Fenêtre

Bonjour,
Depuis ce matin, dès que j'ouvre internet explorer, une fenêtre s'ouvre : il es ecrit avertissement de sécurité.Fichier ouvert. IL y a un nom de fichier, éditeur inconnu .Il semeblerait que ce soit un virus, car depuis, j'ai pleins de fenêtres de pub qui s'ouvrent, des trucs de jeu, que je n'avais pas avant. Je ne comprends pas grand chose à l'informatique, mais j'ai fait un nettoyage (contre les chevaux de Troie et sur les conseils de mon frère assez calé). Il m'à supprimé pleins de "merdes", mais il m'en reste et mon problème reste entier. Qui peut m'aider en m'expliquant assez simplement SVP. Merci beaucoup.
Configuration: Windows Vista
Internet Explorer 7.0

126 réponses

Résumé de la discussion

Une fenêtre d'avertissement de sécurité s'ouvre à chaque lancement d'Internet Explorer sur Windows Vista, et l'ordinateur affiche des publicités et des fichiers suspects, pointant vers une possible infection virale. Plusieurs réponses préconisent une approche anti-malware avec des outils comme ComboFix et l'analyse des éléments au démarrage, afin d'identifier les programmes indésirables et d'établir un rapport exploitable. Des exemples relevés évoquent IncrediMail, LimeWire ou AVG7 dans les démarrages ou les scripts, et l'échange souligne la nécessité d'examiner les journaux et les rapports générés par les outils. Des répertoires temporaires et des scripts suspects dans le répertoire temporaire local et d'autres emplacements révèlent une activité malveillante qui peut persister même après les nettoyages et d'autres méthodes.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    celui ci date du 19/02 j'en veux un nouveau !
    1. voila le scan d'aujourd'hui désolée je me suis plantée ^^

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:44:10, on 24/02/2008
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16609)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Grisoft\AVG7\avgcc.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Menu Démarrer\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\PROGRA~1\INCRED~1\bin\IMApp.exe
      C:\Program Files\Internet Explorer\ieuser.exe
      C:\Windows\System32\mobsync.exe
      C:\Program Files\IncrediMail\bin\IncMail.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Dofus\dofus.dll
      C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Menu Démarrer\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
      O2 - BHO: BrowsingProgram - {F8EACE56-0AF4-3AE3-6EF8-F8CC39675729} - C:\Program Files\BrowsingProgram\BrowsingProgram-1.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Menu Démarrer\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
      O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe
      O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Menu Démarrer\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Menu Démarrer\Spybot - Search & Destroy\SDHelper.dll
      O13 - Gopher Prefix:
      O15 - Trusted Zone: http://www.secuser.com
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
      O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
      O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5234/mcfscan.cab
      O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
      O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
      O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
      O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Menu Démarrer\Spybot - Search & Destroy\SDWinSec.exe
  2. Contributeur sécurité
    si jamais tu as un souci ultérieurement , poste ici .

    @ jamais +
    1. Contributeur sécurité
      j'ai trouvé ca :

      va sur Internet explorer,clic droit,propriétés internet,coller: http://google.fr.
      1. Salut jfk
        Désolée d'avoir disparue, mais j'avais des préocupations. Ton idée n'a rien changée, mais mon problème a disparu. Merci beaucoup, et pour tout. trés sympa de m'avoir aidé jusqu'au bout. Bises .
    2. Contributeur sécurité
      tu as regardé dans "rapports et solution " ???

      l'érreur doit y etre indiqué ,dans ce cas la recherche une solution par le biais du web .
      1. Contributeur sécurité
        salut lola ,s'agit il toujours de cette fenetre :http://img508.imageshack.us/img508/9879/fenetreintempestiveir3.jpg
        1. Salut jfk,
          Oui, c'est exactement celle là, après vérification des chiffres et des lettres . Qu'est-ce que c'est et pourquoi ?
      2. Saut cgui ,salut jfk que ce passe-t-il pas de nouvelles depuis jeudi avons nous fini?
        L'ordinateur n'a plus de problemes mis à part cette fenêtre qui s'ouvre toujours au
        lancement d'internet dans la session de mon mari.
        1. Re
          encore moi !
          Pour JAVA, il y a une alerte de securer qui circule !
          Lola si tu peux aller ici pour vérifier si tu es à jour !
          Je suis sûr que non (t'inquiète pas moi non plus) car ils en sont à la version 6 Update 5 !
          Rappel : Ne garde qu'une seule version sur ton PC.

