Messengerskinner.rtk - Comment le supprimer ?

Résolu
Bonjour,
J'ai installé spybot search & destroy et celui-ci a détecté la presence de messengerskinner.rtk, mais impossible de le supprimer.
Je suis sous windows vista et le fichier affecté est C:\Windows\System32\nvs2.inf .
En consultant le forum, j'ai cru comprendre qu'il fallait d'abord creer un rapport avec Navilog1 et le sousmettre à des spécialiste avant de continuer.
C'est ce que j'ai fait. Mais bizarre ! Il semblerait que l'anayse bloque au niveau de *** Recherche avec GenericNaviSearch *** (plusieurs heures d'attente et rien ne se passe...

Est-ce normal ?

Merci par avance pour votre aide
Nathalie

Voici le rapport :

Creation de la liste des programmes installes

Veuillez patienter

C:\unpffc02.txtLe fichier sp'cifi' est introuvable.
Impossible de trouver C:\unpffc02.txt
Search Navipromo version 3.4.0 commence le 20/01/2008 a 16:24:04,34

!!! Attention,ce rapport peut indiquer des fichiers/programmes legitimes !!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie desinfection sans l'avis d'un specialiste !!!

*** Recherche programmes installes ***

Veuillez patienter

Recherche terminee

*** Recherche dossiers dans C:\Windows ***

Veuillez patienter

Recherche terminee

*** Recherche dossiers dans C:\Program Files ***

Veuillez patienter

Recherche terminee

*** Recherche dossiers dans C:\ProgramData ***

Veuillez patienter

Recherche terminee

*** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs
***

Veuillez patienter

Recherche terminee

*** Recherche dossiers dans C:\Users\Nathalie\AppData\Roaming\MICROS~1\Windows\S
TARTM~1\Programs ***

Veuillez patienter

Recherche terminee

*** Recherche dossiers dans C:\Users\Nathalie\AppData\Local\virtualstore\Program
Files ***

Veuillez patienter

Recherche terminee

*** Recherche dossiers dans C:\Users\Nathalie\AppData\Roaming ***

Veuillez patienter

Recherche terminee

Recherche terminee

*** Recherche avec Catchme par gmer ***
pour + d'infos : http://www.gmer.net

Veuillez patienter ... Le scan peut durer une dizaine de minutes ...

C:\Users\Nathalie\AppData\Local\dxypgimdsg_nav.dat
C:\Users\Nathalie\AppData\Local\dxypgimdsg.dat
C:\Users\Nathalie\AppData\Local\dxypgimdsg.exe
C:\Users\Nathalie\AppData\Local\dxypgimdsg_nav.dat
C:\Users\Nathalie\AppData\Local\dxypgimdsg_navps.dat

*** Recherche avec GenericNaviSearch ***

Veuillez patienter
Configuration: Windows Vista
Internet Explorer 7.0

46 réponses

Résumé de la discussion

Spybot S&D a détecté Messengerskinner.rtk et un fichier potentiellement infecté C:\Windows\System32\nvs2.inf sur Windows Vista, et la suppression directe a échoué, laissant le fichier résistant au nettoyage. Plusieurs interventions suggèrent de générer des rapports et d’obtenir l’analyse spécialisée avant d’agir, Navilog1 et HijackThis, puis d’envisager une restauration système sur Vista et une mise à jour des protections. D'autres recommandations portent sur la sauvegarde du registre, la création d'un fichier .reg pour supprimer des éléments Run, l'exécution en mode administrateur, puis le redémarrage et l'examen du rapport HijackThis. En pratique, les conseils soulignent que les manipulations sur Vista et les outils de désinfection nécessitent une supervision par un spécialiste pour éviter des modifications système instables et des restaurations compromises.

Bobot (l’IA à votre service)
  1. Contributeur
    Bonsoir chris42,

    Ouvre une discussion qui te soit propre pour davantage de clarté.

    Clique sur "Posez votre question".

    Bon courage !
    0
    1. Bonjour j ai suivit ce que vous avez dit pecedemment dans vos réponses. Je vous envoie le resultat de l annalyse par navilog1. Merci d votre aide pour supprimer ce sataner fichier.

      C:\Windows\system32\nvs2.inf trouvé !

      *** Recherche clés spécifiques dans le Registre ***

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche nouveaux fichiers Instant Access :

      2)Recherche Heuristique :

      * Dans "C:\Windows\system32" :

      * Dans "C:\Users\CHRISTELLE\AppData\Local\Microsoft" :

      * Dans "C:\Users\CHRISTELLE\AppData\Local\virtualstore\windows\system32" :

      * Dans "C:\Users\CHRISTELLE\AppData\Local" :

      eooxxifq.dat trouvé !
      eooxxifq_nav.dat trouvé !
      eooxxifq_navps.dat trouvé !

