Fenetre CID

Résolu
Bonjour,

voila j'ai un probleme j'ai ces modite fenetre qui s'ouvre toute les 2min j'aimerai avoir de l'aide svp j'ai lu plusieurs poste deja et il est dit de posté personnelment donc voila j'atend votre aide merci

Ps: je suis sur vista
Configuration: Windows vista
Internet Explorer 7.0

33 réponses

Résumé de la discussion

Problème récurrent : des fenêtres contextuelles s'ouvrent toutes les deux minutes sous Windows Vista et Internet Explorer 7, et l'utilisateur demande de l'aide dans ce sujet. Des réponses variées proposent d'analyser les scripts et les composants présents, sans donner de solution claire ni étape précise pour résoudre le problème à court terme. Certains échanges incluent des extraits techniques et des vérifications d'outils, comme la présence de iexplore.exe et la liste des éléments dans les dossiers utilisateur ou les répertoires listés dans les profils d'utilisateur. Ce qui est utile est la mention des outils et des emplacements susceptibles d'abriter des programmes malveillants, mais aucune recommandation de nettoyage n'est présentée clairement.

Bobot (l’IA à votre service)
  1. ok c'est fait nan plus de probleme merci pour tout mon ordi remarche a merveille jusqu'a la prochaine fois lol
    0
    1. Contributeur sécurité
      ok parfait
      desinstalle navilog via ton panneau de configuration

      as tu encore des problèmes??????
      0
      1. Search Navipromo version 3.5.7 commencé le 2008-05-17 à 11:37:08.08

        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
        !!! Postez ce rapport sur le forum pour le faire analyser !!!
        !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

        Outil exécuté depuis C:\Program Files\navilog1
        Session actuelle : "Johnny"

        Mise à jour le 11.05.2008 à 18h00 par IL-MAFIOSO

        Microsoft Windows Vista 6.0.6000
        Internet Explorer : 7.0.6000.16643
        Système de fichiers : NTFS

        Recherche executé en mode normal

        *** Recherche Programmes installés ***

        *** Recherche dossiers dans "C:\Windows" ***

        *** Recherche dossiers dans "C:\Program Files" ***

        *** Recherche dossiers dans "C:\ProgramData" ***

        *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

        *** Recherche dossiers dans "c:\users\johnny\appdata\roaming\micros~1\windows\startm~1\programs" ***

        *** Recherche dossiers dans "C:\Users\Johnny\AppData\Local\virtualstore\Program Files" ***

        *** Recherche dossiers dans "C:\Users\Johnny\AppData\Roaming" ***

        *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
        pour + d'infos : http://www.gmer.net

        Aucun Fichier trouvé

        *** Recherche avec GenericNaviSearch ***
        !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
        !!! A vérifier impérativement avant toute suppression manuelle !!!

        * Recherche dans "C:\Windows\system32" *

        * Recherche dans "C:\Users\Johnny\AppData\Local\Microsoft" *

        * Recherche dans "C:\Users\Johnny\AppData\Local" *

        *** Recherche fichiers ***

        *** Recherche clés spécifiques dans le Registre ***

        *** Module de Recherche complémentaire ***
        (Recherche fichiers spécifiques)

        1)Recherche nouveaux fichiers Instant Access :

        2)Recherche Heuristique :

        * Dans "C:\Windows\system32" :

        * Dans "C:\Users\Johnny\AppData\Local\Microsoft" :

        * Dans "C:\Users\Johnny\AppData\Local" :

        3)Recherche Certificats :

        Certificat Egroup absent !
        Certificat Electronic-Group absent !
        Certificat OOO-Favorit absent !
        Certificat Sunny-Day-Design-Ltd absent !

        4)Recherche fichiers connus :

        *** Analyse terminée le 2008-05-17 à 12:06:34.72 ***
        0
        1. Contributeur sécurité
          Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

          - Va dans démarrer puis panneau de configuration
          - Double Clique sur l'icône "Comptes d'utilisateurs"
          - Clique ensuite sur désactiver et valide.

          tu télécharge navilog1
          http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

          Laisse-toi guider. Au menu principal, choisis 1 et valides.
          (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
          Patiente jusqu'au message :
          *** Analyse Termine le ..... ***
          Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
          Copie-colle l'intégralité dans une réponse. Referme le blocnote.
          Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
          0
          1. voila ce ke jai eu

            Etat des virus : En sécurité.
            Votre ordinateur ne contient pas de menaces connues.
            Etat des virus : Infecté !
            Votre ordinateur est infecté par au moins une menace connue. Etat des virus :

            188667 fichiers analysés, 0 fichier(s) infecté(s) sur vos lecteurs de disque.

            Aucun virus n'a été détecté en mémoire.

