Pc infecté par Dialer generic

Bonjour,
l'antivirus avast a detecté un virus dans mon pc aprés l'avoir installé,il s'agit de Dialer generic ,
dégats : - des programmes et des logiciel que j'ai déja installé manquent dans le panneau de configuration
- des pages de publicités s'affichent de temps à otre.
- il y a des sites qui ne souvre pa
ce que j'ai fais : j'ai installé AVG anti-spyware et j'ai fais un acan complé du pc et voilà j'ai trouvé :

---------------------------------------------------------

+ Créé à: 00:01 02/10/2008

+ Résultat de l'analyse:

C:\WINDOWS\system32\drivers\pshook11.sys -> Adware.RogueSuspect : Aucune action entreprise.
HKLM\SOFTWARE\Spyware Nuker -> Adware.RogueSuspect : Aucune action entreprise.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Instant Access -> Dialer.Generic : Aucune action entreprise.
C:\Documents and Settings\hassan\Cookies\hassan@estat[1].txt -> TrackingCookie.Estat : Aucune action entreprise.

Fin du rapport

aidez moi s'il vous plais,
Configuration: Windows XP
Internet Explorer 6.0

20 réponses

  1. vous etes là les professionnels ???
    -1
    1. bonjour
      voila ce vous m'avez demander
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 17:57, on 04/10/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\WINDOWS\system32\srksrv.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\system32\WgaTray.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\WINDOWS\system32\igfxtray.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
      C:\WINDOWS\system32\igfxsrvc.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Ares\Ares.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Alwact\Bin\Alwact.exe
      C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe
      C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
      C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
      C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
      C:\Program Files\Fichiers communs\Nokia\MPAPI\MPAPI3s.exe
      C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\MSN Messenger\usnsvc.exe
      C:\WINDOWS\explorer.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.kooora.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [Alwact.exe] C:\Program Files\Alwact\Bin\Alwact.exe
      O4 - HKCU\..\Run: [UMService] C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
      O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
      O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
      O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: PoliceService - Unknown owner - C:\WINDOWS\system32\srksrv.exe
      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
      -2
      1. salut je vais prendre le relait puisque je vois qu'il repond pas ^^

        télécharge combofix (par sUBs) à cette adresse :

        (c est le numéro 5 en bas de la page) : https://www.androidworld.fr/

        et enregistre le sur le Bureau.

        désactive tes protections et ferme toutes tes applications(antivirus, parefeu, garde en temps réel de l'antispyware)
        ferme internet =====>panneau de configuration======>connection reseau======> clique gauche sur les deux et desactive

        et poste un autre rapport hijackthis stp
        -1
        1. salut, dit moi est ce qu'il aura koi reparé ou bien je formate mon pc ?
          repond svp
          -1
          1. Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 10:01, on 03/10/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            C:\WINDOWS\system32\srksrv.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\WINDOWS\system32\WgaTray.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\RTHDCPL.EXE
            C:\WINDOWS\system32\igfxtray.exe
            C:\WINDOWS\system32\hkcmd.exe
            C:\WINDOWS\system32\igfxpers.exe
            C:\WINDOWS\system32\igfxsrvc.exe
            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
            C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
            C:\Program Files\MSN Messenger\MsnMsgr.Exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Ares\Ares.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\Alwact\Bin\Alwact.exe
            C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe
            C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
            C:\Program Files\Fichiers communs\Nokia\MPAPI\MPAPI3s.exe
            C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
            C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
            C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
            C:\Program Files\Menara\dslmon.exe
            C:\Program Files\LG Electronics\Modem USB LG Electronics\IEUM.exe
            C:\program files\internet explorer\iexplore.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\Windows Live Toolbar\msn_sl.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.kooora.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Menara
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
            O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
            O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
            O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
            O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [TXP] c:\program files\topthemesxp\txp.exe
            O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
            O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [Alwact.exe] C:\Program Files\Alwact\Bin\Alwact.exe
            O4 - HKCU\..\Run: [UMService] C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
            O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
            O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
            O4 - Global Startup: DSLMON.lnk = C:\Program Files\Menara\dslmon.exe
            O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
            O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
            O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
            O17 - HKLM\System\CCS\Services\Tcpip\..\{EDF3D966-F49B-43D1-882E-D903E80F5C44}: NameServer = 192.168.50.55 196.12.209.6
            O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: PoliceService - Unknown owner - C:\WINDOWS\system32\srksrv.exe
            O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
            -1
            1. Contributeur sécurité
              Refais un Hijackthis stp.
              -1
              1. bonjour,s'il vous j'atends toujours vos consignes,,aidez moi SVP
                -1
                1. ya quelq'un,si non demain on continu,merci d'avance
                  -1
                  1. [b]SDFix: Version 1.230 [/b]
                    Run by hassan on 02/10/2008 at 22:59