      3)Recherche Certificats :

      Certificat Egroup trouvé !
      Certificat Electronic-Group trouvé !
      Certificat OOO-Favorit trouvé !
      Certificat Sunny-Day-Design-Ltd absent !

      4)Recherche fichiers connus :

      *** Analyse terminée le 11/05/2008 à 19:27:29,74 ***
      0
      1. Contributeur
        Problème MessengerSkinnner de craquinette résolu.
        0
        1. Contributeur
          De rien.

          Bonne chance !
          0
          1. Contributeur
            Re,

            Finalement, il est préférable pour toi d'ouvrir un sujet qui te soit propre.
            Cliquez sur "Posez votre question" et colle tes rapports.

            Cordialement
            0
            1. merci lineve de m avoir repondu et si tu peux me trouver quelqu un qui peut m aider merci c est tres gentil a toi bonne journée
              0
              1. Contributeur
                Bonjour edwigepl,

                Désolée mais je ne fais plus de désinfections (du moins pour le moment).
                Crée ton propre sujet afin qu'on te voie.
                Tu as plusieurs infections visibles dans ton HJT : ShopperReports, LOP, Navipromo...

                Colle tes rapports dans cette nouvelle discussion.

                Cordialement

                0
                1. trés gros problemes avec mssengerskinner j ai donc suivi les instruction j envoi donc les rapports merciSearch Navipromo version 3.5.2 commencé le 09/04/2008 ŕ 14:00:32,57

                  !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                  !!! Postez ce rapport sur le forum pour le faire analyser !!!
                  !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                  Outil exécuté depuis C:\Program Files\navilog1
                  Session actuelle : "pimousse"

                  Mise ŕ jour le 29.03.2008 ŕ 22h00 par IL-MAFIOSO

                  Microsoft Windows XP [version 5.1.2600]
                  Internet Explorer : 7.0.5730.11
                  Systčme de fichiers : NTFS

                  Executé en mode normal

                  *** Recherche Programmes installés ***

                  *** Recherche dossiers dans C:\WINDOWS ***

                  *** Recherche dossiers dans C:\Program Files ***

                  *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

                  *** Recherche dossiers dans "C:\Documents and Settings\pimouss\applic~1" ***

                  *** Recherche dossiers dans "C:\Documents and Settings\pimouss\locals~1\applic~1" ***

                  *** Recherche dossiers dans "C:\Documents and Settings\pimouss\menudm~1\progra~1" ***

                  *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

                  *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                  pour + d'infos : http://www.gmer.net

                  Fichier(s) caché(s) :

                  C:\Documents and Settings\pimouss\Local Settings\Application Data\hajcdcwf.dat
                  C:\Documents and Settings\pimouss\Local Settings\Application Data\hajcdcwf.exe
                  C:\Documents and Settings\pimouss\Local Settings\Application Data\hajcdcwf_nav.dat
                  C:\Documents and Settings\pimouss\Local Settings\Application Data\hajcdcwf_navps.dat

                  *** Recherche avec GenericNaviSearch ***
                  !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                  !!! A vérifier impérativement avant toute suppression manuelle !!!

                  * Recherche dans C:\WINDOWS\system32 *

                  * Recherche dans "C:\Documents and Settings\pimouss\locals~1\applic~1" *

                  * Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

                  * Recherche dans "C:\DOCUME~1\pimouss\locals~1\applic~1" *

                  *** Recherche fichiers ***

                  *** Recherche clés spécifiques dans le Registre ***

                  HKEY_CURRENT_USER\Software\Lanconfig trouvé !

                  *** Module de Recherche complémentaire ***
                  (Recherche fichiers spécifiques)

                  1)Recherche nouveaux fichiers Instant Access :

                  2)Recherche Heuristique :

                  * Dans C:\WINDOWS\system32 :

                  * Dans "C:\Documents and Settings\pimouss\locals~1\applic~1" :

                  hajcdcwf.dat trouvé !

                  * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :

                  * Dans "C:\DOCUME~1\pimouss\locals~1\applic~1" :

                  hajcdcwf.dat trouvé !

                  3)Recherche Certificats :

                  Certificat Egroup trouvé !
                  Certificat Electronic-Group trouvé !
                  Certificat OOO-Favorit trouvé !
                  Certificat Sunny-Day-Design-Ltd absent !

