dans :

              - C:\WINDOWS\system32
              - C:\DOCUME~1\LAURENCE\LOCALS~1\APPLIC~1

              *** Recherche avec GenericNaviSearch ***
              !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
              !!! A vérifier impérativement avant toute suppression manuelle !!!

              * Recherche dans C:\WINDOWS\system32 *

              Fichiers suspects :

              * Recherche dans C:\DOCUME~1\LAURENCE\LOCALS~1\APPLIC~1 *

              *** Recherche fichiers ***

              *** Recherche clés spécifiques dans le Registre ***

              *** Module de Recherche complémentaire ***
              (Recherche fichiers spécifiques)

              1)Recherche fichiers connus:

              2)Recherche Heuristique :

              3)Recherche Certificats :

              Certificat Egroup absent !

              *** Analyse terminée le 10/12/2007 à 22:14:44,14 ***
              0
          2. Contributeur sécurité
            virustotal tres bien pour analyser des fichiers précis
            0
            1. jfkpresident,

              je trouve le deuxième rappot navilog pas très bavard...
              On pourrait recommancer l'étape de détection (1), qu'en penses-tu ?
              0
            2. @Utilisateur anonymedesolé, obligé de reprendre mes occupation de maman, je reviens lundi soir pour voir si vous voulez bien encore m'aider. Merci pour votre patience et gentillesse a lundi si vous le voulez bien donc
              0
            3. Contributeur sécurité
              @Utilisateur anonymece serait préférable effectivement
              0
          3. virgoginie,

            Peux-tu te rendre sur ce site virustotal ou virusscan.jotti et faire analyser les fichiers suivants (s'ils existent encore) :
            0
            1. J'ai un peu du mal avec ces programmes et je n'arrive pas a vous envoyer le rapport mais quand je scan msn messenger il apparait que fileAdvisor Low threat detected
              0
            2. @virgoginieOk pour les fichiers où il met 'no found' ou rien, n'envoie pas de rapport.

              Pour les autres (attends bien qu'il est terminé l'analyse) :
              puis :
              0
          4. Contributeur sécurité
            merci a toi dlld j'ai besoin d'etre épaulé des fois que!
            virgoginie:option 2 (desinfection auto)puis poste le rapport obtenu
            1
            1. Voici donc le rapport de navilog que jfkpresident m'a demandé et merci de votre aide j'espère que je me sortirai de ce virus. Sinon il y a un site 000favorit qui propose un logiciel de desinstalllation de navipromo. Qu'en pensez vous ?

              *** fsbl1.txt non trouvé ***
              (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

              *** Suppression avec sauvegardes résultats GenericNaviSearch ***

              * Suppression dans C:\WINDOWS\System32 *

              * Suppression dans C:\DOCUME~1\LAURENCE\LOCALS~1\APPLIC~1 *

              *** Suppression dossiers dans C:\WINDOWS ***

              *** Suppression dossiers dans C:\Program Files ***

              *** Suppression dossiers dans C:\Documents and Settings\All Users\Application Data ***

              *** Suppression dossiers dans C:\Documents and Settings\laurence\Application Data ***

              *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

              *** Suppression fichiers ***

              *** Suppression fichiers temporaires ***

              Nettoyage contenu C:\WINDOWS\Temp effectué !
              Nettoyage contenu C:\Documents and Settings\laurence\Local Settings\Temp effectué !

              *** Traitement Recherche complémentaire ***
              (Recherche fichiers spécifiques)

              1)Recherche fichiers connus:

              2)Recherche, création sauvegardes et suppression Heuristique :

              *** Sauvegarde du Registre vers dossier Backupnavi ***

              sauvegarde du Registre réalisé avec succès !

              *** Nettoyage Registre ***

              Nettoyage Registre Ok

              *** Certificats ***

              Certificat Egroup absent !

              *** Fichiers suspects non supprimés par Navilog1 ***
              !! Fichiers légitimes possibles, à contrôler avant suppression !!

              *** Nettoyage terminé le 08/12/2007 à 11:36:50,23 ***
              0
            2. Re,

              elle est bien infectée...

              Sinon il y a un site 000favorit qui propose un logiciel de desinstalllation de navipromo. Qu'en pensez vous ?
              Il existe de multiples façons de ce débarasser de cette crasse mais je suis au regret de te dire que tu n'as pas que ça....
              0
          • 1
          • 2