Infesté par navipromo

Bonjour,
je viens de faire reinstallé mon ordi et voilà que je suis déjà infecté par 2 navipromo.bqx et l'autre je ne me rappelle plus. Enfin bref j'ai pas trop les moyens de le ramener maintenant et j'aimerais vraiement le desinfecté. Quelqu'un pourrait il m'aider. D'avance merci
Configuration: Windows XP
Internet Explorer 7.0

30 réponses

Résumé de la discussion

Une personne ayant réinstallé son ordinateur se retrouve infectée par deux malwares, dont navipromo.bqx, et cherche une désinfection efficace sous Windows XP et Internet Explorer 7. Des conseils portent sur l’utilisation de l’outil Navilog avec l’option 1 puis vérification, et sur l’éventualité de lancer l’option 2 seulement après avis, afin d’éviter une désinfection invalide. D’autres évoquent des scans avec des outils comme Bitdefender ou SiSoftware Sandra, et rapportent des difficultés lorsque certains programmes ne sont pas installés, ce qui peut compliquer l’obtention d’un nettoyage complet. En cas de doute, des échanges portent aussi sur le fait que des rapports navilog doivent être copiés et partagés pour évaluer correctement les infections et adapter l’étape suivante.

Bobot (l’IA à votre service)
  1. dejàa 1ere chose tu fais un scan online sur bitdefender.fr et tu postes le rapport içi.
    -1
    1. bonsoir et merci de ta reponse si rapide, mais j'ai déjà bit defender en anti virus et je n'arrive pas à scanner en ligne. J'ai un bloccage de sa part pour analyser un dossier charger sur internet et enregistrer sous mes documents. De plus il y a un site : 000 favorite qui me propose de charger un logiciel pour desinstaller navipromo mais je n'arrive pas à le scanner avec bit defender alors je le dezip pas.
      0
    2. @virgogineBjr,
      pour le scan en ligne faut le faire sous internet explorer.
      Scanne ton PC avec un [httpwww.bitdefender.comscan8ie.html BitDefender en ligne] (uniquement sous Internet Explorer)
      0
    3. @Utilisateur anonymemais je suis déjà sous internet explorer ou alors je comprend plus rien à rien
      0
    4. @virgoginePeux tu effectuer le poste 6 stp ?
      0
  2. Contributeur sécurité
    télécharge navilog:http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
    fais l'option 1 puis copie/colle ton rapport ici
    ne fais pas l'option 2 sans avis!
    0
    1. Search Navipromo version 3.3.6 commencé le 05/12/2007 à 22:18:22,01

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

      Outil exécuté depuis C:\Program Files\navilog1
      Mise à jour le 14.11.2007 à 18h00 par IL-MAFIOSO

      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 7.0.5730.13

      *** Recherche Programmes installés ***

      *** Recherche dossiers dans C:\WINDOWS ***

      *** Recherche dossiers dans C:\Program Files ***

      C:\Program Files\MessengerSkinner trouvé !

      *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

      *** Recherche dossiers dans C:\Documents and Settings\laurence\Application Data ***

      ...\Application Data\MessengerSkinner trouvé !

      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net

      Aucun fichier trouvé dans :

      - C:\WINDOWS\system32
      - C:\DOCUME~1\LAURENCE\LOCALS~1\APPLIC~1

      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!

      * Recherche dans C:\WINDOWS\system32 *

      Fichiers suspects :

      * Recherche dans C:\DOCUME~1\LAURENCE\LOCALS~1\APPLIC~1 *

      Fichiers trouvés :

      ognvfnfmue.exe trouvé !
      ognvfnfmue_m2s.xml trouvé !

      *** Recherche fichiers ***

      C:\WINDOWS\system32\nvs2.inf trouvé !

      *** Recherche clés spécifiques dans le Registre ***

      HKEY_CURRENT_USER\Software\Lanconfig trouvé !

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche fichiers connus:

      2)Recherche Heuristique :

      C:\DOCUME~1\LAURENCE\LOCALS~1\APPLIC~1\ognvfnfmue.dat trouvé !

      3)Recherche Certificats :

      Certificat Egroup trouvé !

      *** Analyse terminée le 05/12/2007 à 22:19:42,09 ***
      0
  3. jfk t'es gentil mais ton idée je l'ai eu avant toi. N'essaye pas d'aller plus vite que la musique ça sert à rien parce que si il faut elle est infectée par 10 autres trucs et ni toi ni elle ne le savent pas..alors bon..
    -2
    1. Salut,
      je vous laisse suivre....