                  4)Recherche fichiers connus :

                  *** Analyse terminée le 09/04/2008 ŕ 14:09:42,51 ***

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 14:14:38, on 09/04/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.5730.0011)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\dllhost.exe
                  C:\WINDOWS\system32\RunDll32.exe
                  C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                  C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
                  C:\WINDOWS\system32\LVCOMSX.EXE
                  C:\Program Files\Logitech\Video\LogiTray.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Skype\Phone\Skype.exe
                  C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe
                  C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                  C:\Program Files\Logitech\Video\FxSvr2.exe
                  C:\Program Files\Skype\Plugin Manager\skypePM.exe
                  C:\Program Files\Windows Live\Messenger\usnsvc.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\WINDOWS\notepad.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
                  O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
                  O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O4 - HKLM\..\Run: [999] C:\applications\XPSP2+_03_Finalise.exe
                  O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                  O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                  O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                  O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                  O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                  O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                  O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
                  O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                  O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                  O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [Ping upload extra road] C:\Documents and Settings\All Users\Application Data\burn spam ping upload\Burn File.exe
                  O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [Simp] C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"
                  O4 - HKUS\S-1-5-19\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\RunOnce: [nltide2] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,L,,4,N (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
                  O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
                  O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
                  O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
                  O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                  O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
                  O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
                  O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                  O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - https://edpl1973.wordpress.com/
                  O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://bmm.imgag.com/imgag/cp/install/crusher-fr.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  0
                  1. Contributeur
                    Bonjour Nathalie,

                    Merci pour ta gentillesse.

                    As-tu nettoyé la retauration système?

                    Ravie d'avoir pu t'aider

                    Bon surf...sans nuisibles !!!
                    0
                    1. bonjour lineeve suite a une infection de messengerskinner je me permets de te contacter j ai suivis tes instructions et fais les rapports je t en fais un copier coller mais que dois je faire maintenant? j espere que tu me repondras merci

                      Search Navipromo version 3.5.2 commencé le 09/04/2008 ŕ 14:00:32,57

                      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                      !!! Postez ce rapport sur le forum pour le faire analyser !!!
                      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                      Outil exécuté depuis C:\Program Files\navilog1
                      Session actuelle : "pimousse"

                      Mise ŕ jour le 29.03.2008 ŕ 22h00 par IL-MAFIOSO

                      Microsoft Windows XP [version 5.1.2600]
                      Internet Explorer : 7.0.5730.11
                      Systčme de fichiers : NTFS

                      Executé en mode normal

                      *** Recherche Programmes installés ***

                      *** Recherche dossiers dans C:\WINDOWS ***

                      *** Recherche dossiers dans C:\Program Files ***

                      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

                      *** Recherche dossiers dans "C:\Documents and Settings\pimouss\applic~1" ***

                      *** Recherche dossiers dans "C:\Documents and Settings\pimouss\locals~1\applic~1" ***

                      *** Recherche dossiers dans "C:\Documents and Settings\pimouss\menudm~1\progra~1" ***

                      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

                      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                      pour + d'infos : http://www.gmer.net

                      Fichier(s) caché(s) :

                      C:\Documents and Settings\pimouss\Local Settings\Application Data\hajcdcwf.dat
                      C:\Documents and Settings\pimouss\Local Settings\Application Data\hajcdcwf.exe
                      C:\Documents and Settings\pimouss\Local Settings\Application Data\hajcdcwf_nav.dat
                      C:\Documents and Settings\pimouss\Local Settings\Application Data\hajcdcwf_navps.dat

                      *** Recherche avec GenericNaviSearch ***
                      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                      !!! A vérifier impérativement avant toute suppression manuelle !!!

                      * Recherche dans C:\WINDOWS\system32 *

                      * Recherche dans "C:\Documents and Settings\pimouss\locals~1\applic~1" *

                      * Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

                      * Recherche dans "C:\DOCUME~1\pimouss\locals~1\applic~1" *

                      *** Recherche fichiers ***

                      *** Recherche clés spécifiques dans le Registre ***

                      HKEY_CURRENT_USER\Software\Lanconfig trouvé !

                      *** Module de Recherche complémentaire ***
                      (Recherche fichiers spécifiques)

                      1)Recherche nouveaux fichiers Instant Access :

                      2)Recherche Heuristique :

                      * Dans C:\WINDOWS\system32 :

                      * Dans "C:\Documents and Settings\pimouss\locals~1\applic~1" :

                      hajcdcwf.dat trouvé !

                      * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :

                      * Dans "C:\DOCUME~1\pimouss\locals~1\applic~1" :

                      hajcdcwf.dat trouvé !