            Votre ordinateur ne contient pas de menaces connues. La détection de virus ne vérifie pas les fichiers compressés.

            Votre ordinateur semble à présent en sécurité. Pour bénéficier d'une protection en temps réel contre les virus, les pirates et le vol d'informations, effectuez une mise à niveau vers Norton Internet Security™.

            Aucun virus n'a été détecté en mémoire.

            L'analyse a été annulée avant la fin. Pour redémarrer l'analyse, cliquez ici.

            Votre ordinateur ne contient pas de menaces connues. La détection de virus ne vérifie pas les fichiers compressés.

            Votre ordinateur semble à présent en sécurité. Pour bénéficier d'une protection en temps réel contre les virus, les pirates et le vol d'informations, effectuez une mise à niveau vers Norton Internet Security™.

            Recherchez le nom des menaces indiquées ci-dessous sur le site Symantec Security Response pour obtenir des conseils de suppression.

            Attention ! L'analyse a détecté un virus actif dans la mémoire de l'ordinateur.
            L'analyse a été interrompue pour éviter toute infection ultérieure.

            Vous devriez fermer l'ordinateur immédiatement et le redémarrer avec un disque de secours antivirus ou similaire.

            Aucun virus n'a été détecté en mémoire.

            Votre ordinateur est infecté par au moins un virus ou cheval de Troie connu.

            Recherchez le nom des menaces indiquées ci-dessous sur le site Symantec Security Response pour obtenir des conseils de suppression.

            Aucun virus n'a été détecté en mémoire.

            Votre ordinateur est infecté par au moins un virus ou cheval de Troie connu.

            Remarque : l'analyse a été annulée avant la fin. Il peut rester des fichiers infectés sur l'ordinateur.

            Recherchez le nom des menaces indiquées ci-dessous sur le site Symantec Security Response pour obtenir des conseils de suppression.

            Aucune analyse n'a été exécutée. Pour lancer la détection de virus, cliquez ici.
            0
            1. Contributeur sécurité
              il faut faire le scan en ligne avec internet explorer

              sinon essaye les autres scan en ligne:

              colle le rapport d'un scan en ligne
              avec un des suivants:

              bitdefender en ligne :
              http://www.bitdefender.fr/scan_fr/scan8/ie.html

              Panda en ligne :
              http://pandasoftware.fr

              Kaspersky en ligne
              https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr

              secuser en ligne :
              http://www.secuser.com/outils/antivirus.htm
              http://www.secuser.com/outils/antivirus_installation.htm

              scan en ligne firefox

              https://www.trendmicro.com/fr_fr/business.html

              scan en ligne norton
              http://www.01net.com/contenu/4473/securite/pasapas_symantec1/

              ou telecharge et installe sur ton ordi

              bit defender free et colle un rapport avec:

              https://www.01net.com/telecharger/windows/Securite/antivirus-antitrojan/fiches/29063.html
              0
              1. ok j'ai viré tous ce qui etait inutile par contre je n'arive pas a effectué une analyse en ligne je ne dois pas etre doué lol
                sinan je n'est plus aucun probleme de fenetre intempestive merci bien
                0
                1. Contributeur sécurité
                  vire spyware doctor de ton ordi
                  si c'est la version gratuite car pas terrrible, il vaudrait mieux mettre spybot sans activer le tea timer:
                  https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/26157.html

                  _____________

                  tu as beaucoup de barre de recherche essaye de faire le menage et de virer celles que tu n'utilise pas via ton panneau de configuration:

                  Google Toolbar Helper
                  Norton Toolbar
                  Dealio
                  Kiwee Toolbar
                  Winamp Toolbar

                  _________________

                  dis nous si tu as encore des soucis avec ton ordi et

                  colle le rapport d'un scan en ligne
                  avec un des suivants:

                  bitdefender en ligne :
                  http://www.bitdefender.fr/scan_fr/scan8/ie.html

                  Panda en ligne :
                  http://pandasoftware.fr

                  Kaspersky en ligne
                  https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                  0
                  1. voici le dernier rapport

                    Logfile of HijackThis v1.99.1
                    Scan saved at 22:35, on 2008-05-14
                    Platform: Unknown Windows (WinNT 6.00.1904)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16643)

