Ouverture intempestives sur firefox

Résolu
Bonjour,
J'ai un souci depuis quelques temps.
J'utilise mozzilla firefox comme navigateur et j'ai constemment des fenetres de pub qui s'ouvre de maniere intempestives. j'ai fais pas mal de nettoyage mais rien n'y fait. mon ordi est un pentium 4 2.8Mghz avec 512 de ram. je fonctionne sous windows xp.je vous joint un hicjackthis en esperant que quelqu'un pourra m'aider a resoudre ce probleme...
Merci d'avance
Krazy1

Logfile of HijackThis v1.99.1
Scan saved at 20:43:04, on 19/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\atwtusb.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\yz dock 0.8.3 French English Japan German Spanish + 37 Docklets\YzDock.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\WINDOWS\system32\TBLMOUSE.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Windows\System32\wsaupdater.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Raccourci vers YzDock.lnk = C:\Program Files\yz dock 0.8.3 French English Japan German Spanish + 37 Docklets\YzDock.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {317153FE-B7FB-419B-AC87-0B2EC97D7A04} (VB2S ActiveX Control) - http://www.subdo.com/activex/vb2s.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - https://driveragent.com/files/driveragent.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: CleanService - Unknown owner - C:\Program Files\StompSoft\Digital File Shredder Pro\CleanService.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe
O23 - Service: Steganos Live Encryption Engine 8.1 [Service] (SLEE_81_SERVICE) - Unknown owner - C:\WINDOWS\system32\SLEE81.exe (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Configuration: Windows XP
Firefox 2.0.0.9

15 réponses

  1. Contributeur sécurité
    bonne continuation!
    0
    1. Merci pour le temps que tu m'a consacré...
      Bye
      krazy
      0
      1. Contributeur sécurité
        oui antivir est mieux actuellement
        0
        1. ok c'est fait...ca a l'air d'aller...
          Merci pour l'aide !
          visiblement antivir a l'air plus performant qu'avast...?!?
          0
          1. Contributeur sécurité
            fix cette ligne

            O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

            _____________

            desisntalle navilog

            si pas de problemes c'est bon

            pour protéger gratos ton ordi

            http://www.commentcamarche.net/telecharger/logiciel 4 securite

            mettre un antivirus

            AVAST en français ou ANTIVIR (en anglais mais très efficace)
            https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
            -------------
            des anti-espions :
            AD AWARE + SPYBOT + si tea timer non active de spybot: WINDOWS DEFENDER ou SPYWARE TERMINATOR

            +/-
            SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

            Rq : spybot et ad-aware on sorti de nouvelles versions cette année vérifiez que vous avez la dernière version
            --------
            un pare feu :
            celui de Windows ou mieux KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)

            https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
            https://manuelsdaide.com/contact/
            http://www.open-files.com/forum/index.php?showtopic=29277
            http://www.commentcamarche.net/telecharger/telecharger 157 zonealarm

            -----------

            CCLEANER pour effacer les traces de surf
            0
            1. voici les rapports :

              AntiVir PersonalEdition Classic
              Report file date: mercredi 26 décembre 2007 19:09

              Scanning for 992538 virus strains and unwanted programs.

              Licensed to: Avira AntiVir PersonalEdition Classic
              Serial number: 0000149996-ADJIE-0001
              Platform: Windows XP
              Windows version: (Service Pack 2) [5.1.2600]
              Username: SYSTEM
              Computer name: KRAZY-PCSSD3UIO

              Version information:
              BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
              AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
              AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
              LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
              LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
              ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
              ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 16:28:12
              ANTIVIR2.VDF : 7.0.1.96 2048 Bytes 14/12/2007 16:28:12
              ANTIVIR3.VDF : 7.0.1.156 284672 Bytes 26/12/2007 16:28:12
              AVEWIN32.DLL : 7.6.0.46 3084800 Bytes 26/12/2007 16:28:13
              AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
              AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
              AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
              AVPACK32.DLL : 7.6.0.2 360488 Bytes 26/12/2007 16:28:13
              AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
              AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
              AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
              NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
              RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
              RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
              SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