                    Microsoft Windows XP [version 5.1.2600]
                    Running From: C:\SDFix

                    [b]Checking Services [/b]:

                    Restoring Default Security Values
                    Restoring Default Hosts File

                    Rebooting

                    [b]Checking Files [/b]:

                    Trojan Files Found:

                    C:\Documents and Settings\hassan\Application Data\addon.dat - Deleted

                    Removing Temp Files

                    [b]ADS Check [/b]:

                    C:\WINDOWS\system32
                    :winsock 747389
                    Total size: 747389 bytes.
                    system32: deleted 747389 bytes in 1 streams.

                    Checking for remaining Streams

                    C:\WINDOWS\system32
                    No streams found.

                    [b]Final Check [/b]:

                    catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2008-10-02 23:05:53
                    Windows 5.1.2600 Service Pack 2 NTFS

                    scanning hidden processes ...

                    scanning hidden services & system hive ...

                    scanning hidden registry entries ...

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
                    "TracesProcessed"=dword:00000000
                    "TracesSuccessful"=dword:00000000
                    "LastTraceFailure"=dword:00000000

                    scanning hidden files ...

                    scan completed successfully
                    hidden processes: 0
                    hidden services: 0
                    hidden files: 0

                    [b]Remaining Services [/b]:

                    Authorized Application Key Export:

                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
                    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
                    "C:\\Program Files\\ma-config.com\\maconfservice.exe"="C:\\Program Files\\ma-config.com\\maconfservice.exe:LocalSubNet:Enabled:maconfservice"
                    "C:\\Program Files\\Ares\\Ares.exe"="C:\\Program Files\\Ares\\Ares.exe:*:Enabled:Ares p2p for windows"
                    "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Disabled:eMule"
                    "C:\\Program Files\\HomePlayer1.5.2\\HomePlayer.exe"="C:\\Program Files\\HomePlayer1.5.2\\HomePlayer.exe:*:Disabled:HomePlayer"
                    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                    "C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"
                    "C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"="C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe:*:Enabled:Assistance … distance - Windows Messenger et voix"
                    "C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"="C:\\Program Files\\Winamp Remote\\bin\\Orb.exe:*:Enabled:Orb"
                    "C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe:*:Enabled:OrbTray"
                    "C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
                    "C:\\Program Files\\8BallClub\\GameDirector.exe"="C:\\Program Files\\8BallClub\\GameDirector.exe:*:Enabled:8BallClub Game"

                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
                    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
                    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

                    [b]Remaining Files [/b]:

                    File Backups: - C:\SDFix\backups\backups.zip

                    [b]Files with Hidden Attributes [/b]:

                    Fri 22 Aug 2008 9 A..H. --- "C:\WINDOWS\system32\wxpmin.dll"
                    Sun 24 Aug 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
                    Thu 2 Oct 2008 14,771,744 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\8171d23d6d072d8b50d065ca55a754fb\BIT2.tmp"
                    Sun 24 Aug 2008 37,835,710 A..H. --- "C:\Documents and Settings\hassan\Local Settings\Application Data\Microsoft\Media Player\MusicType1VirginMegaFr\Downloads\001B1A0C\BITF2.tmp"

                    [b]Finished![/b]
                    -1
                    1. Contributeur sécurité
                      Télécharges SDFix sur ton bureau :
                      http://downloads.andymanchesta.com/RemovalTools/SDFix.exe.

                      --->Double-cliques sur SDFix.exe et choisis "Install" .

                      ( tuto ici : https://www.malekal.com/slenfbot-still-an-other-irc-bot/ )

                      Puis une fois l'installe faite, redémarre en mode sans échec .

                      Comment aller en Mode sans échec :
                      1) Redémarre ton ordi
                      2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                      3) Tu verras un écran avec options de démarrage apparaître
                      4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                      5) Choisis ton compte habituel, et non Administrateur (si besoin ... )

                      Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
                      --->Tapes Y pour lancer le script ...
                      Le Fix supprime les services du virus et nettoie le registre, de ce fait un redémarrage est nécessaire , donc :
                      presse une touche pour redémarrer quand il te le sera demandé .

                      Le PC va mettre du temps avant de démarrer ( c'est normal), après le chargement du Bureau presse une touche lorsque "Finished" s'affiche .

