Impossible d'ouvrir malwarebytes ?

Bonjour,
je n'arrive plus à ouvrir malwarebytes cela me met le programme a cessé de fonctionner puis je suis obligé de fermer le programme.

merci d'avance pour vos réponses.
Configuration: Windows Vista Internet Explorer 7.0

15 réponses

  1. Salut,

    Que fait tu exactement comme manipulation en cliquant sur l'icône ou double clic ou j'sais pas moi ????
    0
    1. j'ai déjà fait clic droit, double clic et puis je l'ai déjà désinstallé mais rien a faire
      0
      1. Re,

        Clic droit sur l'icône et dans le menue déroulant "exécute en tant qu'administrateur" et cela devrait faire l'affaire ....

        ++
        0
        1. Contributeur sécurité
          salut V-X

          le début de post est ici :http://www.commentcamarche.net/forum/affich 12524059 impossible d ouvrir malwarebytes?#4
          0
          1. Re,

            Rete uniquement sur cette discution et prévient les modérateurs que tu es ici et vais le faire aussi.

            Fait ce qui suit:

            ▶ Télécharge random's system information tool (RSIT) et enregistre le sur ton bureau.

            ▶ Double clique sur RSIT.exe pour lancer l'outil.

            ▶ Clique sur ' continue ' à l'écran Disclaimer.

            ▶ Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

            ▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports séparément.
            ( log.txt & info.txt )

            (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

            Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
            0
            1. voici le log:
              Logfile of random's system information tool 1.06 (written by random/random)
              Run by valerie at 2009-05-19 19:39:28
              Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
              System drive C: has 189 GB (64%) free of 293 GB
              Total RAM: 3069 MB (59% free)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 19:39:46, on 19/05/2009
              Platform: Windows Vista SP1 (WinNT 6.00.1905)
              MSIE: Internet Explorer v8.00 (8.00.6001.18702)
              Boot mode: Normal

              Running processes:
              C:\Windows\system32\Dwm.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\Explorer.EXE
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\hp\support\hpsysdrv.exe
              C:\Windows\System32\rundll32.exe
              C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
              C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
              C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
              C:\Program Files\Windows Live\Family Safety\fsui.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\Echovoice\Gamer Statistics\G15 Echovoice Gamer Statistics.exe
              C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Windows\ehome\ehtray.exe
              C:\Program Files\Steam\Steam.exe
              C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\1\AlertModule.exe
              C:\Windows\ehome\ehmsas.exe
              C:\hp\kbd\kbd.exe
              C:\Program Files\OrangeHSS\Launcher\Launcher.exe
              C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
              C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
              C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
              C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
              C:\Program Files\OrangeHSS\browser\browser.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Windows Live\Toolbar\wltuser.exe
              C:\Program Files\OrangeHSS\Deskboard\deskboard.exe
              C:\Windows\system32\NOTEPAD.EXE
              C:\Windows\system32\NOTEPAD.EXE
              C:\Users\valerie\Desktop\HiJackThis.exe
              C:\Windows\system32\NOTEPAD.EXE
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Windows\system32\SearchProtocolHost.exe
              C:\Windows\system32\SearchFilterHost.exe
              C:\Users\valerie\Desktop\RSIT.exe
              C:\Users\valerie\Desktop\valerie.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2102473
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
              R3 - URLSearchHook: PHPNukeFR Toolbar - {1c491116-c175-45e1-a570-6fb14fea8b7b} - C:\Program Files\PHPNukeFR\tbPHP1.dll
              O1 - Hosts: ::1 localhost
              O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
              O2 - BHO: PHPNukeFR Toolbar - {1c491116-c175-45e1-a570-6fb14fea8b7b} - C:\Program Files\PHPNukeFR\tbPHP1.dll
              O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
              O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
              O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
              O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
              O3 - Toolbar: PHPNukeFR Toolbar - {1c491116-c175-45e1-a570-6fb14fea8b7b} - C:\Program Files\PHPNukeFR\tbPHP1.dll
              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
              O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
              O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
              O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [Echovoice Gamer Statistics] C:\Program Files\Echovoice\Gamer Statistics\G15 Echovoice Gamer Statistics.exe
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
              O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
              O4 - HKCU\..\Run: [Pareto_Update] C:\Program Files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe
              O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
              O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
              O13 - Gopher Prefix:
              O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
              O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
              O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
              O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
              O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
              O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
              O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
              O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
              0
              1. et voici l'autres:
                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 19:35:21, on 19/05/2009
                Platform: Windows Vista SP1 (WinNT 6.00.1905)
                MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                Boot mode: Normal