                      3)Recherche Certificats :

                      Certificat Egroup trouvé !
                      Certificat Electronic-Group trouvé !
                      Certificat OOO-Favorit trouvé !
                      Certificat Sunny-Day-Design-Ltd absent !

                      4)Recherche fichiers connus :

                      *** Analyse terminée le 09/04/2008 ŕ 14:09:42,51 ***

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 14:14:38, on 09/04/2008
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.5730.0011)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\dllhost.exe
                      C:\WINDOWS\system32\RunDll32.exe
                      C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                      C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
                      C:\WINDOWS\system32\LVCOMSX.EXE
                      C:\Program Files\Logitech\Video\LogiTray.exe
                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Skype\Phone\Skype.exe
                      C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe
                      C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                      C:\Program Files\Logitech\Video\FxSvr2.exe
                      C:\Program Files\Skype\Plugin Manager\skypePM.exe
                      C:\Program Files\Windows Live\Messenger\usnsvc.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\WINDOWS\notepad.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google/
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                      O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
                      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                      O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
                      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                      O4 - HKLM\..\Run: [999] C:\applications\XPSP2+_03_Finalise.exe
                      O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                      O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                      O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                      O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                      O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                      O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
                      O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [Ping upload extra road] C:\Documents and Settings\All Users\Application Data\burn spam ping upload\Burn File.exe
                      O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [Simp] C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe
                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"
                      O4 - HKUS\S-1-5-19\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\RunOnce: [nltide2] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,L,,4,N (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
                      O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
                      O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
                      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
                      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                      O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
                      O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
                      O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/
                      O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - https://edpl1973.wordpress.com/
                      O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://bmm.imgag.com/imgag/cp/install/crusher-fr.cab
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      End of file - 9818 bytes
                      0
                  2. Bonjour Lineve,
                    Un GRAND MERCI à toi pour ton aide si précieuse et pour le temps que tu passes à nous aider. Sans votre aide (toi et les autres, bien sûr), l'informatique devient vite un enfer !
                    Maintenant, mon PC fonctionne à merveille. Quel bonheur !
                    En plus, grâce à toi, j'ai appris pleins de choses. Je pense que tes conseils vont me servir pour l'avenir. Bien sûr, je penserai à poster les rapports, pour les faire analyser avant de faire quoi que ce soit.
                    Passe un bon week-end et encore merci.
                    Nathalie
                    0
                    1. Contributeur
                      Bonsoir Nathalie,

                      Tout me semble OK !

                      Maintenant que ton PC n'est plus infecté, nous allons nettoyer la restauration système : (voir ici pour Vista)

                      http://www.vista-xp.fr/forum/topic243.html

                      Veille à mettre à jour tous les logiciels de sécurité : antivirus, Java.....

                      Si tu juges ton problème résolu, songe à le mettre en "Résolu".

                      Sois prudente sur le net !
                      0
                      1. Rebonsoir Lineve,

                        Pour mon PC, tout va bien ! Pas de problème particulier. J'ai effectué, comme tu me l'as demandé, un scan avec hijackthis et ai coché hors connexion.
                        Pour être sûre d'avoir fait la bonne manip, j'ai également fait un nouveau log.
                        Est-ce correct ?
                        Nathalie

                        *******************************************************
                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 21:21:28, on 31/01/2008
                        Platform: Windows Vista (WinNT 6.00.1904)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16575)
                        Boot mode: Normal

                        Running processes:
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                        C:\Windows\System32\SysMonitor.exe
                        C:\Windows\RtHDVCpl.exe
                        C:\Program Files\Windows Defender\MSASCui.exe
                        C:\Program Files\MSN Messenger\msnmsgr.exe
                        C:\Program Files\Windows Media Player\wmpnscfg.exe
                        C:\Windows\System32\p2phost.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Program Files\Nikon\NkView6\NkvMon.exe
                        C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                        C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                        C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                        C:\Windows\System32\mobsync.exe
                        C:\Windows\system32\wbem\unsecapp.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O1 - Hosts: ::1 localhost
                        O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
                        O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                        O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] "C:\Windows\system32\SysMonitor.exe"
                        O4 - HKLM\..\Run: [WarReg_PopUp] "C:\Acer\WR_PopUp\WarReg_PopUp.exe"
                        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                        O4 - HKLM\..\Run: [BigDogPath] "C:\Windows\VM_STI.EXE"
                        O4 - HKLM\..\Run: [RtHDVCplC] "C\WINDOWS\RtHDVCpl.exe"
                        O4 - HKLM\..\Run: [avast] "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe"
                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        O4 - HKCU\..\Run: [msnmsgr] C:\Program Files\MSN Messenger\msnmsgr.exe
                        O4 - HKCU\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
                        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                        O4 - HKCU\..\Run: [CollaborationHost] C:\Windows\system32\p2phost.exe
                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE RÉSEAU')
                        O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                        O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O13 - Gopher Prefix:
                        O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
                        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                        O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                        O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                        O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                        0
                        1. Contributeur
                          Bonsoir Nathalie,

                          Comment va ton PC?