                      Le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier C:\SDFix sous le nom "Report.txt".
                      Poste ce dernier dans ta prochaine réponse
                      -1
                      1. Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 20:02, on 02/10/2008
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        C:\WINDOWS\system32\srksrv.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\WINDOWS\system32\WgaTray.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        C:\WINDOWS\RTHDCPL.EXE
                        C:\WINDOWS\system32\igfxtray.exe
                        C:\WINDOWS\system32\hkcmd.exe
                        C:\WINDOWS\system32\igfxsrvc.exe
                        C:\WINDOWS\system32\igfxpers.exe
                        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                        C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                        C:\Program Files\MSN Messenger\MsnMsgr.Exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Ares\Ares.exe
                        C:\Program Files\Alwact\Bin\Alwact.exe
                        C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
                        C:\Program Files\Messenger\msmsgs.exe
                        C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe
                        C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
                        C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                        C:\Program Files\Menara\dslmon.exe
                        C:\Program Files\Fichiers communs\Nokia\MPAPI\MPAPI3s.exe
                        C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
                        C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
                        C:\Program Files\LG Electronics\Modem USB LG Electronics\IEUM.exe
                        C:\program files\internet explorer\iexplore.exe
                        C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                        C:\Program Files\MSN Messenger\usnsvc.exe
                        C:\Program Files\Windows Live Toolbar\msn_sl.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.kooora.com/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Menara
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
                        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                        O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                        O4 - HKLM\..\Run: [TXP] c:\program files\topthemesxp\txp.exe
                        O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                        O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                        O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        O4 - HKCU\..\Run: [Alwact.exe] C:\Program Files\Alwact\Bin\Alwact.exe
                        O4 - HKCU\..\Run: [UMService] C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
                        O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
                        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                        O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
                        O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
                        O4 - Global Startup: DSLMON.lnk = C:\Program Files\Menara\dslmon.exe
                        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
                        O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
                        O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
                        O17 - HKLM\System\CCS\Services\Tcpip\..\{EDF3D966-F49B-43D1-882E-D903E80F5C44}: NameServer = 192.168.50.55 196.12.209.6
                        O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: PoliceService - Unknown owner - C:\WINDOWS\system32\srksrv.exe
                        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                        -1
                        1. Contributeur sécurité
                          Refais un Hijackthis stp
                          -1
                          1. Clean Navipromo version 3.6.6 commencé le 02/10/2008 à 19:49:54,34

                            Outil exécuté depuis C:\Program Files\navilog1
                            Session actuelle : "hassan"

                            Mise à jour le 29.09.2008 à 17h30 par IL-MAFIOSO

                            Microsoft Windows XP [version 5.1.2600]
                            Internet Explorer : 6.0.2900.2180
                            Système de fichiers : NTFS

                            Mode suppression automatique
                            avec prise en charge résultats Catchme et GNS

                            Nettoyage exécuté au redémarrage de l'ordinateur

                            *** fsbl1.txt non trouvé ***
                            (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                            *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                            * Suppression dans "C:\WINDOWS\System32" *

                            C:\WINDOWS\prefetch\yuyiu*.pf trouvé !
                            Copie C:\WINDOWS\prefetch\yuyiu*.pf réalisée avec succès !
                            C:\WINDOWS\prefetch\yuyiu*.pf supprimé !

                            * Suppression dans "C:\Documents and Settings\hassan\locals~1\applic~1" *

                            yuyiu.exe trouvé !
                            Copie yuyiu.exe réalisée avec succès !
                            yuyiu.exe supprimé !

                            yuyiu.dat trouvé !
                            Copie yuyiu.dat réalisée avec succès !
                            yuyiu.dat supprimé !

                            yuyiu_nav.dat trouvé !
                            Copie yuyiu_nav.dat réalisée avec succès !
                            yuyiu_nav.dat supprimé !

                            yuyiu_navps.dat trouvé !
                            Copie yuyiu_navps.dat réalisée avec succès !
                            yuyiu_navps.dat supprimé !

                            *** Suppression dossiers dans "C:\WINDOWS" ***

                            *** Suppression dossiers dans "C:\Program Files" ***

                            *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

                            *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

                            *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                            *** Suppression dossiers dans "C:\Documents and Settings\hassan\applic~1" ***

                            *** Suppression dossiers dans "C:\Documents and Settings\hassan\locals~1\applic~1" ***

                            *** Suppression dossiers dans "C:\Documents and Settings\hassan\menudm~1\progra~1" ***

                            *** Suppression fichiers ***

                            C:\WINDOWS\dialerexe.ini supprimé !

                            *** Suppression fichiers temporaires ***

                            Nettoyage contenu C:\WINDOWS\Temp effectué !
                            Nettoyage contenu C:\Documents and Settings\hassan\locals~1\Temp effectué !