          A+
          1. eh ben raté j'ai cette version mon fils a fait la mise a jour
          2. @lola13Bien vu ...
            ça donne quoi ce que t'a demandé de faire JFK ?
            A+
          3. @cgui33Si tu veux parler du comportement de mon PC, je dirais que depuis quelques jours c'est bien, là il est nickel. Pas de pub, plus de fenêtres, ni de comportement bizaroïde ! Mis à part que je ne reçois plus les posts par mail, alors que je coche la case en bas, mais ça depuis déjà 2 ou 3 jours, je ne comprends plus rien !!!
            J'espère que nous avons bientôt fini. L'informatique, c'est pas trop mon truc, désolée !!!! En tout cas merci.
            Bonsoir, et à demain.
        2. Contributeur sécurité
          BHO demon ?? connnais pas , tu as un lien ??
          1. Alors voila j'ai fais ce que tu m'as dit et voici le rapport ComboFix je m'occupe desuite de l'Hijack :

            ComboFix 08-03-05.3 - MARYLENE 2008-03-06 20:01:43.3 - NTFSx86
            Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.406 [GMT 1:00]
            Endroit: C:\Users\MARYLENE\Desktop\ComboFix.exe
            Command switches used :: C:\Users\MARYLENE\Desktop\CFScript.log
            * Création d'un nouveau point de restauration
            .

            ((((((((((((((((((((((((((((( Fichiers créés 2008-02-06 to 2008-03-06 ))))))))))))))))))))))))))))))))))))
            .