                Running processes:
                C:\Windows\system32\Dwm.exe
                C:\Windows\system32\taskeng.exe
                C:\Windows\Explorer.EXE
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\hp\support\hpsysdrv.exe
                C:\Windows\System32\rundll32.exe
                C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
                C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
                C:\Program Files\Windows Live\Family Safety\fsui.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\Program Files\Echovoice\Gamer Statistics\G15 Echovoice Gamer Statistics.exe
                C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                C:\Program Files\Windows Sidebar\sidebar.exe
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                C:\Windows\ehome\ehtray.exe
                C:\Program Files\Steam\Steam.exe
                C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\1\AlertModule.exe
                C:\Windows\ehome\ehmsas.exe
                C:\hp\kbd\kbd.exe
                C:\Program Files\OrangeHSS\Launcher\Launcher.exe
                C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
                C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
                C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
                C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
                C:\Program Files\OrangeHSS\browser\browser.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Windows Live\Toolbar\wltuser.exe
                C:\Program Files\OrangeHSS\Deskboard\deskboard.exe
                C:\Program Files\Mozilla Firefox\firefox.exe
                C:\Windows\system32\NOTEPAD.EXE
                C:\Windows\system32\SearchFilterHost.exe
                C:\Users\valerie\Desktop\valerie.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2102473
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
                R3 - URLSearchHook: PHPNukeFR Toolbar - {1c491116-c175-45e1-a570-6fb14fea8b7b} - C:\Program Files\PHPNukeFR\tbPHP1.dll
                O1 - Hosts: ::1 localhost
                O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
                O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                O2 - BHO: PHPNukeFR Toolbar - {1c491116-c175-45e1-a570-6fb14fea8b7b} - C:\Program Files\PHPNukeFR\tbPHP1.dll
                O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
                O3 - Toolbar: PHPNukeFR Toolbar - {1c491116-c175-45e1-a570-6fb14fea8b7b} - C:\Program Files\PHPNukeFR\tbPHP1.dll
                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
                O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [Echovoice Gamer Statistics] C:\Program Files\Echovoice\Gamer Statistics\G15 Echovoice Gamer Statistics.exe
                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                O4 - HKCU\..\Run: [Pareto_Update] C:\Program Files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe
                O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
                O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
                O13 - Gopher Prefix:
                O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
                O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
                O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                0
                1. Re,

                  Tu as une infection.

                  ▶ Désactive le « contrôle des comptes utilisateurs = UAC »
                  (tu le réactiveras après ta désinfection): Ne pas oublier !!
                  Désactiver l'UAC est nécessaire pour pouvoir faire fonctionner certains programmes sous Vista.
                  - Vas dans Démarrer puis panneau de configuration
                  - Double Clique sur l'icône "Comptes d'utilisateurs"
                  - Clique ensuite sur désactiver et valide.
                  - Redémarre ton pc.
                  Comment désactiver L'UAC

                  Télécharge Toolbar-S&D (Team IDN) sur ton Bureau

                  !! Déconnectes toi et fermes toute tes applications en cours le temps de la manipe !!

                  ▶ Double-cliques sur l'.exe pour lancer l'installe et laisses toi guider ...

                  ▶ Une fois fait, cliques sur le raccourci créé sur ton bureau pour lancer l'outil .

                  ▶ Choisis l'option 1 ( "recherche") et tapes "entrée" .

                  ▶Une fois le scan finit , un rapport va apparaître, copie/colles l'intégralité
                  de son contenu dans ta prochaine réponse ...

                  ( le rapport est en outre sauvegardé ici -> C:\TB.txt )

                  Tutoriel Toolbard-S&D

                  Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
                  0
                  1. voici le rapport:
                    -----------\\ ToolBar S&D 1.2.8 XP/Vista

                    Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                    X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU E2200 @ 2.20GHz )
                    BIOS : Phoenix - AwardBIOS v6.00PG
                    USER : valerie ( Administrator )
                    BOOT : Normal boot
                    C:\ (Local Disk) - NTFS - Total:286 Go (Free:184 Go)
                    D:\ (Local Disk) - NTFS - Total:12 Go (Free:1 Go)
                    E:\ (CD or DVD)
                    F:\ (USB)
                    G:\ (USB)
                    H:\ (USB)
                    I:\ (USB)
                    J:\ (USB)
                    K:\ (USB) - FAT - Total:990 Mo (Free:0 Go)
                    L:\ (USB) - FAT32 - Total:3868 Mo (Free:0 Go)
                    M:\ (USB) - FAT - Total:939 Mo (Free:0 Go)

                    "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                    Option : [1] ( 19/05/2009|19:49 )

                    [ UAC => 0 ]

                    -----------\\ Recherche de Fichiers / Dossiers ...