                            *** Traitement Recherche complémentaire ***
                            (Recherche fichiers spécifiques)

                            1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                            C:\WINDOWS\system32\nsinet.exe trouvé !
                            Copie C:\WINDOWS\system32\nsinet.exe réalisée avec succès !
                            C:\WINDOWS\system32\nsinet.exe supprimé !

                            2)Recherche, création sauvegardes et suppression Heuristique :

                            * Dans "C:\WINDOWS\system32" *

                            * Dans "C:\Documents and Settings\hassan\locals~1\applic~1" *

                            *** Sauvegarde du Registre vers dossier Safebackup ***

                            sauvegarde du Registre réalisée avec succès !

                            *** Nettoyage Registre ***

                            Nettoyage Registre Ok

                            *** Certificats ***

                            Certificat Egroup supprimé !
                            Certificat Electronic-Group supprimé !
                            Certificat Montorgueil absent !
                            Certificat OOO-Favorit supprimé !
                            Certificat Sunny-Day-Design-Ltdt absent !

                            *** Nettoyage terminé le 02/10/2008 à 19:53:30,35 ***
                            -1
                            1. Contributeur sécurité
                              Relance Navilog, Sur le menu principal, choisis 2.
                              Suis les instructions et patiente.

                              L'outil va t'informer qu'il redémarrera ton ordinateur.
                              Sauvegarde les documents ouverts, s'il y en a, puis ferme toutes les fenêtres.
                              Appuie sur une touche ainsi que demandé.

                              Si ton ordinateur ne redémarre pas automatiquement, fais le manuellement.
                              Choisis ta session habituelle si nécessaire.
                              Patiente jusqu'au message *** Nettoyage terminé le ….*** (il se peut que ça prenne un certain temps).
                              Un document du Bloc-notes est créé. Sauvegarde le rapport de manière à le retrouver.
                              * Copie/colle le contenu de ce compte-rendu dans ta prochaine réponse.
                              Referme le Bloc-notes.
                              Ton Bureau va réapparaître.

                              Note : Si ton Bureau ne réapparaît pas, presse Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
                              Onglet "Processus" > Fichier (menu) > Nouvelle tâche (Exécuter...) > tape explorer et clique sur OK.
                              --
                               
                              -1
                              1. Search Navipromo version 3.6.6 commencé le 02/10/2008 à 18:54:27,71

                                !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                                !!! Postez ce rapport sur le forum pour le faire analyser !!!
                                !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                                Outil exécuté depuis C:\Program Files\navilog1
                                Session actuelle : "hassan"

                                Mise à jour le 29.09.2008 à 17h30 par IL-MAFIOSO

                                Microsoft Windows XP [version 5.1.2600]
                                Internet Explorer : 6.0.2900.2180
                                Système de fichiers : NTFS

                                Recherche executé en mode normal

                                *** Recherche Programmes installés ***

                                Favorit

                                *** Recherche dossiers dans "C:\WINDOWS" ***

                                *** Recherche dossiers dans "C:\Program Files" ***

                                *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

                                *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

                                *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                                *** Recherche dossiers dans "C:\Documents and Settings\hassan\applic~1" ***

                                *** Recherche dossiers dans "C:\Documents and Settings\hassan\locals~1\applic~1" ***

                                *** Recherche dossiers dans "C:\Documents and Settings\hassan\menudm~1\progra~1" ***

                                *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                                pour + d'infos : http://www.gmer.net

                                *** Recherche avec GenericNaviSearch ***
                                !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                                !!! A vérifier impérativement avant toute suppression manuelle !!!

                                * Recherche dans "C:\WINDOWS\system32" *

                                Fichiers suspects :

                                nsinet.exe trouvé !

                                * Recherche dans "C:\Documents and Settings\hassan\locals~1\applic~1" *

                                Fichiers trouvés :

                                yuyiu.exe trouvé !
                                yuyiu.dat trouvé !
                                yuyiu_nav.dat trouvé !
                                yuyiu_navps.dat trouvé !

                                *** Recherche fichiers ***

                                C:\WINDOWS\dialerexe.ini trouvé !

                                *** Recherche clés spécifiques dans le Registre ***

                                *** Module de Recherche complémentaire ***
                                (Recherche fichiers spécifiques)

                                1)Recherche nouveaux fichiers Instant Access :

                                C:\WINDOWS\system32\nsinet.exe trouvé !

                                2)Recherche Heuristique :

                                * Dans "C:\WINDOWS\system32" :

                                * Dans "C:\Documents and Settings\hassan\locals~1\applic~1" :

                                yuyiu.dat trouvé !
                                yuyiu.exe trouvé !
                                yuyiu_nav.dat trouvé !
                                yuyiu_navps.dat trouvé !