      A+
      0
  4. Contributeur sécurité
    d'accord avec toi surtout quand j'ai vu:navipromo.bqx
    bqx m'a intrigué dans un premier temps
    mais ca reste un post pour supprimer navipromo?
    0
    1. Salut,

      Il te faut une mise à jour, un parefeu, un antivirus et des antispyware(s)....

      > Télécharge SiSoftware Sandra Lite XIIc,
      puis
      0
      1. pourquoi SiSoftware Sandra Lite XIIc ?

        0
      2. @orb42Je préfers ce message,
        0
      3. heuuu, mais j'ai déjà tous ca
        0
      4. donc voilà :
        SiSoftware Sandra

        Système
        Nom de l'Hôte : PCBUREAU
        Utilisateur : laurence
        Groupe de Travail : MSHOME

        Processeur
        Modèle : Intel(R) Celeron(R) CPU 2.66GHz
        Vitesse : 2.67GHz
        Noyaux par Processeur : 1 Unité(s)
        Threads par Noyau : 1 Unité(s)
        Cache de Données Interne : 1x 16kB, Synchrone, Ecriture Directe, jeu à 8 voies, 64 octets de taille de ligne
        Cache sur Carte L2 : 1x 256kB, ECC, Synchrone, ATC, jeu à 4 voies, 64 octets de taille de ligne, 2 lignes par secteur

        Système
        Système : P4VM800
        Carte mère : P4VM800
        Bus : AGP PCI IMB USB i2c/SMBus
        Support MP : 1 Processeur(s)
        APIC MP : Oui
        BIOS Système : American Megatrends Inc. P1.30
        Mémoire Totale : 1GB DDR-SDRAM

        Chipset 1
        Modèle : ASRock Inc Standard Host Bridge
        Vitesse du Bus Principal : 4x 133MHz (532MHz taux de transfert)
        Mémoire Totale : 1GB DDR-SDRAM
        Vitesse du Bus Mémoire : 2x 166MHz (332MHz taux de transfert)

        Système Vidéo
        Moniteur/Panneau : Écran Plug-and-Play
        Adaptateur : RADEON 9550
        Adaptateur : RADEON 9550 Secondary
        Périphérique d'Images : Labtec WebCam Pro

        Dispositifs de Stockage Physiques
        Maxtor 6Y120L0 (ATA) : 114GB (C:)
        BENQ DVD DD DW1650 (ATAPI) : 530MB (D:)

        Dispositifs de Stockage Logiques
        Disque Dur (C:) : 114GB (102GB, 89% Espace Libre) (NTFS) @ Maxtor 6Y120L0 (ATA)
        ZT2ZCD1 (D:) : 529MB (CDFS) @ BENQ DVD DD DW1650 (ATAPI)
        3.5" 1.44Mo (A:) : N/A

        Périphériques
        Port(s) Série/Parallèle : 1 COM / 1 LPT
        Contrôleur USB/Hub : Contrôleur hôte universel USB Rev 5 ou ultérieur VIA
        Contrôleur USB/Hub : Contrôleur hôte universel USB Rev 5 ou ultérieur VIA
        Contrôleur USB/Hub : Contrôleur hôte universel USB Rev 5 ou ultérieur VIA
        Contrôleur USB/Hub : Contrôleur hôte universel USB Rev 5 ou ultérieur VIA
        Contrôleur USB/Hub : Contrôleur hôte étendu USB VIA
        Contrôleur USB/Hub : Concentrateur USB racine
        Contrôleur USB/Hub : Concentrateur USB racine
        Contrôleur USB/Hub : Concentrateur USB racine
        Contrôleur USB/Hub : Concentrateur USB racine
        Contrôleur USB/Hub : Concentrateur USB racine
        Contrôleur USB/Hub : Périphérique USB composite
        Clavier : Clavier standard 101/102 touches ou clavier Microsoft Natural Keyboard PS/2
        Souris : Souris Microsoft PS/2

        Dispositif(s) Multimédia
        Dispositif : C-Media AC97 Audio Device

        Gestion de l'Énergie
        Etat de la Ligne AC : Connecté

        Système(s) d'Exploitation
        Système Windows : Microsoft Windows XP (2002) Personnel 5.01.2600 (Service Pack 2)
        Compatibilité de Plate-forme : Win32 x86