              Configuration settings for the scan:
              Jobname..........................: Complete system scan
              Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
              Logging..........................: low
              Primary action...................: interactive
              Secondary action.................: ignore
              Scan master boot sector..........: off
              Scan boot sector.................: on
              Boot sectors.....................: I:,
              Scan memory......................: on
              Process scan.....................: on
              Scan registry....................: on
              Search for rootkits..............: off
              Scan all files...................: Intelligent file selection
              Scan archives....................: on
              Recursion depth..................: 20
              Smart extensions.................: on
              Macro heuristic..................: on
              File heuristic...................: medium

              Start of the scan: mercredi 26 décembre 2007 19:09

              The scan of running processes will be started
              Scan process 'avscan.exe' - '1' Module(s) have been scanned
              Scan process 'avcenter.exe' - '1' Module(s) have been scanned
              Scan process 'msimn.exe' - '1' Module(s) have been scanned
              Scan process 'CLI.exe' - '1' Module(s) have been scanned
              Scan process 'CLI.exe' - '1' Module(s) have been scanned
              Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
              Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
              Scan process 'alg.exe' - '1' Module(s) have been scanned
              Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
              Scan process 'YzDock.exe' - '1' Module(s) have been scanned
              Scan process 'rapimgr.exe' - '1' Module(s) have been scanned
              Scan process 'wcescomm.exe' - '1' Module(s) have been scanned
              Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
              Scan process 'avgnt.exe' - '1' Module(s) have been scanned
              Scan process 'jusched.exe' - '1' Module(s) have been scanned
              Scan process 'CLI.exe' - '1' Module(s) have been scanned
              Scan process 'SMax4.exe' - '1' Module(s) have been scanned
              Scan process 'SMax4PNP.exe' - '1' Module(s) have been scanned
              Scan process 'svchost.exe' - '1' Module(s) have been scanned
              Scan process 'SMAgent.exe' - '1' Module(s) have been scanned
              Scan process 'sched.exe' - '1' Module(s) have been scanned
              Scan process 'a2service.exe' - '1' Module(s) have been scanned
              Scan process 'explorer.exe' - '1' Module(s) have been scanned
              Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
              Scan process 'avguard.exe' - '1' Module(s) have been scanned
              Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
              Scan process 'svchost.exe' - '1' Module(s) have been scanned
              Scan process 'svchost.exe' - '1' Module(s) have been scanned
              Scan process 'svchost.exe' - '1' Module(s) have been scanned
              Scan process 'svchost.exe' - '1' Module(s) have been scanned
              Scan process 'svchost.exe' - '1' Module(s) have been scanned
              Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
              Scan process 'lsass.exe' - '1' Module(s) have been scanned
              Scan process 'services.exe' - '1' Module(s) have been scanned
              Scan process 'winlogon.exe' - '1' Module(s) have been scanned
              Scan process 'csrss.exe' - '1' Module(s) have been scanned
              Scan process 'smss.exe' - '1' Module(s) have been scanned
              37 processes with 37 modules were scanned

              Start scanning boot sectors:
              Boot sector 'C:\'
              [NOTE] No virus was found!
              Boot sector 'D:\'
              [NOTE] No virus was found!
              Boot sector 'I:\'
              [NOTE] No virus was found!

              Starting to scan the registry.
              The registry was scanned ( '34' files ).

              Starting the file scan:

              Begin scan in 'C:\'
              C:\pagefile.sys
              [WARNING] The file could not be opened!
              Begin scan in 'D:\' <D>
              Begin scan in 'I:\' <I>

              End of the scan: mercredi 26 décembre 2007 20:08
              Used time: 59:47 min

              The scan has been done completely.