            Pas de nouveau fichier créé dans cet espace de temps

            .
            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2008-03-06 15:19 --------- d-----w C:\Users\TOMMY\AppData\Roaming\OpenOffice.org2
            2008-03-06 15:19 --------- d-----w C:\Users\TOMMY\AppData\Roaming\AVG7
            2008-03-06 09:14 --------- d-----w C:\ProgramData\Google Updater
            2008-03-05 11:10 --------- d-----w C:\Program Files\Java
            2008-03-05 11:09 --------- d-----w C:\Program Files\Common Files\Java
            2008-03-05 11:01 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
            2008-03-05 09:35 --------- d-----w C:\Users\TOMMY\AppData\Roaming\LimeWire
            2008-03-04 17:01 --------- d-----w C:\Program Files\Dofus
            2008-03-02 15:42 --------- d-----w C:\Users\GIL\AppData\Roaming\OpenOffice.org2
            2008-03-02 10:53 --------- d-----w C:\Users\GIL\AppData\Roaming\AVG7
            2008-02-26 20:31 --------- d-----w C:\Program Files\CleanUp!
            2008-02-25 20:50 --------- d-----w C:\Program Files\Navilog1
            2008-02-23 17:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared
            2008-02-23 09:10 --------- d-----w C:\Program Files\Common Files\Adobe
            2008-02-22 14:00 --------- d-----w C:\Program Files\Norton Security Scan
            2008-02-22 09:14 69,689 ----a-w C:\Windows\UNZIP.DLL
            2008-02-22 09:14 507,904 ----a-w C:\Windows\TMUPDATE.DLL
            2008-02-22 09:14 286,720 ----a-w C:\Windows\PATCH.EXE
            2008-02-21 10:05 --------- d-----w C:\Program Files\Panda Security
            2008-02-19 18:40 --------- d-----w C:\Program Files\CCleaner
            2008-02-19 17:42 --------- d-----w C:\Program Files\Trend Micro
            2008-02-18 18:49 --------- d-----w C:\Program Files\Lavasoft
            2008-02-18 18:48 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
            2008-02-18 18:43 --------- d-----w C:\ProgramData\Lavasoft
            2008-02-17 19:46 --------- d-----w C:\Program Files\FBrowserAdvisor
            2008-02-17 19:36 --------- d-----w C:\Users\GIL\AppData\Roaming\LimeWire
            2008-02-14 08:04 194,560 ----a-w C:\Windows\System32\WebClnt.dll
            2008-02-14 08:04 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
            2008-02-14 08:01 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
            2008-02-14 08:01 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
            2008-02-14 08:01 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
            2008-02-14 08:01 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
            2008-02-14 08:01 24,064 ----a-w C:\Windows\System32\netcfg.exe
            2008-02-14 08:01 22,016 ----a-w C:\Windows\System32\netiougc.exe
            2008-02-14 08:01 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
            2008-02-14 08:01 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
            2008-02-14 08:01 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
            2008-02-14 08:01 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
            2008-02-14 08:01 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
            2008-02-14 08:01 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
            2008-02-14 08:00 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
            2008-02-14 08:00 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
            2008-02-14 08:00 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
            2008-02-14 08:00 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
            2008-02-14 08:00 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
            2008-02-14 08:00 1,686,528 ----a-w C:\Windows\System32\gameux.dll
            2008-02-14 07:58 824,832 ----a-w C:\Windows\System32\wininet.dll
            2008-02-14 07:58 56,320 ----a-w C:\Windows\System32\iesetup.dll
            2008-02-14 07:58 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
            2008-02-14 07:58 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
            2008-02-09 12:27 180 ----a-w C:\Users\GIL\AppData\Roaming\wklnhst.dat
            2008-01-29 16:14 --------- d-----w C:\Program Files\LimeWire
            2008-01-27 19:00 --------- d-----w C:\Users\TOMMY\AppData\Roaming\Corel
            2008-01-25 12:56 --------- d-----w C:\Users\TOMMY\AppData\Roaming\Nvu
            2008-01-25 12:56 --------- d-----w C:\Program Files\Nvu
            2008-01-22 14:21 --------- d-----w C:\Users\GIL\AppData\Roaming\Corel
            2008-01-22 14:12 --------- d-----w C:\Program Files\InstallShield Installation Information
            2008-01-22 14:10 --------- d-----w C:\Program Files\Common Files\Corel
            2008-01-22 14:09 --------- d-----w C:\Program Files\Corel
            2008-01-22 14:05 --------- d-----w C:\Program Files\Common Files\InstallShield
            2008-01-10 05:50 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
            2008-01-09 09:14 --------- d-----w C:\Program Files\Windows Sidebar
            2008-01-09 09:14 --------- d-----w C:\Program Files\Windows Mail
            2008-01-09 09:01 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
            2008-01-09 09:01 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
            2008-01-09 09:00 11,776 ----a-w C:\Windows\System32\sbunattend.exe
            2007-12-14 10:32 12,632 ----a-w C:\Windows\System32\lsdelete.exe
            2007-12-13 07:29 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
            2007-12-13 07:29 223,232 ----a-w C:\Windows\System32\WMASF.DLL
            2007-12-13 07:29 1,327,104 ----a-w C:\Windows\System32\quartz.dll
            2007-09-08 08:29 174 --sha-w C:\Program Files\desktop.ini
            2007-11-24 11:02 168 --sh--r C:\Windows\System32\5F7BF6CE0E.sys
            2007-11-24 11:02 3,764 --sha-w C:\Windows\System32\KGyGaAvL.sys
            .

            ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            REGEDIT4
            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 10:00 1232896]
            "IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-08-21 10:44 208946]
            "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 13:36 201728]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 09:17 579072]
            "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-06 19:15 86016]
            "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-06 19:15 8466432]
            "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-06 19:15 81920]
            "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 15:15 81920]
            "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
            "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]

            [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
            "AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 12:24 219136]

            C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
            Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-09-08 15:38:58 126136]

            C:\Users\MARYLENE\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\
            wkcalrem.LNK - C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe [2005-08-19 06:14:28 21504]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
            avgwlntf.dll 2007-09-08 09:07 9216 C:\Windows\System32\avgwlntf.dll