                                3)Recherche Certificats :

                                Certificat Egroup trouvé !
                                Certificat Electronic-Group trouvé !
                                Certificat Montorgueil absent !
                                Certificat OOO-Favorit trouvé !
                                Certificat Sunny-Day-Design-Ltd absent !

                                4)Recherche fichiers connus :

                                *** Analyse terminée le 02/10/2008 à 18:56:38,76 ***
                                -1
                                1. Contributeur sécurité
                                  Clique sur ce lien :
                                  http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
                                  Clique sur navilog1.exe pour télécharger navilog1
                                  Choisis Enregistrer

                                  et enregistre-le sur ton bureau.

                                  Ensuite double clique sur navilog1.exe pour lancer l'installation.
                                  Une fois l'installation terminée, le fix s'exécutera automatiquement.
                                  (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

                                  Laisse-toi guider. Au menu principal, choisis 1 et valide.
                                  (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

                                  Patiente jusqu'au message :
                                  *** Analyse Terminée le ..... ***
                                  Appuie sur une touche comme demandé, le bloc note va s'ouvrir.
                                  Copie-colle l'intégralité dans une réponse. Referme le bloc note.
                                  Le rapport est en outre sauvegardé à la racine du disque (C:\fixnavi.txt)
                                  poste le rapport obtenu
                                  -1
                                  1. bonjour, voilà
                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 18:37, on 02/10/2008
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    C:\WINDOWS\system32\srksrv.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    C:\WINDOWS\system32\WgaTray.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\WINDOWS\RTHDCPL.EXE
                                    C:\WINDOWS\system32\igfxtray.exe
                                    C:\WINDOWS\system32\hkcmd.exe
                                    C:\WINDOWS\system32\igfxsrvc.exe
                                    C:\WINDOWS\system32\igfxpers.exe
                                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                    C:\Program Files\MSN Messenger\MsnMsgr.Exe
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\Program Files\Ares\Ares.exe
                                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    C:\Program Files\Alwact\Bin\Alwact.exe
                                    C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
                                    C:\documents and settings\hassan\local settings\application data\yuyiu.exe
                                    C:\Program Files\Messenger\msmsgs.exe
                                    C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe
                                    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                                    C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
                                    C:\Program Files\Menara\dslmon.exe
                                    C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
                                    C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
                                    C:\Program Files\Fichiers communs\Nokia\MPAPI\MPAPI3s.exe
                                    C:\Program Files\LG Electronics\Modem USB LG Electronics\IEUM.exe
                                    C:\program files\internet explorer\iexplore.exe
                                    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                    C:\Program Files\MSN Messenger\usnsvc.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                    C:\WINDOWS\system32\NOTEPAD.EXE

                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.kooora.com/
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php
                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Menara
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
                                    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                                    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                                    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                                    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                    O4 - HKLM\..\Run: [TXP] c:\program files\topthemesxp\txp.exe
                                    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                                    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                                    O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
                                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
                                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    O4 - HKCU\..\Run: [Alwact.exe] C:\Program Files\Alwact\Bin\Alwact.exe
                                    O4 - HKCU\..\Run: [UMService] C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
                                    O4 - HKCU\..\Run: [yuyiu] "c:\documents and settings\hassan\local settings\application data\yuyiu.exe" yuyiu
                                    O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
                                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                    O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
                                    O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
                                    O4 - Global Startup: DSLMON.lnk = C:\Program Files\Menara\dslmon.exe
                                    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
                                    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
                                    O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
                                    O17 - HKLM\System\CCS\Services\Tcpip\..\{EDF3D966-F49B-43D1-882E-D903E80F5C44}: NameServer = 192.168.50.55 196.12.209.6
                                    O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: PoliceService - Unknown owner - C:\WINDOWS\system32\srksrv.exe
                                    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                                    -1
                                    1. Contributeur sécurité
                                      Bonjour

                                      Télécharge le fichier d’installation d’Hijackthis en cliquant sur ce lien

                                      http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

                                      * Enregistre HJTInstall.exe sur ton bureau.

                                      * Double-clique sur HJTInstall.exe pour lancer le programme

                                      Tuto : https://www.malekal.com/tutoriel-hijackthis/
                                      http://pagesperso-orange.fr/rginformatique/section%20virus/Hijenr.gif
                                      http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm

                                      * Accepte la license en cliquant sur le bouton "I Accept"
                                      * Choisis l'option "Do a system scan and save a log file"
                                      * Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
                                      * Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

                                      * Colle le rapport que tu viens de copier sur ce forum
                                      -1