              7940 Scanning directories
              342571 Files were scanned
              0 viruses and/or unwanted programs were found
              0 Files were classified as suspicious:
              0 files were deleted
              0 files were repaired
              0 files were moved to quarantine
              0 files were renamed
              1 Files cannot be scanned
              342571 Files not concerned
              2223 Archives were scanned
              1 Warnings
              0 Notes

              hijackthis :

              Logfile of HijackThis v1.99.1
              Scan saved at 20:19:18, on 26/12/2007
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16574)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\a-squared Free\a2service.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
              C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
              C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
              C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
              C:\PROGRA~1\MICROS~3\rapimgr.exe
              C:\Program Files\yz dock 0.8.3 French English Japan German Spanish + 37 Docklets\YzDock.exe
              C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
              C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avscan.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
              C:\Program Files\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Windows\System32\wsaupdater.exe,
              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
              O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
              O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
              O4 - Startup: Raccourci vers YzDock.lnk = C:\Program Files\yz dock 0.8.3 French English Japan German Spanish + 37 Docklets\YzDock.exe
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
              O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
              O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
              O11 - Options group: [INTERNATIONAL] International*
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
              O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
              O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
              O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
              O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
              O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
              O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
              O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              0
              1. Contributeur sécurité
                ok

                vide ce qui est en quarantaine dans antivir,

                _______________

                désactive la restauration système pour purger les virus qui seraient dedans
                puis redemarre
                puis réactive là (dans DEMARRER puis TOUS LES PROGRAMMES puis ACCESSOIRE puis OUTILS SYSTEME puis RESTAURATION SYSTEME puis paramètre)

                ______________

                recolle un scan antivir et hijackthis et dis tes soucis actuels

                a plus
                0
                1. voici le rapport de sacn avec antivir :

                  AntiVir PersonalEdition Classic
                  Report file date: mercredi 26 décembre 2007 17:30

                  Scanning for 992538 virus strains and unwanted programs.

                  Licensed to: Avira AntiVir PersonalEdition Classic
                  Serial number: 0000149996-ADJIE-0001
                  Platform: Windows XP
                  Windows version: (Service Pack 2) [5.1.2600]
                  Username: krazy
                  Computer name: KRAZY-PCSSD3UIO

                  Version information:
                  BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                  AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
                  AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
                  LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
                  LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
                  ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
                  ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 16:28:12
                  ANTIVIR2.VDF : 7.0.1.96 2048 Bytes 14/12/2007 16:28:12
                  ANTIVIR3.VDF : 7.0.1.156 284672 Bytes 26/12/2007 16:28:12
                  AVEWIN32.DLL : 7.6.0.46 3084800 Bytes 26/12/2007 16:28:13
                  AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
                  AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
                  AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                  AVPACK32.DLL : 7.6.0.2 360488 Bytes 26/12/2007 16:28:13
                  AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
                  AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
                  AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
                  NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
                  RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
                  RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
                  SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

                  Configuration settings for the scan:
                  Jobname..........................: Local Drives
                  Configuration file...............: c:\program files\avira\antivir personaledition classic\alldrives.avp
                  Logging..........................: low
                  Primary action...................: interactive
                  Secondary action.................: ignore
                  Scan master boot sector..........: off
                  Scan boot sector.................: on
                  Boot sectors.....................: H:,
                  Scan memory......................: on
                  Process scan.....................: on
                  Scan registry....................: on
                  Search for rootkits..............: off
                  Scan all files...................: Intelligent file selection
                  Scan archives....................: on
                  Recursion depth..................: 20
                  Smart extensions.................: on
                  Macro heuristic..................: on
                  File heuristic...................: medium