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
            "{3A4CC070-3EBE-487B-A0FF-45EDA3BC40D8}"= Disabled:UDP:C:\Users\MARYLENE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KTGVXAXU\incredimail_install[1].exe:IncrediMail Installer
            "{4C513806-F318-4BE4-9F1A-7235C75E80FA}"= Disabled:TCP:C:\Users\MARYLENE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KTGVXAXU\incredimail_install[1].exe:IncrediMail Installer
            "{DD6C55C9-E2AA-4B26-BD4A-23B79B4166A7}"= Disabled:UDP:C:\Users\MARYLENE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VZOHF9KL\incredimail_install[1].exe:IncrediMail Installer
            "{68119F36-BADA-4FC5-BB42-7C1BA65F48CB}"= Disabled:TCP:C:\Users\MARYLENE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VZOHF9KL\incredimail_install[1].exe:IncrediMail Installer
            "{AE260EA3-6410-4925-A142-CDFF5C06DEBA}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
            "{115928D3-9437-431F-A240-CE0C94C88CCC}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
            "{895165A4-CCE7-43FF-870C-9800BD3787E4}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
            "{DB317B35-7C10-4507-BD88-F7AD6328EAA5}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
            "{91DDBE26-D5BF-4294-87B9-95D6CAE2B618}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
            "{9ADD85FC-7AA3-4621-9FE2-6BAA83E6AC75}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
            "{787E57E6-DBED-435D-BC3D-11944A8C9E1C}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
            "{D99B153E-0999-4A93-84F9-BBB05C5A8960}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
            "{AD5C173C-DC89-4A34-B590-F0FCD977126B}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
            "TCP Query User{D18D7B1F-5E4F-4EB7-A316-2DE528BB78F1}C:\escan\kavupd.exe"= UDP:C:\escan\kavupd.exe:kavupd|Desc=kavupd
            "UDP Query User{1A9D65A8-79CA-4265-9C1F-A459F15CBFBE}C:\escan\kavupd.exe"= TCP:C:\escan\kavupd.exe:kavupd|Desc=kavupd
            "{B2361EE9-7CD6-437A-BC3B-D85C38A4EF58}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
            "{23E4C176-9AA0-431A-9D2C-E76B82156771}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
            "{6F4E9A05-C268-4A1D-9C3F-71E736DF1D61}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
            "{FBA6DCE8-7E31-47CB-9C2D-C3FC67D7E7CC}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
            "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

            R3 AvgWFP;AVG7 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfp.sys [2007-12-21 09:17]

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a5772cd2-5dd9-11dc-a237-806e6f6e6963}]
            \shell\AutoRun\command - E:\INTRO.EXE

            .
            Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
            "2008-02-22 16:17:59 C:\Windows\Tasks\Norton Security Scan.job"
            - C:\Program Files\Norton Security Scan\Nss.exe
            "2008-03-06 18:49:13 C:\Windows\Tasks\User_Feed_Synchronization-{B2923FDC-50D5-44F3-9889-8DA1630BEE98}.job"
            ??
            ????1\- C:\Windows\system32\msfeedssync.exe
            "2008-03-06 15:19:08 C:\Windows\Tasks\User_Feed_Synchronization-{B430F359-4A87-447A-9FCA-12CBADE38FB4}.job"
            - C:\Windows\system32\msfeedssync.exe
            .
            **************************************************************************

            catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2008-03-06 20:04:23
            Windows 6.0.6000 NTFS

            Balayage processus cachés ...

            Balayage caché autostart entries ...

            Balayage des fichiers cachés ...

            Scan terminé avec succès
            Les fichiers cachés: 0

            **************************************************************************
            .
            Temps d'accomplissement: 2008-03-06 20:05:11
            ComboFix-quarantined-files.txt 2008-03-06 19:05:08
            ComboFix2.txt 2008-02-28 20:50:50
            ComboFix3.txt 2008-02-27 21:12:30
            .
            2008-03-05 07:14:00 --- E O F ---
          2. @lola 13Voila chose dite chose faite l'Hijack est là :

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 20:12:25, on 06/03/2008
            Platform: Windows Vista (WinNT 6.00.1904)
            MSIE: Internet Explorer v7.00 (7.00.6000.16609)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\Dwm.exe
            C:\Program Files\Grisoft\AVG7\avgcc.exe
            C:\Windows\System32\rundll32.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Program Files\Google\Google Updater\GoogleUpdater.exe
            C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\PROGRA~1\INCRED~1\bin\IMApp.exe
            C:\Windows\system32\wbem\unsecapp.exe
            C:\Windows\system32\werfault.exe
            C:\Windows\System32\mobsync.exe
            C:\Windows\Explorer.exe
            C:\Program Files\Internet Explorer\IEUser.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Trend Micro\HijackThis\hijackthis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            O1 - Hosts: ::1 localhost
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
            O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
            O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
            O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O13 - Gopher Prefix:
            O15 - Trusted Zone: http://www.secuser.com
            O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
            O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
            O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
            O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
            O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u5-windows-i586-jc.cab
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5244/mcfscan.cab
            O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
            O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
            O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
            O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
            O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
            O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
          3. Re
            Moi je l'ai téléchargé ici
            Apparemment il y en a au moins un autre qui fait mieux (soi-disant) mais qui est payant !
            BHOdemon ne listerait pas tous les BHO présents sur le poste !
            A voir