        Services Réseau
        Adaptateur : Carte Fast Ethernet compatible VIA

        Conseils de Performance
        Conseil 2546 : Les gros modules de mémoire devraient être ECC/Parités.
        Conseil 2 : Double-cliquez sur le Conseil ou appuyez sur la touche Enter si le Conseil est sélectionné pour en savoir plus concernant cet élément.
        0
    2. MMMmm
      MessengerSkinner...

      virgogine,

      Poste nous un rapport HijackThis stp,

      Télécharge HiJackThis
      0
      1. Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 00:16:49, on 08/12/2007
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16544)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Windows Defender\MsMpEng.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
        C:\WINDOWS\System32\FTRTSVC.exe
        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        C:\Program Files\Spyware Doctor\svcntaux.exe
        C:\Program Files\Spyware Doctor\swdsvc.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\wdfmgr.exe
        C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
        C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
        C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\WINDOWS\system32\RunDll32.exe
        C:\Program Files\Spyware Doctor\SDTrayApp.exe
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
        C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe
        C:\WINDOWS\System32\alg.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
        C:\PROGRA~1\Wanadoo\ComComp.exe
        C:\PROGRA~1\Wanadoo\Toaster.exe
        C:\PROGRA~1\Wanadoo\Inactivity.exe
        C:\PROGRA~1\Wanadoo\PollingModule.exe
        C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
        C:\PROGRA~1\Wanadoo\Watch.exe
        C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
        C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
        C:\Program Files\Google\Google Updater\GoogleUpdater.exe
        C:\Program Files\Windows Live\Messenger\usnsvc.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\Documents and Settings\laurence\Mes documents\eMule\emule.exe
        C:\Program Files\BitDefender\BitDefender 2008\uiscan.exe
        C:\WINDOWS\explorer.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
        R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
        O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)
        O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
        O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
        O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
        O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
        O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe" /minimized
        O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
        O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: AVG Anti-Spyware 7.5
        O4 - Global Startup: BTTray.lnk = ?
        O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
        O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
        O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
        O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
        O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
        O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
        O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\Win32\RpcDataSrv.exe
        O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\RpcSandraSrv.exe
        O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
        O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
        O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
        O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
        0
    3. RE,

      je regarde ton log...

      tu n'as que le parefeu windows ?
      > Télécharge Zone Alarme, en cas de problème
      > Télécharge Ccleaner, si besoin est tu trouveras des Tutoriaux ici,
      ici et là
      0
      1. je t'envoie le rapport d'avg
        ---------------------------------------------------------
        AVG Anti-Spyware - Rapport d'analyse
        ---------------------------------------------------------

        + Créé à: 07:57:54 08/12/2007

        + Résultat de l'analyse:

        C:\Documents and Settings\laurence\Cookies\laurence@2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@himedia.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@adtech[2].txt -> TrackingCookie.Adtech : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA2D7LG3.txt -> TrackingCookie.Advertising : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAA3FYF6.txt -> TrackingCookie.Advertising : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAHZMUQB.txt -> TrackingCookie.Advertising : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAN8RMPK.txt -> TrackingCookie.Advertising : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAOJNJ72.txt -> TrackingCookie.Advertising : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAOL4B1L.txt -> TrackingCookie.Advertising : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAPQ2DBR.txt -> TrackingCookie.Advertising : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAV4APPV.txt -> TrackingCookie.Advertising : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAYC1TZF.txt -> TrackingCookie.Advertising : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@advertising[1].txt -> TrackingCookie.Advertising : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@advertising[2].txt -> TrackingCookie.Advertising : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@advertising[4].txt -> TrackingCookie.Advertising : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@atdmt[2].txt -> TrackingCookie.Atdmt : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA2KWOO5.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA6OOOH9.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA74GM9D.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA7BW6D7.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAF21FKW.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAGA203L.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAHSAA7E.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAL3M81Y.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAPIF7KC.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@bluestreak[1].txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@bluestreak[2].txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@bluestreak[4].txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@doubleclick[1].txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA4AYJD9.txt -> TrackingCookie.Euroclick : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA6OHIHG.txt -> TrackingCookie.Euroclick : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAF85G77.txt -> TrackingCookie.Euroclick : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAG5V26T.txt -> TrackingCookie.Euroclick : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@mediaplex[1].txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA0GZSPA.txt -> TrackingCookie.Netflame : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA0K7HQ9.txt -> TrackingCookie.Netflame : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAL2YQNW.txt -> TrackingCookie.Netflame : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAPZPJF5.txt -> TrackingCookie.Netflame : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAVWIBH0.txt -> TrackingCookie.Netflame : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA0WGGAM.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA0Z1KYA.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA160JO8.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA1SR5N6.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA2VXVZZ.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA3WFA8J.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA40S1ZS.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA5WLKPY.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA67KK1W.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA6RWGFK.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA8INRJU.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAAQL2DG.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAARPDDB.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CADKC311.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAHP9JIZ.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAJ3XEOV.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAJSHTNR.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAKK0HTD.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAMXW12N.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CANHEETE.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAO54X85.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CARFWZ7S.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CARM3JBY.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CASPII2I.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAW6PMT9.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAXY9E7C.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@serving-sys[2].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@serving-sys[4].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA0UG0N9.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA2RZT55.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA3GY77B.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA4W0RE7.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA7J3HGT.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA7S3LJD.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA8EES37.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA8US135.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAEPUD9T.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAF4ZKSB.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAK84NXE.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAO4EH3V.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAOWBMJS.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAQQ7DXZ.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAR1VYDF.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAS352YN.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAVJRPOF.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAWTBO5S.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAYV3QLH.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAZPGFPE.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@smartadserver[1].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@smartadserver[2].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@smartadserver[4].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@tradedoubler[3].txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA2VXAOC.txt -> TrackingCookie.Weborama : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CA3KI9MJ.txt -> TrackingCookie.Weborama : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@CAYR5OHB.txt -> TrackingCookie.Weborama : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@weborama[1].txt -> TrackingCookie.Weborama : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@weborama[2].txt -> TrackingCookie.Weborama : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@weborama[3].txt -> TrackingCookie.Weborama : Aucune action entreprise.
        C:\Documents and Settings\laurence\Cookies\laurence@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.