                  Start of the scan: mercredi 26 décembre 2007 17:30

                  The scan of running processes will be started
                  Scan process 'avscan.exe' - '1' Module(s) have been scanned
                  Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                  Scan process 'sched.exe' - '1' Module(s) have been scanned
                  Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                  Scan process 'avguard.exe' - '1' Module(s) have been scanned
                  Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                  Scan process 'CLI.exe' - '1' Module(s) have been scanned
                  Scan process 'CLI.exe' - '1' Module(s) have been scanned
                  Scan process 'alg.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'rapimgr.exe' - '1' Module(s) have been scanned
                  Scan process 'SMAgent.exe' - '1' Module(s) have been scanned
                  Scan process 'YzDock.exe' - '1' Module(s) have been scanned
                  Scan process 'wcescomm.exe' - '1' Module(s) have been scanned
                  Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                  Scan process 'jusched.exe' - '1' Module(s) have been scanned
                  Scan process 'CLI.exe' - '1' Module(s) have been scanned
                  Scan process 'SMax4.exe' - '1' Module(s) have been scanned
                  Scan process 'SMax4PNP.exe' - '1' Module(s) have been scanned
                  Scan process 'a2service.exe' - '1' Module(s) have been scanned
                  Scan process 'explorer.exe' - '1' Module(s) have been scanned
                  Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                  Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                  Scan process 'lsass.exe' - '1' Module(s) have been scanned
                  Scan process 'services.exe' - '1' Module(s) have been scanned
                  Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                  Scan process 'csrss.exe' - '1' Module(s) have been scanned
                  Scan process 'smss.exe' - '1' Module(s) have been scanned
                  34 processes with 34 modules were scanned

                  Start scanning boot sectors:
                  Boot sector 'C:\'
                  [NOTE] No virus was found!
                  Boot sector 'D:\'
                  [NOTE] No virus was found!
                  Boot sector 'I:\'
                  [NOTE] No virus was found!
                  Boot sector 'A:\'
                  [NOTE] In the drive 'A:\' no data medium is inserted!

                  Starting to scan the registry.
                  The registry was scanned ( '35' files ).

                  Starting the file scan:

                  Begin scan in 'C:\'
                  C:\pagefile.sys
                  [WARNING] The file could not be opened!
                  C:\Program Files\Panda Security\NanoScan\Engine\psnflg.dll
                  [DETECTION] Is the Trojan horse TR/Agent.bux.1
                  [INFO] The file was moved to '47e08874.qua'!
                  C:\Program Files\WinISO\WinISO.exe
                  [DETECTION] Is the Trojan horse TR/Crypt.U.Gen
                  [INFO] The file was moved to '47e088fc.qua'!
                  C:\System Volume Information\_restore{FDDE16BD-C162-4CC9-AE82-290E08D1A9D0}\RP2\A0001350.dll
                  [DETECTION] Is the Trojan horse TR/Agent.bux.1
                  [INFO] The file was moved to '47a28965.qua'!
                  C:\System Volume Information\_restore{FDDE16BD-C162-4CC9-AE82-290E08D1A9D0}\RP2\A0001351.exe
                  [DETECTION] Is the Trojan horse TR/Crypt.U.Gen
                  [INFO] The file was moved to '47a2896c.qua'!
                  Begin scan in 'D:\' <D>
                  Begin scan in 'I:\' <I>
                  Begin scan in 'A:\'
                  Search path A:\ could not be opened!
                  Le volume ne contient pas de système de fichiers connu. Vérifiez si tous les pilotes de système
                  de fichiers nécessaires sont chargés et si le volume n'est pas endommagé.

                  Begin scan in 'E:\'
                  Search path E:\ could not be opened!
                  Le périphérique n'est pas prêt.

                  Begin scan in 'F:\'
                  Search path F:\ could not be opened!
                  Le périphérique n'est pas prêt.

                  Begin scan in 'H:\'
                  Search path H:\ could not be opened!
                  Le périphérique n'est pas prêt.

                  End of the scan: mercredi 26 décembre 2007 18:29
                  Used time: 59:16 min

                  The scan has been done completely.

                  7953 Scanning directories
                  343038 Files were scanned
                  4 viruses and/or unwanted programs were found
                  0 Files were classified as suspicious:
                  0 files were deleted
                  0 files were repaired
                  4 files were moved to quarantine
                  0 files were renamed
                  1 Files cannot be scanned
                  343034 Files not concerned
                  2221 Archives were scanned
                  1 Warnings
                  0 Notes
                  0
                  1. Bonjour,
                    Voici le rapport dd fichier C:\WINDOWS\system32\userinit.exe :