                          Relance hijackthis pour un scan seulement (Do a system scan) et coche hors connexion Internet et toutes fenêtres fermées, sauf hijackthis : (clic droit, n'oublie pas).

                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [QuickTime Task] C:\Windows\System32\qttask.exe
                          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                          O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                          O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000


                          Clique sur "Fix checked" ("Fixer objet") hors connexion.

                          Dis-moi comment va ta machine. Si tout se passe bien, je te donnerai les derniers conseils (nettoyage de la restauration système, par erxemple).

                          A te lire
                          0
                          1. Bonsoir Lineve,

                            Voici les 2 rapports demandés :

                            Bonne sirée
                            Nathalie

                            File/Folder C:\Users\Nathalie\AppData\Local\VirtualStore\Windows\DSC01497.zip/img091307-www.photoshop. com not found.
                            C:\Users\Nathalie\AppData\Local\VirtualStore\Windows\DSC01497.zip moved successfully.
                            C:\Users\Nathalie\Documents\Mes fichiers reçus\DSC01497.zip moved successfully.
                            C:\Users\Nathalie\Desktop\img091307-www.photoshop.com moved successfully.

                            OTMoveIt2 v1.0.17 log created on 01312008_181409
                            **************************************************************************************************
                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 18:46:03, on 31/01/2008
                            Platform: Windows Vista (WinNT 6.00.1904)
                            MSIE: Internet Explorer v7.00 (7.00.6000.16575)
                            Boot mode: Normal

                            Running processes:
                            C:\Windows\system32\taskeng.exe
                            C:\Windows\system32\Dwm.exe
                            C:\Windows\Explorer.EXE
                            C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                            C:\Windows\System32\SysMonitor.exe
                            C:\Windows\System32\qttask.exe
                            C:\Windows\RtHDVCpl.exe
                            C:\Program Files\Windows Defender\MSASCui.exe
                            C:\Program Files\MSN Messenger\msnmsgr.exe
                            C:\Windows\ehome\ehtray.exe
                            C:\Program Files\Windows Media Player\wmpnscfg.exe
                            C:\Windows\System32\p2phost.exe
                            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                            C:\Program Files\Windows Sidebar\sidebar.exe
                            C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                            C:\Windows\system32\wbem\unsecapp.exe
                            C:\Program Files\Nikon\NkView6\NkvMon.exe
                            C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                            C:\Windows\System32\rundll32.exe
                            C:\Windows\ehome\ehmsas.exe
                            C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                            C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                            R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                            O1 - Hosts: ::1 localhost
                            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                            O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
                            O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                            O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
                            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] "C:\Windows\system32\SysMonitor.exe"
                            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                            O4 - HKLM\..\Run: [QuickTime Task] C:\Windows\System32\qttask.exe
                            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                            O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                            O4 - HKLM\..\Run: [WarReg_PopUp] "C:\Acer\WR_PopUp\WarReg_PopUp.exe"
                            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                            O4 - HKLM\..\Run: [BigDogPath] "C:\Windows\VM_STI.EXE"
                            O4 - HKLM\..\Run: [RtHDVCplC] "C\WINDOWS\RtHDVCpl.exe"
                            O4 - HKLM\..\Run: [avast] "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe"
                            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                            O4 - HKCU\..\Run: [msnmsgr] C:\Program Files\MSN Messenger\msnmsgr.exe
                            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                            O4 - HKCU\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
                            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                            O4 - HKCU\..\Run: [CollaborationHost] C:\Windows\system32\p2phost.exe
                            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE RÉSEAU')
                            O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                            O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                            O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                            O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                            O13 - Gopher Prefix:
                            O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
                            O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                            O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                            O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                            O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                            0
                            1. Contributeur
                              Bonsoir Nathalie,

                              En effet, tu héberges un nuisible.
                              Télécharge OTMoveIT (de Old_Timer) sur ton Bureau.