        Fin du rapport

        et merci de ton aide
        0
      2. je n'ai pas trouver l'onglet erreur dans ccleaner mais bon pour le reste j'ai bien tout suivie tes instruction et je t'envoie mon rapport hijackthis après redemarrage de mon pc.
        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 08:39:14, on 08/12/2007
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16544)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Windows Defender\MsMpEng.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\ZoneLabs\vsmon.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
        C:\WINDOWS\System32\FTRTSVC.exe
        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        C:\Program Files\Spyware Doctor\svcntaux.exe
        C:\Program Files\Spyware Doctor\swdsvc.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Spyware Doctor\SDTrayApp.exe
        C:\WINDOWS\system32\wdfmgr.exe
        C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\WINDOWS\system32\RunDll32.exe
        C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe
        C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
        C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
        C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
        C:\Program Files\Google\Google Updater\GoogleUpdater.exe
        C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
        C:\PROGRA~1\Wanadoo\ComComp.exe
        C:\PROGRA~1\Wanadoo\Toaster.exe
        C:\PROGRA~1\Wanadoo\Inactivity.exe
        C:\PROGRA~1\Wanadoo\PollingModule.exe
        C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
        C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
        C:\WINDOWS\System32\alg.exe
        C:\PROGRA~1\Wanadoo\Watch.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
        R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
        R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
        O2 - BHO: (no name) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O3 - Toolbar: (no name) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - (no file)
        O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
        O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
        O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
        O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
        O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
        O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe" /minimized
        O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
        O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
        O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: AVG Anti-Spyware 7.5
        O4 - Global Startup: BTTray.lnk = ?
        O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
        O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
        O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
        O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
        O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
        O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
        O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\Win32\RpcDataSrv.exe
        O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\RpcSandraSrv.exe
        O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
        O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
        O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
        O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
        O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
        0
    4. Contributeur sécurité
      re,
      dans le rapport navilog on voit que l'infection vient de messenger skinner:C:\Program Files\MessengerSkinner trouvé !
      pourquoi ne pas faire l'option 2 maintenant et vérification apres???
      1
      1. Salut,

        Oui MessengerSkinner a encore frappé....avec ses fichiers .dat

        0
        1. j'ai fait ce que jfk avait noté pour navilog option 2 mais après scan avec bit defender navipro etait toujours là oh rage et desespoir
          pour ton message dlld je n'ai pas les programmes que tu m'indiques dans ajout/suppression de programme. J'ai juste window live installer et window live messenger.
          Je suis un peu desesperer et compte sur vous pour votre aide. Merci de rester dans la chasse comme tu dis.
          0
      2. Contributeur sécurité
        merci a toi dlld j'ai besoin d'etre épaulé des fois que!
        virgoginie:option 2 (desinfection auto)puis poste le rapport obtenu
        1
        1. Voici donc le rapport de navilog que jfkpresident m'a demandé et merci de votre aide j'espère que je me sortirai de ce virus. Sinon il y a un site 000favorit qui propose un logiciel de desinstalllation de navipromo. Qu'en pensez vous ?