                    Running processes:
                    C:\Windows\System32\smss.exe
                    C:\Windows\system32\csrss.exe
                    C:\Windows\system32\wininit.exe
                    C:\Windows\system32\csrss.exe
                    C:\Windows\system32\services.exe
                    C:\Windows\system32\lsass.exe
                    C:\Windows\system32\lsm.exe
                    C:\Windows\system32\winlogon.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\SLsvc.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                    C:\Windows\system32\Dwm.exe
                    C:\Windows\Explorer.EXE
                    C:\Windows\system32\taskeng.exe
                    C:\Windows\System32\spoolsv.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                    C:\Program Files\Spyware Doctor\pctsAuxs.exe
                    C:\Program Files\Spyware Doctor\pctsSvc.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\Spyware Doctor\pctsTray.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\SearchIndexer.exe
                    C:\Windows\system32\WUDFHost.exe
                    C:\Windows\system32\taskeng.exe
                    C:\Program Files\Windows Defender\MSASCui.exe
                    C:\Windows\RtHDVCpl.exe
                    C:\Windows\System32\rundll32.exe
                    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                    C:\Windows\System32\rundll32.exe
                    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                    C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                    C:\Program Files\Packard Bell\FIJI\ABoard.exe
                    C:\Program Files\Kiwee Toolbar2\1.5.131\kwtbaim.exe
                    C:\Program Files\Packard Bell\FIJI\AOSD.exe
                    C:\Program Files\Windows Sidebar\sidebar.exe
                    C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                    C:\Program Files\Windows Media Player\wmpnscfg.exe
                    C:\Program Files\eMule\emule.exe
                    C:\Program Files\Windows Media Player\wmpnetwk.exe
                    C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                    C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
                    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                    C:\Windows\System32\mobsync.exe
                    C:\Program Files\Windows Live\Messenger\usnsvc.exe
                    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                    C:\Windows\servicing\TrustedInstaller.exe
                    C:\Windows\system32\SearchProtocolHost.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                    C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
                    C:\Windows\system32\SearchFilterHost.exe
                    C:\Users\Johnny\Desktop\HijackThis.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                    R3 - URLSearchHook: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll
                    R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
                    O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
                    O2 - BHO: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll
                    O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb126\Dealio.dll
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                    O3 - Toolbar: Afficher Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
                    O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb126\Dealio.dll
                    O3 - Toolbar: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll
                    O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
                    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                    O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                    O4 - HKLM\..\Run: [MSPService] C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                    O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
                    O4 - HKLM\..\Run: [ACTIVBOARD] C:\Program Files\Packard Bell\FIJI\aboard.exe
                    O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                    O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe
                    O4 - HKLM\..\Run: [KiweeHook] "C:\Program Files\Kiwee Toolbar2\1.5.131\kwtbaim.exe"
                    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                    O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
                    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                    O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
                    O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
                    O8 - Extra context menu item: Compare Prices with &Dealio - C:\Users\Johnny\AppData\LocalLow\Dealio\kb126\res\DealioSearch.html
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                    O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                    O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                    O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb126\Dealio.dll
                    O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb126\Dealio.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
                    O11 - Options group: [INTERNATIONAL] International*
                    O13 - Gopher Prefix:
                    O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
                    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{FA35026A-AEC4-4F0D-940B-F7AEDC55470E}: NameServer = 192.168.1.1,192.168.1.2
                    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                    O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
                    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                    O23 - Service: ccEvtMgr - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                    O23 - Service: ccSetMgr - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                    O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                    O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
                    O23 - Service: lxcg_device - - C:\Windows\system32\lxcgcoms.exe
                    O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                    O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                    O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
                    0
                    1. j'ai rien dit lol c bon sa remarche
                      0
                      1. oui parse que tou sa g dja verifier je suis bien connecté a mon reseau local etc...ok je vais tenté une restauration
                        mais avec vista comment fait on?
                        0
                        1. Contributeur sécurité
                          Réparer manuellement la connexion Internet

                          Si, par malchance, vous n'avez plus accès à votre connexion Internet après avoir fait tourner ComboFix, la première chose à essayer est de faire redémarrer votre ordinateur. Cette seule manip devrait corriger la grande majorité des problèmes de non-connexion à Internet après l'utilisation de ComboFix. Si vous n'avez toujours pas de connexion Internet après avoir redémarré, exécutez les étapes suivantes:

                          1. Cliquez sur le bouton Démarrer.
                          2. Cliquez sur l'option de menu Paramètres.
                          3. Cliquez sur l'option Panneau de configuration.
                          4. Après l'ouverture du Panneau de configuration, faites un double clic sur l'icône Connexions réseau. Si votre Panneau de configuration est paramétré pour un affichage en catégories, faites un double clic sur Connexions réseau et Internet puis cliquez sur Connexions réseau tout en bas.
                          5. Vous verrez alors une liste de toutes les connexions réseau disponibles. Repérez la connexion vers votre adaptateur Sans Fil ou Réseau local et faites un clic droit dessus.
                          6. Vous verrez alors un menu similaire à celui de l'image ci-dessous. Cliquez simplement sur l'option de menu Réparer.