                    File userinit.exe received on 07.11.2006 07:25:02 (CET)
                    Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
                    Result: 1/28 (3.58%)
                    Loading server information...
                    Your file is queued in position: ___.
                    Estimated start time is between ___ and ___ .
                    Do not close the window until scan is complete.
                    The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
                    If you are waiting for more than five minutes you have to resend your file.
                    Your file is being scanned by VirusTotal in this moment,
                    results will be shown as they're generated.
                    Compact Compact
                    Print results Print results
                    Your file has expired or does not exists.
                    Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

                    You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
                    Email:

                    Antivirus Version Last Update Result
                    AVG - - -
                    AntiVir - - -
                    Antivir7 - - -
                    Authentium - - -
                    Avast - - -
                    BitDefender - - -
                    CAT-QuickHeal - - -
                    ClamAV - - -
                    DrWeb - - -
                    Ewido - - suspicious
                    F-Prot - - -
                    F-Prot4 - - -
                    Fortinet - - -
                    Ikarus - - -
                    Kaspersky - - -
                    McAfee - - -
                    Microsoft - - -
                    NOD32v2 - - -
                    Norman - - -
                    Panda - - -
                    Sophos - - -
                    Symantec - - -
                    TheHacker - - -
                    UNA - - -
                    VBA32 - - -
                    VirusBuster - - -
                    eTrust-InoculateIT - - -
                    eTrust-Vet - - -
                    Additional information
                    MD5: 84717891f0734c611721f56c60b5fbc3

                    je n'ai pas trouvé le second...C:\Windows\System32\wsaupdater.exe...!!!?!

                    l
                    0
                    1. Contributeur sécurité
                      analyse ces deux fichiers sur virus total et colleemoi les rapports: https://www.virustotal.com/gui/

                      C:\WINDOWS\system32\userinit.exe

                      C:\Windows\System32\wsaupdater.exe
                      0
                      1. Bonjour,
                        Desole pour le retard...je n'etais pas chez moi...!
                        voici le resultat de l'analyse navilog:
                        Clean Navipromo version 3.3.8 commencé le 24/12/2007 à 19:45:37,57

                        Outil exécuté depuis C:\Program Files\navilog1
                        Mise à jour le 11.12.2007 à 18h00 par IL-MAFIOSO

                        Microsoft Windows XP [version 5.1.2600]
                        Internet Explorer : 7.0.5730.11
                        Système de fichiers : NTFS

                        Mode suppression automatique

                        *** Creation backups fichiers trouvés par Catchme ***

                        Copie vers "C:\Program Files\navilog1\Backupnavi"

                        Copie C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr.dat réalisée avec succès !
                        Copie C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr.exe réalisée avec succès !
                        Copie C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr_nav.dat réalisée avec succès !
                        Copie C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr_navps.dat réalisée avec succès !

                        *** Suppression des fichiers trouvés avec Catchme ***

                        C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr.dat supprimé !
                        C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr.exe supprimé !
                        C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr_nav.dat supprimé !
                        C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr_navps.dat supprimé !

                        ** 2ème passage avec résultats Catchme **

                        * Dans C:\WINDOWS\system32 *

                        C:\WINDOWS\prefetch\zgcotxdimr*.pf trouvé !
                        Copie C:\WINDOWS\prefetch\zgcotxdimr*.pf réalisée avec succès !
                        C:\WINDOWS\prefetch\zgcotxdimr*.pf supprimé !

                        * Dans "C:\Documents and Settings\krazy\local settings\application data" *

                        *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                        * Suppression dans C:\WINDOWS\System32 *

                        * Suppression dans "C:\Documents and Settings\krazy\local settings\application data" *

                        *** Suppression dossiers dans C:\WINDOWS ***

                        *** Suppression dossiers dans C:\Program Files ***

                        *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

                        *** Suppression dossiers dans "C:\Documents and Settings\krazy\application data" ***

                        *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

                        *** Suppression fichiers ***

                        C:\WINDOWS\system32\nvs2.inf supprimé !

                        *** Suppression fichiers temporaires ***

                        Nettoyage contenu C:\WINDOWS\Temp effectué !
                        Nettoyage contenu C:\Documents and Settings\krazy\local settings\Temp effectué !