          *** fsbl1.txt non trouvé ***
          (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

          *** Suppression avec sauvegardes résultats GenericNaviSearch ***

          * Suppression dans C:\WINDOWS\System32 *

          * Suppression dans C:\DOCUME~1\LAURENCE\LOCALS~1\APPLIC~1 *

          *** Suppression dossiers dans C:\WINDOWS ***

          *** Suppression dossiers dans C:\Program Files ***

          *** Suppression dossiers dans C:\Documents and Settings\All Users\Application Data ***

          *** Suppression dossiers dans C:\Documents and Settings\laurence\Application Data ***

          *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

          *** Suppression fichiers ***

          *** Suppression fichiers temporaires ***

          Nettoyage contenu C:\WINDOWS\Temp effectué !
          Nettoyage contenu C:\Documents and Settings\laurence\Local Settings\Temp effectué !

          *** Traitement Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Recherche fichiers connus:

          2)Recherche, création sauvegardes et suppression Heuristique :

          *** Sauvegarde du Registre vers dossier Backupnavi ***

          sauvegarde du Registre réalisé avec succès !

          *** Nettoyage Registre ***

          Nettoyage Registre Ok

          *** Certificats ***

          Certificat Egroup absent !

          *** Fichiers suspects non supprimés par Navilog1 ***
          !! Fichiers légitimes possibles, à contrôler avant suppression !!

          *** Nettoyage terminé le 08/12/2007 à 11:36:50,23 ***
          0
        2. Re,

          elle est bien infectée...

          Sinon il y a un site 000favorit qui propose un logiciel de desinstalllation de navipromo. Qu'en pensez vous ?
          Il existe de multiples façons de ce débarasser de cette crasse mais je suis au regret de te dire que tu n'as pas que ça....
          0
      3. virgoginie,

        Peux-tu te rendre sur ce site virustotal ou virusscan.jotti et faire analyser les fichiers suivants (s'ils existent encore) :
        0
        1. J'ai un peu du mal avec ces programmes et je n'arrive pas a vous envoyer le rapport mais quand je scan msn messenger il apparait que fileAdvisor Low threat detected
          0
        2. @virgoginieOk pour les fichiers où il met 'no found' ou rien, n'envoie pas de rapport.

          Pour les autres (attends bien qu'il est terminé l'analyse) :
          puis :
          0
      4. Contributeur sécurité
        virustotal tres bien pour analyser des fichiers précis
        0
        1. jfkpresident,

          je trouve le deuxième rappot navilog pas très bavard...
          On pourrait recommancer l'étape de détection (1), qu'en penses-tu ?
          0
        2. @Utilisateur anonymedesolé, obligé de reprendre mes occupation de maman, je reviens lundi soir pour voir si vous voulez bien encore m'aider. Merci pour votre patience et gentillesse a lundi si vous le voulez bien donc
          0
        3. Contributeur sécurité
          @Utilisateur anonymece serait préférable effectivement
          0
      5. Bonsoir, bonsoir.....

        peux-tu refaire le poste 2 stp.

        télécharge navilog:http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
        fais l'option 1 puis copie/colle ton rapport ici
        ne fais pas l'option 2 sans avis!
        0
        1. Search Navipromo version 3.3.6 commencé le 10/12/2007 à 22:13:24,59

          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
          !!! Postez ce rapport sur le forum pour le faire analyser !!!
          !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

          Outil exécuté depuis C:\Program Files\navilog1
          Mise à jour le 14.11.2007 à 18h00 par IL-MAFIOSO

          Microsoft Windows XP [version 5.1.2600]
          Internet Explorer : 7.0.5730.13

          *** Recherche Programmes installés ***

          *** Recherche dossiers dans C:\WINDOWS ***

          *** Recherche dossiers dans C:\Program Files ***

          *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

          *** Recherche dossiers dans C:\Documents and Settings\laurence\Application Data ***

          *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

          *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
          pour + d'infos : http://www.gmer.net

          Aucun fichier trouvé dans :

          - C:\WINDOWS\system32
          - C:\DOCUME~1\LAURENCE\LOCALS~1\APPLIC~1

          *** Recherche avec GenericNaviSearch ***
          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
          !!! A vérifier impérativement avant toute suppression manuelle !!!