                          7. Laissez le processus de réparation se dérouler, et lorsqu'il a terminé, votre connexion Internet devrait être de nouveau opérationnelle.

                          ______________

                          sinon essaye LSPFIX:

                          http://www.zdnet.fr/telecharger/windows/fiche/0,39021313,39138667s,00.htm

                          ______________

                          ou winsokfx

                          http://www.shantee.net

                          ______________

                          si la connection ne remarche pas restaurte ton ordi avant l'utilisation de combofix
                          0
                          1. bonsoir...
                            bon et bien depuis hier soir ke j'ai posté ce raport j'ai eteind mon pc et depuis ce matin il m'ai impossible de me connecté a internet via mon pc...
                            heureusement que j'ai ma ps3 pour me connecté pour vous laisser ce petit message...
                            0
                            1. Contributeur sécurité
                              recolle nous un rapport hijakchits pour voir
                              0
                              1. ComboFix 08-05-12.1 - Johnny 2008-05-13 18:51:59.1 - NTFSx86
                                Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1828 [GMT 2:00]
                                Endroit: C:\Users\Johnny\Desktop\KillBagle.exe
                                * Création d'un nouveau point de restauration
                                .

                                (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                .

                                C:\Users\Johnny\AppData\Roaming\macromedia\Flash Player\#SharedObjects\XE2K4ZZT\iforex.com
                                C:\Users\Johnny\AppData\Roaming\macromedia\Flash Player\#SharedObjects\XE2K4ZZT\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
                                C:\Users\Johnny\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
                                C:\Users\Johnny\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol

                                .
                                ((((((((((((((((((((((((((((( Fichiers créés 2008-04-13 to 2008-05-13 ))))))))))))))))))))))))))))))))))))
                                .

                                2008-05-13 18:41 . 2008-05-13 18:41 <REP> d-------- C:\_OTMoveIt
                                2008-05-09 16:46 . 2008-05-10 15:02 <REP> d-------- C:\Program Files\Navilog1
                                2008-05-08 13:08 . 2008-05-08 14:01 <REP> d-------- C:\Lop SD
                                2008-05-08 12:31 . 2008-05-08 12:31 <REP> d-------- C:\Users\Johnny\AppData\Roaming\PC Tools
                                2008-05-08 12:31 . 2008-05-13 17:46 <REP> d-a------ C:\Users\All Users\TEMP
                                2008-05-08 12:31 . 2008-05-12 22:06 <REP> d-------- C:\Program Files\Spyware Doctor
                                2008-05-08 12:31 . 2007-12-10 13:53 81,288 --a------ C:\Windows\System32\drivers\iksyssec.sys
                                2008-05-08 12:31 . 2007-12-10 13:53 66,952 --a------ C:\Windows\System32\drivers\iksysflt.sys
                                2008-05-08 12:31 . 2008-02-01 11:55 42,376 --a------ C:\Windows\System32\drivers\ikfilesec.sys
                                2008-05-08 12:31 . 2007-12-10 13:53 29,576 --a------ C:\Windows\System32\drivers\kcom.sys
                                2008-05-08 12:02 . 2008-05-08 12:03 <REP> d-------- C:\Program Files\NoAdware5.0
                                2008-05-03 12:49 . 2008-05-03 12:49 <REP> d-------- C:\Program Files\MB Softs
                                2008-05-03 12:18 . 2008-05-03 12:28 862 --a------ C:\Windows\System32\LexFiles.ulf
                                2008-05-03 12:15 . 2008-05-03 12:18 <REP> d-------- C:\Program Files\Lexmark 2300 Series
                                2008-05-03 12:15 . 2008-05-03 12:18 1,314 --a------ C:\lxcginst.000
                                2008-05-03 12:15 . 2008-05-03 12:28 1,033 --a------ C:\lxcginst.csv
                                2008-05-03 12:14 . 2008-05-04 12:57 <REP> d-------- C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}
                                2008-05-03 12:14 . 2008-05-03 12:14 <REP> d-------- C:\Temp
                                2008-05-03 12:14 . 2008-05-03 12:14 <REP> d-------- C:\Lexmark
                                2008-05-03 12:14 . 2008-05-03 12:27 278 --a------ C:\lxcgfire.csv
                                2008-05-03 12:14 . 2008-05-03 12:15 278 --a------ C:\lxcgfire.000
                                2008-04-30 21:30 . 2008-04-30 21:30 <REP> d-------- C:\Program Files\HD1988 Labs
                                2008-04-28 21:01 . 2008-02-28 14:26 1,414,440 --a------ C:\Windows\System32\ShellManager310E2D762.dll
                                2008-04-28 21:01 . 2008-02-28 14:01 774,144 --a------ C:\Windows\System32\NEROINSTAEC43759.DB
                                2008-04-28 20:59 . 2008-04-28 20:59 <REP> d-------- C:\Program Files\BoontyGames
                                2008-04-28 20:59 . 2008-04-28 20:59 0 --a------ C:\Windows\Irremote.ini
                                2008-04-28 20:58 . 2008-04-28 20:58 <REP> d-------- C:\Boonty
                                2008-04-28 13:22 . 2008-05-10 16:04 1,251 --a------ C:\Users\Johnny\AppData\Roaming\QuickZip45.ini
                                2008-04-28 13:21 . 2008-04-28 13:21 <REP> d-------- C:\Program Files\QuickZip4
                                2008-04-26 17:51 . 2008-04-26 17:51 <REP> d-------- C:\Users\All Users\Winamp Toolbar
                                2008-04-26 17:51 . 2008-04-26 17:51 <REP> d-------- C:\Program Files\Winamp Toolbar
                                2008-04-26 17:50 . 2008-04-26 18:00 <REP> d-------- C:\Users\Johnny\AppData\Roaming\Winamp
                                2008-04-26 17:50 . 2008-04-26 18:09 <REP> d-------- C:\Program Files\Winamp
                                2008-04-19 16:52 . 2008-04-19 16:52 <REP> d-------- C:\Program Files\Antipub
                                2008-04-17 10:43 . 2008-04-17 10:43 <REP> d-------- C:\Users\All Users\Team Wave Body