                        *** Traitement Recherche complémentaire ***
                        (Recherche fichiers spécifiques)

                        1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                        2)Recherche, création sauvegardes et suppression Heuristique :

                        * Dans C:\WINDOWS\system32 *

                        * Dans "C:\Documents and Settings\krazy\local settings\application data" *

                        phlmkf.dat trouvé !
                        Copie phlmkf.dat réalisée avec succès !
                        phlmkf.dat supprimé !

                        phlmkf_nav.dat trouvé !
                        Copie phlmkf_nav.dat réalisée avec succès !
                        phlmkf_nav.dat supprimé !

                        phlmkf.exe trouvé !
                        Copie phlmkf.exe réalisée avec succès !
                        phlmkf.exe supprimé !

                        phlmkf_navps.dat trouvé !
                        Copie phlmkf_navps.dat réalisée avec succès !
                        phlmkf_navps.dat supprimé !

                        C:\WINDOWS\prefetch\phlmkf*.pf trouvé !
                        Copie C:\WINDOWS\prefetch\phlmkf*.pf réalisée avec succès !
                        C:\WINDOWS\prefetch\phlmkf*.pf supprimé !

                        *** Sauvegarde du Registre vers dossier Backupnavi ***

                        sauvegarde du Registre réalisée avec succès !

                        *** Nettoyage Registre ***

                        Nettoyage Registre Ok

                        *** Certificats ***

                        Certificat Egroup supprimé !

                        *** Nettoyage terminé le 24/12/2007 à 19:53:48,01 ***

                        et le log hijackthis:
                        Logfile of HijackThis v1.99.1
                        Scan saved at 19:58:11, on 24/12/2007
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16574)

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\Program Files\a-squared Free\a2service.exe
                        C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                        C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                        C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        C:\PROGRA~1\MICROS~3\rapimgr.exe
                        C:\Program Files\yz dock 0.8.3 French English Japan German Spanish + 37 Docklets\YzDock.exe
                        C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                        C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                        C:\Program Files\HijackThis\HijackThis.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Windows\System32\wsaupdater.exe,
                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
                        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                        O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                        O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        O4 - Startup: Raccourci vers YzDock.lnk = C:\Program Files\yz dock 0.8.3 French English Japan German Spanish + 37 Docklets\YzDock.exe
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                        O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
                        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
                        O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
                        O11 - Options group: [INTERNATIONAL] International*
                        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                        O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                        O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
                        O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                        O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                        O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                        O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                        O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                        O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                        O23 - Service: CleanService - Unknown owner - C:\Program Files\StompSoft\Digital File Shredder Pro\CleanService.exe (file missing)
                        O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
                        O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe
                        O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe
                        O23 - Service: Steganos Live Encryption Engine 8.1 [Service] (SLEE_81_SERVICE) - Unknown owner - C:\WINDOWS\system32\SLEE81.exe (file missing)
                        O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

                        pour le moment les fenetres ne s'ouvrent plus.
                        J'ai aussi fait un scan en ligne et des infrctions ont ete trouvé;mais j'ai oublie de garder le rapport...!
                        en tout cas pour le moment ca a l'air de fonctionner...
                        merci pour tout...et bonnes fetes de fin d'annee
                        krazy
                        0
                        1. Contributeur sécurité
                          = Lance navilog1
                          = Cette fois-ci choisi l'option 2
                          = Navilog va faire le nettoyage.. patient jusqu'à ce qui soit marqué *** Nettoyage Termine le ..... ***
                          = Un rapport va être génrer sur ton C:\ qui sera en option 2
                          Note: le bureau disparaît

                          = colle le contenu du rapport de navilog (qui est en option2)

                          PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
                          Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
                          Tape explorer et valide. Celà te fera apparaitre ton bureau.