                              http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe

                              Double-clique sur OTMoveIt.exe pour le lancer.
                              Copie la liste qui se trouve en citation ci-dessous,
                              et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

                              C:\Users\Nathalie\AppData\Local\VirtualStore\Windows\DSC01497.zip/img091307-www.photoshop. com
                              C:\Users\Nathalie\AppData\Local\VirtualStore\Windows\DSC01497.zip
                              C:\Users\Nathalie\Documents\Mes fichiers reçus\DSC01497.zip
                              C:\Users\Nathalie\Desktop\img091307-www.photoshop.com


                              Clique sur MoveIt! pour lancer la suppression.
                              Le résultat apparaîtra dans le cadre Results.
                              Clique sur Exit pour fermer.
                              Poste le rapport situé dans C:\\\_OTMoveIt\MovedFiles.

                              Il te sera peut-être demandé de redémarrer le pc pour achever la suppression.
                              Si c'est le cas, accepte par Yes.

                              Reviens avec le rapport de OTmoveIT ainsi qu'un nouveau log hijackthis.

                              A te lire
                              0
                              1. Bonsoir Lineve,

                                Voici le rapport. Cette fois, ça a marché (enfin, je crois)

                                Dans l'attente de tes nouvelles instructions

                                Nathalie

                                -------------------------------------------------------------------------------
                                KASPERSKY ONLINE SCANNER REPORT
                                Wednesday, January 30, 2008 7:07:57 PM
                                Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
                                Kaspersky Online Scanner version: 5.0.98.0
                                Kaspersky Anti-Virus database last update: 30/01/2008
                                Kaspersky Anti-Virus database records: 501769
                                -------------------------------------------------------------------------------

                                Scan Settings:
                                Scan using the following antivirus database: standard
                                Scan Archives: true
                                Scan Mail Bases: true

                                Scan Target - My Computer:
                                C:\
                                D:\
                                E:\
                                F:\
                                G:\
                                H:\
                                I:\
                                J:\

                                Scan Statistics:
                                Total number of scanned objects: 113578
                                Number of viruses found: 1
                                Number of infected objects: 5
                                Number of suspicious objects: 0
                                Duration of the scan process: 01:14:10