            A+
        3. Contributeur sécurité
          salut a vous deux ,un peu occupé avec ma fille mais de retour !!

          j'ai fait une faute pour le Cfscript de combofix ,on va le refaire comme ceci:

          > Ferme tout tes navigateurs (donc copie ou imprime les instructions avant)
          - Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie/colle dedans les lignes suivantes :

          files::
          C:\Program Files\BrowsingProgram\BrowsingProgram-1.dll

          registry::
          [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F8EACE56-0AF4-3AE3-6EF8-F8CC39675729}]


          - Enregistre ce fichier sous le nom CFScript
          - Fait un glisser/déposer de ce fichier CFScrïpt sur le fichier ComboFix.exe comme sur cette image. (Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris.) Combofix va démarrer.
          - Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
          - Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
          - Ne touche à rien tant que le scan n'est pas terminé sinon le PC peut planter !
          - Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
          Note : Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

          ensuite reposte un hijack .
          1. Salut JFK
            Merci de revenir
            As tu déjà essayé BHOdemon ?
            (peut-être n'est il pas compatible avec VISTA !)
            Je vais regarder
            A+
        4. Re
          Pour le vérifier :
          Désinstalles JAVA et relance un scan mcAfee
          Supprime le répertoire JAVA :
          Double-clique sur OTMoveIt.exe pour le lancer. (tu l'as déjà il me semble !)
          Assure toi que la case "Unregister Dll's and Ocx's" soit bien cochée !!!
          Copie le texte ci-dessous, et colle le dans le cadre de gauche de OTMoveIt nommé Paste List of Files/Folders to be moved.

          C:\Users\Marylene\Appdata\Locallow\Sun\Java

          Clique sur MoveIt! pour lancer la suppression.
          Si OTMoveIt propose de redémarrer ton PC, accepte.
          Lorsqu' un résultat apparaît dans le cadre Results, clique sur Exit.
          Dans ta future réponse, envoie le rapport de OTMoveIt situé sur C:\_OTMoveIt\MovedFiles.
          Le nom du rapport est la date de sa création.

          Apparemment tu avais déjà le pb sur ton ancienne installation de VISTA :
          C:\Windows.old\...\3\27007203-261a3020 Exploit-ByteVerify sur ton rapport McAfee

          A+
          1. Re
            Donc tu as eu un message du style : file not found lorsque tu as tapé le dir ... après avoir désinstaller JAVA !?!?
            Alors, si Oui (un prog ou ligne base de registre ... ou autre !? ) te remet ces saloperies car ce sont les mêmes !
            Soit c'est normal (lors de la réinstallation de JAVA) ... ce qui m'étonnerait fort !
            Va voir ici
            J'espère que JFK va revenir(il est pas loin ... je crois)
            A+
            1. Salut
              Tu peux me dire ce que tu as fait exactement (dans l'ordre)
              Merci
              A+
              1. Salut cgui !
                J'ai fait exactement ce que tu as dit, et dans l'ordre où tu me l'as dit. Pourquoi ?
            2. Salut

              Ouais pas bon ... à ( \ ) près !
              Bon j'attends une réponse de JFK !
              Mais si personne ne te répond ce soir :
              Désinstalles tes versions de JAVA (une normalement)
              Ensuite : vérifie que le répertoire 3 n'existe plus (même commande qu'ici)
              sauf que la réponse ne devrait pas être la même !

              Réinstalles Java

              Ensuite redémarre le PC et refais un scan McAfee

              A+
              1. Salut cgui, !
                Voici le scan McAfee, après manoeuvres.