                                .
                                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                2008-04-30 19:22 --------- d-----w C:\Users\Johnny\AppData\Roaming\Packard Bell
                                2008-04-28 19:02 --------- d-----w C:\Program Files\Common Files\Nero
                                2008-04-28 11:22 --------- d-----w C:\Program Files\Free Easy Burner
                                2008-04-21 07:45 --------- d-----w C:\Program Files\Kiwee Toolbar2
                                2008-04-11 15:01 --------- d-----w C:\Program Files\Windows Mail
                                2008-04-08 11:14 --------- d-----w C:\Program Files\Norton 360
                                2008-03-28 17:08 --------- d-----w C:\Program Files\Poker
                                2008-03-27 19:05 --------- d-----w C:\Program Files\WordBiz
                                2008-03-23 20:55 --------- d-----w C:\Program Files\SopCast
                                2008-03-20 19:49 --------- d-----w C:\Program Files\NeroInstall.bak
                                2008-03-13 19:32 --------- d-----w C:\Users\Johnny\AppData\Roaming\vlc
                                2008-03-13 18:02 --------- d-----w C:\Program Files\VideoLAN
                                2008-03-13 18:01 --------- d-----w C:\Program Files\Dealio
                                2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
                                2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
                                2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
                                2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
                                2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
                                2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
                                2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
                                2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys
                                2008-02-23 11:36 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
                                2008-02-23 11:36 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
                                2008-02-23 11:36 542,720 ----a-w C:\Windows\System32\sysmain.dll
                                2008-02-23 11:36 502,784 ----a-w C:\Windows\System32\wlansvc.dll
                                2008-02-23 11:36 47,104 ----a-w C:\Windows\System32\wlanapi.dll
                                2008-02-23 11:36 297,984 ----a-w C:\Windows\System32\wlansec.dll
                                2008-02-23 11:36 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
                                2008-02-23 11:36 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
                                2008-02-23 11:36 2,923,520 ----a-w C:\Windows\explorer.exe
                                2008-02-23 11:35 194,560 ----a-w C:\Windows\System32\WebClnt.dll
                                2008-02-23 11:34 613,888 ----a-w C:\Windows\System32\wpd_ci.dll
                                2008-02-23 11:34 558,080 ----a-w C:\Windows\System32\oleaut32.dll
                                2008-02-23 11:34 35,328 ----a-w C:\Windows\System32\dispci.dll
                                2008-02-23 11:34 260,096 ----a-w C:\Windows\System32\dpx.dll
                                2008-02-23 11:34 224,824 ----a-w C:\Windows\System32\clfs.sys
                                2008-02-23 11:34 221,696 ----a-w C:\Windows\System32\umpnpmgr.dll
                                2008-02-23 11:34 19,456 ----a-w C:\Windows\System32\cfgmgr32.dll
                                2008-02-23 11:34 12,800 ----a-w C:\Windows\System32\batt.dll
                                2008-02-23 11:34 101,888 ----a-w C:\Windows\System32\drvinst.exe
                                2008-02-23 11:34 1,585,664 ----a-w C:\Windows\System32\setupapi.dll
                                2008-02-23 11:33 905,400 ----a-w C:\Windows\System32\winresume.exe
                                2008-02-23 11:33 595,456 ----a-w C:\Windows\System32\schedsvc.dll
                                2008-02-23 11:33 39,424 ----a-w C:\Windows\System32\lodctr.exe
                                2008-02-23 11:33 32,256 ----a-w C:\Windows\System32\unlodctr.exe
                                2008-02-23 11:33 23,552 ----a-w C:\Windows\System32\nshhttp.dll
                                2008-02-23 11:33 17,408 ----a-w C:\Windows\System32\prflbmsg.dll
                                2008-02-23 11:33 115,200 ----a-w C:\Windows\System32\loadperf.dll
                                2008-02-23 11:31 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
                                2008-02-23 11:31 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
                                2008-02-23 11:31 24,064 ----a-w C:\Windows\System32\netcfg.exe
                                2008-02-23 11:31 22,016 ----a-w C:\Windows\System32\netiougc.exe
                                2008-02-23 11:31 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
                                2008-02-23 11:30 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
                                2008-02-23 11:30 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
                                2008-02-23 11:30 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
                                2008-02-23 11:30 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
                                2008-02-23 11:30 223,232 ----a-w C:\Windows\System32\WMASF.DLL
                                2008-02-23 11:30 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
                                2008-02-23 11:30 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
                                2008-02-23 11:30 2,048 ----a-w C:\Windows\System32\asferror.dll
                                2008-02-23 11:30 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
                                2008-02-23 11:30 1,686,528 ----a-w C:\Windows\System32\gameux.dll
                                2008-02-23 11:30 1,327,104 ----a-w C:\Windows\System32\quartz.dll
                                2008-02-23 11:29 11,776 ----a-w C:\Windows\System32\sbunattend.exe
                                2008-02-23 11:25 2,048 ----a-w C:\Windows\System32\tzres.dll
                                2008-02-23 11:22 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
                                2008-02-22 19:05 53,080 ----a-w C:\Windows\System32\wuauclt.exe
                                2008-02-22 19:05 43,352 ----a-w C:\Windows\System32\wups2.dll
                                2008-02-22 19:05 1,712,984 ----a-w C:\Windows\System32\wuaueng.dll
                                2008-02-22 19:05 1,524,224 ----a-w C:\Windows\System32\wucltux.dll
                                2008-02-22 19:04 80,896 ----a-w C:\Windows\System32\wudriver.dll
                                2008-02-22 19:04 549,720 ----a-w C:\Windows\System32\wuapi.dll
                                2008-02-22 19:04 33,624 ----a-w C:\Windows\System32\wups.dll
                                2008-02-22 19:03 31,232 ----a-w C:\Windows\System32\wuapp.exe
                                2008-02-22 19:03 163,000 ----a-w C:\Windows\System32\wuwebv.dll
                                2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
                                2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
                                2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
                                2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
                                2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
                                2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll
                                2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe
                                2007-11-14 07:35 174 --sha-w C:\Program Files\desktop.ini
                                .