          * Recherche dans C:\WINDOWS\system32 *

          Fichiers suspects :

          * Recherche dans C:\DOCUME~1\LAURENCE\LOCALS~1\APPLIC~1 *

          *** Recherche fichiers ***

          *** Recherche clés spécifiques dans le Registre ***

          *** Module de Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Recherche fichiers connus:

          2)Recherche Heuristique :

          3)Recherche Certificats :

          Certificat Egroup absent !

          *** Analyse terminée le 10/12/2007 à 22:14:44,14 ***
          0
      6. Contributeur sécurité
        une fois de plus pas tres bavard ce rapport
        0
        1. En effet mais l'ordi semble sain,
          0
          1. oui, toujours - analyser avec bitdefender
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 22:53:29, on 10/12/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16544)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Defender\MsMpEng.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
            C:\WINDOWS\System32\FTRTSVC.exe
            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            C:\Program Files\Spyware Doctor\svcntaux.exe
            C:\Program Files\Spyware Doctor\swdsvc.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\wdfmgr.exe
            C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
            C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\alg.exe
            C:\Program Files\Spyware Doctor\SDTrayApp.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\WINDOWS\system32\RunDll32.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe
            C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
            C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
            C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
            C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
            C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
            C:\Program Files\Google\Google Updater\GoogleUpdater.exe
            C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
            C:\PROGRA~1\Wanadoo\ComComp.exe
            C:\PROGRA~1\Wanadoo\Toaster.exe
            C:\PROGRA~1\Wanadoo\Inactivity.exe
            C:\PROGRA~1\Wanadoo\PollingModule.exe
            C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
            C:\PROGRA~1\Wanadoo\Watch.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\WINDOWS\system32\msiexec.exe
            C:\Program Files\Windows Live\installer\WLSetupSvc.exe
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
            R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
            R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
            O2 - BHO: (no name) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O3 - Toolbar: (no name) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - (no file)
            O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
            O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
            O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
            O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
            O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
            O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe" /minimized
            O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
            O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
            O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: AVG Anti-Spyware 7.5
            O4 - Global Startup: BTTray.lnk = ?
            O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
            O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
            O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
            O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
            O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
            O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
            O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\Win32\RpcDataSrv.exe
            O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\RpcSandraSrv.exe
            O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
            O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
            O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
            0
        2. Re,

          pour info
          0
          1. bonjour et encore merci pour ton aide je ne faire que ceci, mais bon voici mon rapport hijackthis après avoir suivie toutes tes consignes
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 10:51:39, on 11/12/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16544)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Defender\MsMpEng.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
            C:\WINDOWS\System32\FTRTSVC.exe
            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            C:\Program Files\Spyware Doctor\svcntaux.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Spyware Doctor\swdsvc.exe
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\WINDOWS\system32\RunDll32.exe
            C:\Program Files\Spyware Doctor\SDTrayApp.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe
            C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
            C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
            C:\WINDOWS\system32\svchost.exe
            C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
            C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\WINDOWS\system32\wdfmgr.exe
            C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
            C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
            C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
            C:\Program Files\Google\Google Updater\GoogleUpdater.exe
            C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
            C:\PROGRA~1\Wanadoo\ComComp.exe
            C:\PROGRA~1\Wanadoo\Toaster.exe
            C:\PROGRA~1\Wanadoo\Inactivity.exe
            C:\PROGRA~1\Wanadoo\PollingModule.exe
            C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
            C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
            C:\WINDOWS\System32\alg.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\PROGRA~1\Wanadoo\Watch.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
            O2 - BHO: (no name) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
            O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
            O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
            O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
            O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\avgas.exe" /minimized
            O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
            O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
            O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: AVG Anti-Spyware 7.5
            O4 - Global Startup: BTTray.lnk = ?
            O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
            O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
            O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Documents and Settings\laurence\Bureau\AVG Anti-Spyware 7.5\guard.exe
            O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
            O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
            O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
            O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\Win32\RpcDataSrv.exe
            O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\RpcSandraSrv.exe
            O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
            O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
            O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
            0
        3. Bonsoir,
          comment se comporte le PC?
          A+
          --
          0
          1. bonjour,
            il y a un leger mieux mais bitdefender me dit que maintenant il y 5 fichiers infestés par navipromo.
            0
        4. Re,
          JFK, si t'es encore là....

          > Essaye d'installer Antivir : ouvre ce lien, lis le tuto, télécharge Antivir.
          Tu peux aussi télecharger Antivir ICI.