                                Infected Object Name / Virus Name / Last Action
                                C:\Boot\BCD Object is locked skipped
                                C:\Boot\BCD.LOG Object is locked skipped
                                C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
                                C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
                                C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
                                C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
                                C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
                                C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
                                C:\Program Files\Alwil Software\Avast4\DATA\report\Protection résidente.txt Object is locked skipped
                                C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\15528c3e575b206455c3acf0fde3843c_d4f670d1-5fad-48ea-bfb1-7219519a79b5 Object is locked skipped
                                C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\227079127aef20c8b739e926fc1888f4_192024c0-460d-4b2f-8466-9717c5e49b6b Object is locked skipped
                                C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\669da1db9ffb74816e57db1c7792b283_d4f670d1-5fad-48ea-bfb1-7219519a79b5 Object is locked skipped
                                C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\89a9dc49305ecf2b8b9e4f1f29e90148_d4f670d1-5fad-48ea-bfb1-7219519a79b5 Object is locked skipped
                                C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a6dd76bd153860f2f35fb4368e494fd6_d4f670d1-5fad-48ea-bfb1-7219519a79b5 Object is locked skipped
                                C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b1dc6b3c6616428bbc70307b059bdff3_d4f670d1-5fad-48ea-bfb1-7219519a79b5 Object is locked skipped
                                C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c22a665200b31fc3d1f6a9899236facc_d4f670d1-5fad-48ea-bfb1-7219519a79b5 Object is locked skipped
                                C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c2cb3dc9264421de4405e39123ed1fd5_d4f670d1-5fad-48ea-bfb1-7219519a79b5 Object is locked skipped
                                C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
                                C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.147.Crwl Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.147.gthr Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.wid Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010002.wid Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010016.ci Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010016.wid Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010016.wsb Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy46.gthr Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\NtfFB10.tmp Object is locked skipped
                                C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\NtfFB11.tmp Object is locked skipped
                                C:\ProgramData\Microsoft\Windows\DRM\drmstore.hds Object is locked skipped
                                C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-11022006-050241.log Object is locked skipped
                                C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\CardSpace\CardSpace.db Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Messenger\nathalie.callenaere@wanadoo.fr\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Messenger\nathalie.callenaere@wanadoo.fr\SharingMetadata\pending.dat Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Messenger\nathalie.callenaere@wanadoo.fr\SharingMetadata\Working\database_FE74_15E_7401_1B53\dfsr.db Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Messenger\nathalie.callenaere@wanadoo.fr\SharingMetadata\Working\database_FE74_15E_7401_1B53\fsr.log Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Messenger\nathalie.callenaere@wanadoo.fr\SharingMetadata\Working\database_FE74_15E_7401_1B53\fsrtmp.log Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Messenger\nathalie.callenaere@wanadoo.fr\SharingMetadata\Working\database_FE74_15E_7401_1B53\tmp.edb Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Windows\UsrClass.dat{9cf63806-40f3-11dc-9da8-001921e99bbb}.TM.blf Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Windows\UsrClass.dat{9cf63806-40f3-11dc-9da8-001921e99bbb}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Windows\UsrClass.dat{9cf63806-40f3-11dc-9da8-001921e99bbb}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Windows Defender\FileTracker\{7404C653-C812-4B8D-A8DC-E587FC7DE2A2} Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Windows Live Contacts\nathalie.callenaere@wanadoo.fr\real\members.stg Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Windows Live Contacts\nathalie.callenaere@wanadoo.fr\shadow\members.stg Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Windows Mail\edb.log Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Windows Mail\tmp.edb Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Temp\~DF3D9F.tmp Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Temp\~DF58CE.tmp Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Temp\~DF7E9D.tmp Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\Temp\~DF7EA6.tmp Object is locked skipped
                                C:\Users\Nathalie\AppData\Local\VirtualStore\Windows\DSC01497.zip/img091307-www.photoshop.com Infected: Backdoor.Win32.DsBot.mw skipped
                                C:\Users\Nathalie\AppData\Local\VirtualStore\Windows\DSC01497.zip ZIP: infected - 1 skipped
                                C:\Users\Nathalie\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
                                C:\Users\Nathalie\Desktop\img091307-www.photoshop.com Infected: Backdoor.Win32.DsBot.mw skipped
                                C:\Users\Nathalie\Documents\Mes fichiers reçus\DSC01497.zip/img091307-www.photoshop.com Infected: Backdoor.Win32.DsBot.mw skipped
                                C:\Users\Nathalie\Documents\Mes fichiers reçus\DSC01497.zip ZIP: infected - 1 skipped
                                C:\Users\Nathalie\NTUSER.DAT Object is locked skipped
                                C:\Users\Nathalie\ntuser.dat.LOG1 Object is locked skipped
                                C:\Users\Nathalie\ntuser.dat.LOG2 Object is locked skipped
                                C:\Users\Nathalie\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
                                C:\Users\Nathalie\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
                                C:\Users\Nathalie\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
                                C:\Windows\Debug\PASSWD.LOG Object is locked skipped
                                C:\Windows\Debug\sam.log Object is locked skipped
                                C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
                                C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Object is locked skipped
                                C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Object is locked skipped
                                C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WindowsUpdate.log Object is locked skipped
                                C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT Object is locked skipped
                                C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked skipped
                                C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked skipped
                                C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{646c22bc-c465-11dc-801c-001921e99bbb}.TM.blf Object is locked skipped
                                C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{646c22bc-c465-11dc-801c-001921e99bbb}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
                                C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{646c22bc-c465-11dc-801c-001921e99bbb}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
                                C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT Object is locked skipped
                                C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked skipped
                                C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked skipped
                                C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
                                C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
                                C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
                                C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped
                                C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
                                C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
                                C:\Windows\System32\catroot2\edb.log Object is locked skipped
                                C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
                                C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
                                C:\Windows\System32\config\COMPONENTS Object is locked skipped
                                C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
                                C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
                                C:\Windows\System32\config\DEFAULT Object is locked skipped
                                C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
                                C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
                                C:\Windows\System32\config\RegBack\COMPONENTS Object is locked skipped
                                C:\Windows\System32\config\RegBack\DEFAULT Object is locked skipped
                                C:\Windows\System32\config\RegBack\SAM Object is locked skipped
                                C:\Windows\System32\config\RegBack\SECURITY Object is locked skipped
                                C:\Windows\System32\config\RegBack\SOFTWARE Object is locked skipped
                                C:\Windows\System32\config\RegBack\SYSTEM Object is locked skipped
                                C:\Windows\System32\config\SAM Object is locked skipped
                                C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
                                C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
                                C:\Windows\System32\config\SECURITY Object is locked skipped
                                C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
                                C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
                                C:\Windows\System32\config\SOFTWARE Object is locked skipped
                                C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
                                C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
                                C:\Windows\System32\config\SYSTEM Object is locked skipped
                                C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
                                C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
                                C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.0.regtrans-ms Object is locked skipped
                                C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.1.regtrans-ms Object is locked skipped
                                C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.2.regtrans-ms Object is locked skipped
                                C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.blf Object is locked skipped
                                C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
                                C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
                                C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
                                C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
                                C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
                                C:\Windows\System32\Msdtc\KtmRmTm.blf Object is locked skipped
                                C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000001 Object is locked skipped
                                C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000002 Object is locked skipped
                                C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
                                C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
                                C:\Windows\System32\wbem\Repository\INDEX.BTR Object is locked skipped
                                C:\Windows\System32\wbem\Repository\MAPPING1.MAP Object is locked skipped
                                C:\Windows\System32\wbem\Repository\MAPPING2.MAP Object is locked skipped
                                C:\Windows\System32\wbem\Repository\OBJECTS.DATA Object is locked skipped
                                C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.001 Object is locked skipped
                                C:\Windows\System32\wfp\wfpdiag.etl Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Antivirus.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\ODiag.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\OSession.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
                                C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
                                C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped
                                C:\Windows\Temp\_avast4_\Webshlock.txt Object is locked skipped
                                C:\Windows\WindowsUpdate.log Object is locked skipped
                                D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