                                ------- Sigcheck -------

                                .
                                ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                .
                                REGEDIT4
                                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                                [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
                                2008-03-20 00:36 1267040 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll

                                [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}]
                                2008-04-03 10:52 265360 --a------ C:\Program Files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                                "{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "C:\Program Files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll" [2008-04-03 10:52 265360]
                                "{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2008-03-20 00:36 1267040]

                                [HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
                                [HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
                                [HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
                                [HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]

                                [HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
                                [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
                                [HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
                                [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

                                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
                                "{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= C:\Program Files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll [2008-04-03 10:52 265360]
                                "{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2008-03-20 00:36 1267040]

                                [HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
                                [HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
                                [HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
                                [HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]

                                [HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
                                [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
                                [HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
                                [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

                                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-02-23 13:29 1232896]
                                "SmpcSys"="C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe" [2007-07-19 15:32 1120568]
                                "MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
                                "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [ ]
                                "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 14:36 201728]
                                "eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2007-05-13 16:57 5308416]

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-11-14 18:06 1006264]
                                "RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 18:07 4390912 C:\Windows\RtHDVCpl.exe]
                                "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-06 21:15 86016]
                                "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-06 21:15 8466432]
                                "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-06 21:15 81920]
                                "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-01-11 12:40 232184]
                                "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-11-14 10:00 243200]
                                "MSPService"="C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe" [2007-06-13 00:36 102400]
                                "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 23:59 115816]
                                "toolbar_eula_launcher"="C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe" [2007-02-20 18:20 28672]
                                "ACTIVBOARD"="C:\Program Files\Packard Bell\FIJI\aboard.exe" [2007-01-18 14:03 79416]
                                "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
                                "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
                                "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 18:38 583048]
                                "au"="C:\Program Files\Dealio\DealioAU.exe" [2008-02-08 14:11 546144]
                                "KiweeHook"="C:\Program Files\Kiwee Toolbar2\1.5.131\kwtbaim.exe" [2008-04-03 10:51 56456]
                                "ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-04-10 15:14 1107848]