          > télécharge GenProc http://www.alt-shift-return.org/Info/Fichiers/GenProc.zip sur ton bureau
          0
          1. Contributeur sécurité
            je suis encore la .
            fais ce que te dit dlld post 45 et je jetterai un coup d'oeil sur les rapports;
            0
          2. re, je n'ai plus accés à ma messagerie mais je vous envoie le rapport antivir

            AntiVir PersonalEdition Classic
            Report file date: mercredi 12 décembre 2007 17:02

            Scanning for 971385 virus strains and unwanted programs.

            Licensed to: Avira AntiVir PersonalEdition Classic
            Serial number: 0000149996-ADJIE-0001
            Platform: Windows XP
            Windows version: (Service Pack 2) [5.1.2600]
            Username: SYSTEM
            Computer name: PCBUREAU

            Version information:
            BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
            AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
            AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
            LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
            LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
            ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
            ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 14:26:55
            ANTIVIR2.VDF : 7.0.1.30 1575424 Bytes 30/11/2007 16:00:48
            ANTIVIR3.VDF : 7.0.1.80 214528 Bytes 12/12/2007 16:00:48
            AVEWIN32.DLL : 7.6.0.40 3064320 Bytes 12/12/2007 16:00:49
            AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
            AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
            AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
            AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 08:46:00
            AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
            AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
            AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
            NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
            RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
            RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
            SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

            Configuration settings for the scan:
            Jobname..........................: Complete system scan
            Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
            Logging..........................: low
            Primary action...................: interactive
            Secondary action.................: ignore
            Scan master boot sector..........: off
            Scan boot sector.................: on
            Boot sectors.....................: C:,
            Scan memory......................: on
            Process scan.....................: on
            Scan registry....................: on
            Search for rootkits..............: off
            Scan all files...................: Intelligent file selection
            Scan archives....................: on
            Recursion depth..................: 20
            Smart extensions.................: on
            Macro heuristic..................: on
            File heuristic...................: medium

            Start of the scan: mercredi 12 décembre 2007 17:02

            The scan of running processes will be started
            Scan process 'avscan.exe' - '1' Module(s) have been scanned
            Scan process 'avcenter.exe' - '1' Module(s) have been scanned
            Scan process 'sched.exe' - '1' Module(s) have been scanned
            Scan process 'avgnt.exe' - '1' Module(s) have been scanned
            Scan process 'avguard.exe' - '1' Module(s) have been scanned
            Scan process 'iexplore.exe' - '1' Module(s) have been scanned
            Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
            Scan process 'emule.exe' - '1' Module(s) have been scanned
            Scan process 'Watch.exe' - '1' Module(s) have been scanned
            Scan process 'ALERTM~1.EXE' - '1' Module(s) have been scanned
            Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
            Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
            Scan process 'Toaster.exe' - '1' Module(s) have been scanned
            Scan process 'ComComp.exe' - '1' Module(s) have been scanned
            Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
            Scan process 'NMIndexStoreSvr.exe' - '1' Module(s) have been scanned
            Scan process 'alg.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '0' Module(s) have been scanned
            Scan process 'NMIndexingService.exe' - '1' Module(s) have been scanned
            Scan process 'GoogleUpdater.exe' - '1' Module(s) have been scanned
            Scan process 'BTTray.exe' - '1' Module(s) have been scanned
            Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
            Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
            Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
            Scan process 'NMBgMonitor.exe' - '1' Module(s) have been scanned
            Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
            Scan process 'zlclient.exe' - '0' Module(s) have been scanned
            Scan process 'bdagent.exe' - '1' Module(s) have been scanned
            Scan process 'avgas.exe' - '1' Module(s) have been scanned
            Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
            Scan process 'rundll32.exe' - '1' Module(s) have been scanned
            Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
            Scan process 'livesrv.exe' - '0' Module(s) have been scanned
            Scan process 'vsserv.exe' - '0' Module(s) have been scanned
            Scan process 'xcommsvr.exe' - '0' Module(s) have been scanned
            Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
            Scan process 'SDTrayApp.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'explorer.exe' - '1' Module(s) have been scanned
            Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
            Scan process 'swdsvc.exe' - '1' Module(s) have been scanned
            Scan process 'svcntaux.exe' - '1' Module(s) have been scanned
            Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
            Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
            Scan process 'guard.exe' - '0' Module(s) have been scanned
            Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
            Scan process 'vsmon.exe' - '0' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'btwdins.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'MsMpEng.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
            Scan process 'lsass.exe' - '1' Module(s) have been scanned
            Scan process 'services.exe' - '1' Module(s) have been scanned
            Scan process 'winlogon.exe' - '1' Module(s) have been scanned
            Scan process 'csrss.exe' - '1' Module(s) have been scanned
            Scan process 'smss.exe' - '1' Module(s) have been scanned
            53 processes with 53 modules were scanned

            Start scanning boot sectors:
            Boot sector 'C:\'
            [NOTE] No virus was found!