                                Scan process completed.
                                0
                                1. Contributeur
                                  Bonjour Nathalie,

                                  On va essayer une autre manière :

                                  Précautions pour Vista :

                                  Il faut :
                                  -désactiver le "mode protégé" d'IE par outils>options internet>sécurité.
                                  -décocher la case > redémarrer le navigateur, aller sur le site kaspersky.


                                  Fais un scan en ligne Kaspersky (merci à Charles Ingals)

                                  https://www.kaspersky.fr/downloads

                                  * Clique sur Accept
                                  * Une barre jaune va te demander si tu acceptes d'installer le Kavwebscan_Unicode.cab, installe l'Active X.
                                  * Clique une nouvelle fois sur "Accept"
                                  * Les bases de mises à jour vont s'installer, patiente un moment
                                  * Clique sur Next.
                                  * Clique sur My Computer, le scan se met en route; attends la fin du scan sans fermer la fenêtre sinon il s'arrêtera.

                                  A la fin du scan, si des objets infectés sont découverts, clique sur Save report as... Choisis bureau et nomme le rapport "rapport Kaspersky" et dans le champ d'enregistrement, choisis "fichiers texte" enregistre alors le rapport.

                                  Copie/colle la totalité du fichier texte ouvert, par clic droit dessus, sélectionner tout/copier.

                                  Colle ce rapport dans ta réponse sur le forum.

                                  Aide en cas de problème :Cybersécurité

                                  http://cybersecurite.xooit.com/t100-Scan-en-ligne-Kaspersky.htm#768

                                  NOTE: Le scan est à faire avec Internet Explorer.

                                  Si ça ne marche pas encore, essaie ceci :

                                  Fais un scan antivirus en ligne avec Nod32

                                  http://www.sprintvision.com/nod32-online-scanner.htm

                                  (avec Internet Explorer) puis poste le rapport ici ensuite :

                                  Tuto :

                                  http://pageperso.aol.fr/loraline60/nod32_scan.htm

                                  Courage !
                                  0
                                  1. Bonjour Lineve,
                                    Je tarde un peu pour envoyer le rapport Kapersky car je crois que je ne fais pas les choses correctement ?
                                    En suivant tes conseils, j'obtiens toujours le même résultat et je ne sais pas si la manière d'envoyer le rapport est la bonne.
                                    Si je fais enregistrer le rapport, j'obtiens de nombreuses pages et impossible de sélectionner les fichiers infestés ou alors je fais un copier/coller et j'ai le même résultat que le post 26. As-tu une idée de ce que je ne fais pas correctement ? Nathalie
                                    0
                                    1. Contributeur
                                      Bonsoir Nathalie,

                                      Ton rapport n'est pas complet.

                                      Précautions pour Vista :

                                      Il faut :
                                      -désactiver le "mode protégé" d'IE par outils>options internet>sécurité.
                                      -décocher la case > redémarrer le navigateur, aller sur le site kaspersky.


                                      Puis

                                      Assure-toi que les contrôles active x soient bien configurés dans les options internet comme décrit sur ce lien=> http://www.inoculer.com/activex.php3

                                      Fais un scan en ligne avec https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr

                                      Dans la nouvelle fenêtre qui s'affiche clique sur J'accepte

                                      On va te demander de télécharger un ou deux contrôles active x, accepte . Laisse le faire les mises à jour puis quand il aura fini, clique sur Suivant

                                      Dans le menu Choisissez la cible de l'analyse , sélectionne Poste de travail .
                                      Le scan va commencer.Poste le rapport qui sera généré stp.

                                      Aide en cas de problème : http://cybersecurite.xooit.com/t100-Scan-e...spersky.htm#768

                                      NOTE: le scan est à faire avec Internet Explorer

                                      A te lire
                                      0
                                      • 1
                                      • 2
                                      • 3