                          ______________________

                          colle le rapport d'un scan en ligne
                          avec un des suivants:

                          bitdefender en ligne :
                          http://www.bitdefender.fr/scan_fr/scan8/ie.html

                          Panda en ligne :
                          http://pandasoftware.fr

                          secuser en ligne :
                          http://www.secuser.com/outils/antivirus.htm

                          scan en ligne firefox

                          https://www.trendmicro.com/fr_fr/business.html

                          ______________________

                          puis recolle un rapport hiajckhtis et dis tes problemes actuels
                          0
                          1. Bonjour jlpjlp,
                            j'ai suivi tes instructions.
                            voici le resultat:
                            Search Navipromo version 3.3.8 commencé le 20/12/2007 à 6:22:10,25

                            !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                            !!! Postez ce rapport sur le forum pour le faire analyser !!!
                            !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                            Outil exécuté depuis C:\Program Files\navilog1
                            Mise à jour le 11.12.2007 à 18h00 par IL-MAFIOSO

                            Microsoft Windows XP [version 5.1.2600]
                            Internet Explorer : 7.0.5730.11
                            Système de fichiers : NTFS

                            Executé en mode normal

                            *** Recherche Programmes installés ***

                            WebMediaPlayer

                            *** Recherche dossiers dans C:\WINDOWS ***

                            *** Recherche dossiers dans C:\Program Files ***

                            C:\Program Files\WebMediaPlayer trouvé !

                            *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

                            *** Recherche dossiers dans "C:\Documents and Settings\krazy\application data" ***

                            *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

                            ...\WebMediaPlayer trouvé !

                            *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                            pour + d'infos : http://www.gmer.net

                            Fichier(s) caché(s) :

                            C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr.dat
                            C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr.exe
                            C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr_nav.dat
                            C:\Documents and Settings\krazy\Local Settings\Application Data\zgcotxdimr_navps.dat

                            *** Recherche avec GenericNaviSearch ***
                            !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                            !!! A vérifier impérativement avant toute suppression manuelle !!!

                            * Recherche dans C:\WINDOWS\system32 *

                            * Recherche dans "C:\Documents and Settings\krazy\local settings\application data" *

                            Fichiers trouvés :

                            zgcotxdimr.exe trouvé !

                            *** Recherche fichiers ***

                            C:\DOCUME~1\ALLUSE~1\Bureau\WebMediaPlayer.lnk trouvé !
                            C:\WINDOWS\tmlpcert2007 trouvé !
                            C:\WINDOWS\system32\nvs2.inf trouvé !

                            *** Recherche clés spécifiques dans le Registre ***

                            HKEY_CURRENT_USER\Software\Lanconfig trouvé !

                            *** Module de Recherche complémentaire ***
                            (Recherche fichiers spécifiques)

                            1)Recherche nouveaux fichiers Instant Access :

                            2)Recherche Heuristique :

                            * Dans C:\WINDOWS\system32 :

                            * Dans "C:\Documents and Settings\krazy\local settings\application data" :

                            zgcotxdimr.dat trouvé !

                            3)Recherche Certificats :

                            Certificat Egroup trouvé !

                            4)Recherche fichiers connus :

                            *** Analyse terminée le 20/12/2007 à 6:29:42,53 ***
                            Je vais m'absenter quelques jours donc je risque de ne pas repondre rapidement mais en tout cas merci pour la rapidite de ta reponse et pour ton aide...ce forum est super
                            0
                            1. Contributeur sécurité
                              Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

                              F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Windows\System32\wsaupdater.exe,

                              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

                              O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

                              O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta

                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

                              O16 - DPF: {317153FE-B7FB-419B-AC87-0B2EC97D7A04} (VB2S ActiveX Control) - http://www.subdo.com/activex/vb2s.cab

                              O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - https://driveragent.com/files/driveragent.cab

                              O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

                              ________________________

                              Fais un clic droit sur ce lien : (IL-MAFIOSO)
                              http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
                              Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
                              Ensuite double clique sur navilog1.exe pour lancer l'installation.
                              Une fois l'installation terminée, le fix s'exécutera automatiquement.
                              (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

                              Laisse-toi guider. Au menu principal, choisis 1 et valides.
                              (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

                              Patiente jusqu'au message :
                              *** Analyse Termine le ..... ***
                              Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
                              Copie-colle l'intégralité dans une réponse. Referme le blocnote.
                              Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
                              0