                C:\MSNFix\MSNFix\incl\Process.exe PrcViewer
                C:\Program Files\Navilog1\Process.exe PrcViewer
                C:\Program Files\Navilog1\reboot.exe Generic PUP.g
                C:\Users\MARYLENE\...\6.0\3\27007203-261a3020 Exploit-ByteVerify
                C:\Users\MARYLENE\...\6.0\53\76fb16b5-425de6b9 Exploit-ByteVerify
                C:\Users\MARYLENE\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
                C:\Windows.old\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
                C:\Windows.old\...\3\27007203-261a3020 Exploit-ByteVerify
                C:\Windows.old\...\53\76fb16b5-425de6b9 Exploit-ByteVerify
                C:\Windows.old\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
                C:\Windows.old\Users\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
                C:\Windows.old\Users\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
                C:\Windows.old\Users\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
            3. Re

              Fais démarrer--> exécuter
              tape cmd (+ entrée)
              Dans la fenêtre qui va s'ouvrir :
              Tape : CD C:\ (+ entrée)
              Ensuite tape : Dir 3 /S (+ entrée)

              Tu devrais voir apparaitre le chemin complet, mais je suis presque sûr que ce sera :
              C:\Users\Marylene\Appdata\...\Sun\Java\Deployment\Cache\6.0\3
              Sous Vista, je ne sais pas ce qu'il y a entre les deux !

              A+ (mardi soir)
              1. Après recherche je crois bien que au milieu il y aura :
                Local\Temp\Low

                A vérifier !
                A+
              2. @cgui33Salut !
                Tu avais presque tout bon à 1 ficher près !

                C:\Users\Marylene\Appdata\Locallow\Sun\Java\Deployment\Cache\6.3

                Pour le \3 je ne l'ai pas vu mais je ne pouvais pas décaler la fenêtre !!

                En plus j'en ai marre ça fait 4 fois que je poste ce truc et ça n'arrive jamais sur le forum !! vive l'informatique (quand ça marche ) !!!!!
            4. Re
              Dans l'explorateur :
              Outils --> Options des dossiers --> Affichage
              Décocher : Cacher les extensions dont le type est connu
              Fichiers et dossiers cachés
              sélectionner : Afficher le fichiers et dossiers cachés
              Décocher : Masquer les fichiers protégés du système d'exploitation
              Tu devrais le trouver avec ça !

              A+
              PS : Fais la manip inverse après !
              1. Désolée, mais il est absolument impossible de mettre la main sur ces fichiers, même en suivant la manip de cgui. J'ai même tapé "C:\Users\MARYLENE", il m'a sorti tous les fichiers et j'ai cherché un par un, NEANT; même mon fils qui est assez fort et qui m'aide ne l'a pas trouvé. Comment ça se fait ?
              2. @lola13Si vous avez une autre idée, je prends. En attendant , je me couche , je chercherai demain. Bonne soirée et bonne nuit !
            5. Contributeur sécurité
              effectivement je voudrais bien avoir le chemin complet égalment.
              1. Salut
                Comment faire pour le trouver ? J'ai essayé de passer par l'exporateur, en tapant le nom du fichier mais il n'a rien trouvé. Quelle est la marche à suivre ?
              2. @lola13Salut !
                Tu avais presque tout bon à 1 ficher près !

                C:\Users\Marylene\Appdata\Locallow\Sun\Java\Deployment\Cache\6.3

                Pour le \3 je ne l'ai pas vu mais je ne pouvais pas décaler la fenêtre !!

                En plus j'en ai marre ça fait 4 fois que je poste ce truc et ça n'arrive jamais sur le form !! vive l'informatique (quand ça marche ) !!!!!
            6. Salut lola

              Ces lignes me semblent dangereuses :
              C:\Users\MARYLENE\...\6.0\3\27007203-261a3020 Exploit-ByteVerify
              C:\Users\MARYLENE\...\6.0\53\76fb16b5-425de6b9 Exploit-ByteVerify

              Attends la confirmation de JFK !
              Si tu pouvais nous donner le chemin complet, ce serait bien !

              A+
              1. Re
                Désolé je me suis planté !
                Tu peux le faire avec McAffe free scan ?
                Merci
                A demain
                1. Salut jfk et cgui
                  Désolée d'avoir été aussi longue mais j'ai eu un souci. Que des bugs, et tout refaire chaque fois; et comme le scan dure environ 2h30 ou 3h, vous imaginez !! Bref, j'ai fini par y arriver !!! OUF !!