            Starting to scan the registry.
            The registry was scanned ( '29' files ).

            Starting the file scan:

            Begin scan in 'C:\'
            C:\pagefile.sys
            [WARNING] The file could not be opened!
            C:\Program Files\Navilog1\Backupnavi\ognvfnfmue.exe
            [DETECTION] Is the Trojan horse TR/Dropper.Gen
            [INFO] The file was deleted!
            C:\System Volume Information\_restore{09B1298D-ED77-4BB7-A8E9-8BCE24EA457C}\RP39\A0006949.exe
            [DETECTION] Is the Trojan horse TR/Dropper.Gen
            [INFO] The file was moved to '47900c87.qua'!
            C:\System Volume Information\_restore{09B1298D-ED77-4BB7-A8E9-8BCE24EA457C}\RP55\A0010866.exe
            [DETECTION] Is the Trojan horse TR/Dropper.Gen
            [INFO] The file was moved to '47900d1f.qua'!

            End of the scan: mercredi 12 décembre 2007 18:03
            Used time: 1:00:44 min

            The scan has been done completely.

            2703 Scanning directories
            60445 Files were scanned
            3 viruses and/or unwanted programs were found
            0 Files were classified as suspicious:
            1 files were deleted
            0 files were repaired
            2 files were moved to quarantine
            0 files were renamed
            1 Files cannot be scanned
            60442 Files not concerned
            852 Archives were scanned
            1 Warnings
            1 Notes
            0
          3. et voici lRapport GenProc 0.72 [1] effectué le 12/12/2007 à 18:11:18,31 - SystemRoot = C:\WINDOWS

            Dans CCleaner, clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. C'est tout.

            # Etape 1/ Télécharge :

            - Brute Force Uninstaller http://www.merijn.org/files/bfu.zip et décompresse-le dans un dossier propre à lui (C:\BFU)
            * Fais un clic droit de souris sur ce lien : http://perso.orange.fr/Chercheur-perso/scripts/toolbar.bfu
            et choisis "Enregistrer sous" (dans IE c'est "Enregistrer le lien sous..")
            afin de télécharger toolbar.bfu (de Chercheur), Type "Tous les fichiers". Sauvegarde dans le dossier créé (C:\BFU)

            ***** Copie ce qui suit dans un fichier texte et redémarre en mode sans échec comme indiqué ici https://docs.microsoft.com/en-us/?mfr=true (choisis ta session courante "laurence") *****

            # Etape 2/

            * Démarre le "Brute Force Uninstaller" en double-cliquant sur BFU.exe.
            Clique sur le petit dossier jaune, à la droite de la boîte "Scriptline to execute", et double-clique sur : Toolbar.bfu
            - Dans la boîte "Scriptline to execute", tu devrais maintenant voir ceci : C:\BFU\Toolbar.bfu
            Clique sur "Execute" et laisse-le faire son travail.
            Attendre que "Complete script execution" apparaîsse et clique sur OK. Clique exit pour fermer le programme BFU.
            Recommence encore une fois.

            # Etape 3/

            Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.

            # Etape 4/

            Redémarre normalement et poste :
            - Un nouveau rapport HijackThis, toutes fenêtres et applications fermées http://www.trendsecure.com/portal/en-US/threat_analytics/HiJackThis.exe ;

            Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
            e rapport genproc
            0
          4. @virgoginieje n'ai rien compris à ce dernier message. N'empêche que je n'ai plus accés à ma messagerie. Je suis en panique,
            0
        5. Bon bah voilà....
          0
          1. Contributeur sécurité
            coucou MP
            0
          2. oui, plus de mail, je suis obligés de passer par ootlook express sinon je ne vois pas ce que vous me répondez
            0
          3. @virgoginieRe,
            tu passais par quoi avant pour les mails ? (web, msn ?)
            --
            0
          4. @Utilisateur anonymej'ai résolue mon problème de messagerie mais pas celui de 'navipromo'
            0
          5. @virgoginieOK, je vais t'envoyer une recette pour forcer la désinstallation de la crasse cet PM
            0
        • 1
        • 2