                                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 23:18 443968]

                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                                "EnableLUA"= 0 (0x0)
                                "ValidateAdminCodeSignatures"= 1 (0x1)
                                "FilterAdministratorToken"= 1 (0x1)

                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                                "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL

                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                                "msacm.mkdmp3enc"= C:\PROGRA~1\CYBERL~1\MAGICS~1\Kernel\Burner\MKDMP3Enc.ACM
                                "VIDC.YV12"= yv12vfw.dll

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                                "UacDisableNotify"=dword:00000001

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                                "DisableMonitoring"=dword:00000001

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                                "DisableMonitoring"=dword:00000001

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                                "DisableMonitoring"=dword:00000001

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
                                "EnableFirewall"= 0 (0x0)

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
                                "{7E1E89E1-C3B8-4FF9-AB2C-54B8836CCB5E}"= C:\Program Files\CyberLink\MagicSports\MagicSports.exe:CyberLink MagicSports
                                "{780B0225-3B1D-4926-912A-FBCA504AF94B}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
                                "{F0F74F2B-FF94-43FB-8040-6AD5226FE601}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
                                "{F77C2039-E7F6-4BE9-8EE6-046D08393894}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
                                "{C7192142-2BA0-4C59-B794-D4DFD994595B}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
                                "{7FCB2C36-0A4D-4CCA-9180-83800EFC9471}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
                                "{B0C26777-390D-46CF-A673-43DC3FF4540F}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
                                "{B89E753E-6CA3-4AF7-A32A-3E361B871358}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
                                "{6CAB4D84-E4AD-4EEF-A865-D35F606C1B5B}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
                                "{D0A79461-80D8-444C-8721-F70FAC7C33AC}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
                                "{E32278C5-1C87-4DF6-B5C0-1CBFBCD40C18}"= UDP:C:\Program Files\eMule\emule.exe:eMule
                                "{F79F241D-F108-4319-BE3D-A04515984A88}"= TCP:C:\Program Files\eMule\emule.exe:eMule
                                "{E8E75928-72A1-481C-A11C-E12A007EF630}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
                                "{0CCE4A62-CBF2-44D0-AE61-C1ED5DD80E0E}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
                                "{2B8DAF89-F0BB-47BD-9845-B58766E7794A}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
                                "{B310015C-C63B-4BDD-ABC5-DAC43EC85B68}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
                                "{F2C0663D-0370-4FD4-960A-116500021242}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
                                "{A574B164-409C-4440-9C55-14841071FD5C}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
                                "{FE9B8810-947F-4D2B-BBB1-C53D503FBC03}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
                                "{F60C4D32-4BDC-4177-8E43-CA73B9F6AD96}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
                                "EnableFirewall"= 0 (0x0)

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
                                "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
                                "EnableFirewall"= 0 (0x0)

                                R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080508.002\IDSvix86.sys [2008-02-14 03:39]
                                R3 athrusb;Atheros Wireless LAN USB device driver;C:\Windows\system32\DRIVERS\athrusb.sys [2006-12-22 21:05]
                                R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-01-09 23:32]

                                *Newly Created Service* - COMHOST
                                .
                                Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
                                "2008-05-13 16:30:00 C:\Windows\Tasks\Extension de garantie.job"
                                - C:\Program Files\Packard Bell\SetupmyPC\PBCarNot.exe
                                "2008-05-13 16:30:00 C:\Windows\Tasks\Recovery DVD Creator.job"
                                - C:\Program Files\Packard Bell\SetupMyPc\MCDCheck.exe
                                .
                                **************************************************************************

                                catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                Rootkit scan 2008-05-13 18:55:37
                                Windows 6.0.6000 NTFS

                                detected NTDLL code modification:
                                ZwClose

                                Balayage processus cachés ...

                                Balayage caché autostart entries ...

                                Balayage des fichiers cachés ...