                  C:\$Recycle.Bin\...\$RDMQR9B.zip PrcViewer
                  C:\MSNFix\MSNFix\incl\Process.exe PrcViewer
                  C:\Program Files\Navilog1\Process.exe PrcViewer
                  C:\Program Files\Navilog1\reboot.exe Generic PUP.g
                  C:\Users\MARYLENE\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
                  C:\Users\MARYLENE\...\6.0\3\27007203-261a3020 Exploit-ByteVerify
                  C:\Users\MARYLENE\...\6.0\53\76fb16b5-425de6b9 Exploit-ByteVerify
                  C:\Users\MARYLENE\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
                  C:\Windows.old\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
                  C:\Windows.old\...\3\27007203-261a3020 Exploit-ByteVerify
                  C:\Windows.old\...\53\76fb16b5-425de6b9 Exploit-ByteVerify
                  C:\Windows.old\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
                  C:\Windows.old\Users\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
                  C:\Windows.old\Users\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
                  C:\Windows.old\Users\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
              2. Salut lola
                Comment va la jambe ?
                Peux tu aller refaire un scan Panda pour nous donner un rapport comme celui-ci

                Merci
                A+
                1. Salut cgui,
                  La jambe ne va pas trop mal, je te remercie.
                  C'est tout ce que j'ai pu tirer du rapport du scan PANDA; Il n'y a pas de détail, je ne peux pas avoir de véritable rapport, et je ne peut même pas désinfecter , car il faut s'abonner.
                  Je te dis bonne fin de soirée. A plus;

                  ANALYSIS: 2008-02-29 23:18:57
                  PROTECTIONS: 1
                  MALWARE: 7
                  SUSPECTS: 0
                  ;***********************************************************************************************************************************************************************************
                  PROTECTIONS
                  Description Version Active Updated
                  ;===================================================================================================================================================================================
                  AVG 7.5.516 7.5.516 Yes Yes
                  ;===================================================================================================================================================================================
                  MALWARE
                  Id Description Type Active Severity Disinfectable Disinfected Location
                  ;===================================================================================================================================================================================
                  00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Users\MARYLENE\AppData\Roaming\Microsoft\Windows\Cookies\marylene@doubleclick[1].txt
                  00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Users\MARYLENE\AppData\Roaming\Microsoft\Windows\Cookies\marylene@247realmedia[1].txt
                  00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Users\MARYLENE\AppData\Roaming\Microsoft\Windows\Cookies\marylene@xiti[1].txt
                  00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Users\MARYLENE\AppData\Roaming\Microsoft\Windows\Cookies\marylene@advertising[2].txt
                  00173520 Cookie/Bluestreak TrackingCookie No 0 Yes No C:\Users\MARYLENE\AppData\Roaming\Microsoft\Windows\Cookies\marylene@bluestreak[2].txt
                  00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Users\MARYLENE\AppData\Roaming\Microsoft\Windows\Cookies\marylene@smartadserver[2].txt
                  01262593 Application/NirCmd.A HackTools No 0 Yes No C:\Windows\Nircmd.exe
                  ;===================================================================================================================================================================================
                  SUSPECTS
                  Location
                  ;==============================================================================================================================================================il faut s'abonner .
              3. Contributeur sécurité
                met toi sur la session de ton mari et poste moi un hijack .
                1. Voila l'Hijack de la session de mon mari:

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 20:59:16, on 29/02/2008
                  Platform: Windows Vista (WinNT 6.00.1904)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16609)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Grisoft\AVG7\avgcc.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                  C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Windows\system32\wbem\unsecapp.exe
                  c:\program files\common files\installshield\updateservice\isuspm.exe
                  C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
                  C:\Windows\System32\mobsync.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Menu Démarrer\Spybot - Search & Destroy\SDHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                  O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                  O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
                  O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Menu Démarrer\Spybot - Search & Destroy\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Menu Démarrer\Spybot - Search & Destroy\SDHelper.dll
                  O13 - Gopher Prefix:
                  O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                  O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
                  O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                  O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5234/mcfscan.cab
                  O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
                  O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                  O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                  O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                  O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
                  O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
                  O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Menu Démarrer\Spybot - Search & Destroy\SDWinSec.exe
              • 1
              • 2
              • 3
              • 4
              • 5
              • 6
              • 7