                                Scan terminé avec succès
                                Les fichiers cachés: 0

                                **************************************************************************
                                .
                                Temps d'accomplissement: 2008-05-13 18:57:10
                                ComboFix-quarantined-files.txt 2008-05-13 16:57:04

                                Pre-Run: 332,483,219,456 octets libres
                                Post-Run: 332,499,222,528 octets libres

                                271 --- E O F --- 2008-05-09 13:51:47
                                0
                                1. desoler je par en weekend jusqua lundi donc je men reocupe des lundi merci pour ton aide et a lundi
                                  0
                                  1. peut tu appliquer le message 4 de jlpjlp stp
                                    sauf lopxp
                                    0
                                    1. voila le rapport obtenue

                                      Clean Navipromo version 3.5.6 commencé le 10/05/2008 à 14:58:53,74

                                      Outil exécuté depuis C:\Program Files\navilog1
                                      Session actuelle : "Johnny"

                                      Mise à jour le 02.05.2008 à 22h00 par IL-MAFIOSO

                                      Microsoft Windows Vista 6.0.6000
                                      Internet Explorer : 7.0.6000.16643
                                      Système de fichiers : NTFS

                                      Mode suppression automatique
                                      avec prise en charge résultats Catchme et GNS

                                      *** fsbl1.txt non trouvé ***
                                      (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                                      *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                                      * Suppression dans "C:\Windows\System32" *

                                      * Suppression dans "C:\Users\Johnny\AppData\Local\Microsoft" *

                                      * Suppression dans "C:\Users\Johnny\AppData\Local" *

                                      dheifjfb.exe trouvé !
                                      Copie dheifjfb.exe réalisée avec succès !
                                      dheifjfb.exe supprimé !

                                      dheifjfb.dat trouvé !
                                      Copie dheifjfb.dat réalisée avec succès !
                                      dheifjfb.dat supprimé !

                                      dheifjfb_nav.dat trouvé !
                                      Copie dheifjfb_nav.dat réalisée avec succès !
                                      dheifjfb_nav.dat supprimé !

                                      dheifjfb_navps.dat trouvé !
                                      Copie dheifjfb_navps.dat réalisée avec succès !
                                      dheifjfb_navps.dat supprimé !

                                      dheifjfb_navfx.dat trouvé !
                                      Copie dheifjfb_navfx.dat réalisée avec succès !
                                      dheifjfb_navfx.dat supprimé !

                                      *** Suppression dossiers dans "C:\Windows" ***

                                      *** Suppression dossiers dans "C:\Program Files" ***

                                      C:\Program Files\WebMediaPlayer ...suppression...
                                      C:\Program Files\WebMediaPlayer supprimé !

                                      *** Suppression dossiers dans "C:\ProgramData" ***

                                      *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                                      ...\WebMediaPlayer ...suppression...
                                      ...\WebMediaPlayer supprimé !

                                      *** Suppression dossiers dans c:\users\johnny\appdata\roaming\micros~1\windows\startm~1\programs ***

                                      *** Suppression dossiers dans "C:\Users\Johnny\AppData\Local\virtualstore\Program Files" ***

                                      *** Suppression dossiers dans "C:\Users\Johnny\AppData\Roaming" ***

                                      *** Suppression fichiers ***

                                      C:\Windows\system32\nvs2.inf supprimé !

                                      *** Suppression fichiers temporaires ***

                                      Nettoyage contenu C:\Windows\Temp effectué !
                                      Nettoyage contenu C:\Users\Johnny\AppData\Local\Temp effectué !

                                      *** Traitement Recherche complémentaire ***
                                      (Recherche fichiers spécifiques)

                                      1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                                      2)Recherche, création sauvegardes et suppression Heuristique :

                                      * Dans "C:\Windows\system32" *

                                      * Dans "C:\Users\Johnny\AppData\Local\Microsoft" *

                                      * Dans "C:\Users\Johnny\AppData\Local" *

                                      *** Sauvegarde du Registre vers dossier Safebackup ***

                                      sauvegarde du Registre réalisée avec succès !

                                      *** Nettoyage Registre ***

                                      Nettoyage Registre Ok

                                      *** Certificats ***

                                      Certificat Egroup supprimé !
                                      Certificat Electronic-Group supprimé !
                                      Certificat OOO-Favorit supprimé !
                                      Certificat Sunny-Day-Design-Ltdt absent !

                                      *** Nettoyage terminé le 10/05/2008 à 15:02:54,72 ***
                                      0
                                      1. bonjour
                                        tu cliques sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
                                        Au menu principal, choisis 2 et valides.
                                        (ne fais pas le choix ,3 ou 4 sans notre avis/accord)

                                        Le fix va t'informer qu'il va alors redémarrer ton PC
                                        Fermes toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
                                        Appuies sur une touche comme demandé.
                                        (si ton Pc ne redémarre pas automatiquement, fais le toi même)
                                        Au redémarrage de ton PC, choisis ta session habituelle.

                                        Patiente jusqu'au message :
                                        *** Nettoyage Termine le ..... ***
                                        Le bloc-notes va s'ouvrir.
                                        Sauvegarde le rapport de manière à le retrouver
                                        Referme le bloc-notes. Ton bureau va réapparaitre

                                        PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
                                        Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
                                        Tape explorer et valide. Celà te fera apparaitre ton bureau.

                                        Poste le rapport
                                        0
                                        • 1
                                        • 2