                    -----------\\ [..\Internet Explorer\Main]

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                    "Start Page"="http://search.conduit.com?SearchSource=10&ctid=CT2102473"
                    "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                    "Local Page"="C:\\Windows\\system32\\blank.htm"
                    "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                    "Search Bar"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                    "Default_search_url"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                    "Url"="https://www.msn.com/fr-fr/actualite/"

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                    "Start Page"="https://www.msn.com/fr-fr"
                    "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                    "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                    "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                    "Local Page"="C:\\Windows\\System32\\blank.htm"
                    "Search bar"="http://www.bing.com/spresults.aspx"

                    --------------------\\ Recherche d'autres infections

                    C:\Program Files\Live-Player
                    [b]==> EGDACCESS <==/b

                    [ UAC => 1 ]

                    1 - "C:\ToolBar SD\TB_1.txt" - 23/04/2009|13:44 - Option : [1]
                    2 - "C:\ToolBar SD\TB_2.txt" - 23/04/2009|14:19 - Option : [2]
                    3 - "C:\ToolBar SD\TB_3.txt" - 23/04/2009|14:44 - Option : [2]
                    4 - "C:\ToolBar SD\TB_4.txt" - 23/04/2009|14:54 - Option : [2]
                    5 - "C:\ToolBar SD\TB_5.txt" - 23/04/2009|14:56 - Option : [2]
                    6 - "C:\ToolBar SD\TB_6.txt" - 23/04/2009|14:56 - Option : [1]
                    7 - "C:\ToolBar SD\TB_7.txt" - 19/05/2009|19:49 - Option : [1]

                    -----------\\ Fin du rapport a 19:49:43,96
                    0
                    1. Re,

                      OKI.

                      * A chaque fois que vous êtes amené à exécuter Navilog1.bat ou Navilog1.exe pour l'installation, ne double-cliquez pas sur le fichier ou raccourci mais faites un clic droit dessus et dans le menu contextuel choisssez "Exécuter en tant qu'administrateur".

                      ▶ Installe NAVILOG1

                      Remarque concernant la détection de Navilog1 par certains programmes de sécurités :

                      ▶ Certains fichiers de Navilog1.exe peuvent être considérés comme dangereux et donc supprimés ou neutralisés par certains programmes de sécurités. Ce sont des faux positifs et dans certains cas, vous serez amener à désactiver votre protection le temps du téléchargement/utilisation de Navilog1.
                      / !\ Déconnecte toi du net et désactive ton antivirus et antispyware résident pour que Navilog1 puisse s'exécuter normalement. / !\

                      Le lancement de l'installation de Navilog1 se fait en exécutant Navilog1.exe

                      (Si vous avez téléchargé navilog1.zip, Veuillez auparavant décompresser ce fichier)

                      Une fois l'installation terminé, pour lancer le fix :

                      - en utilisant le raccourci crée sur le bureau : Navilog1

                      - Via le poste de travail, en exécutant le fichier Navilog1.bat se trouvant dans %program files%Navilog1

                      Après le choix de la langue et les messages d'avertissement, le menu s'affiche.

                      Faite le choix 1

                      Effectue la vérification du système à la recherche de l'adware. Un scan avec catchme de GMER est également éffectué pour Windows XP. Cette analyse peut durer une dizaine de minutes. Patientez alors jusqu'au message «Analyse terminée le ....». Appuyez sur une touche comme demandé et le bloc note va souvrir , Enregistrez-le sur votre disque. Puis Ouvrez-le et Copiez-Collez l'intégralité de ce rapport sur le forum qui vous l'auras demandé.

                      (si le bloc-note ne s'ouvre pas : Rendez-vous dans votre poste de travail, à la racine du disque C vous trouverez le rapport sous le nom de fixnavi.txt)

                      Attention : Ne lancez-pas la partie désinfection (choix 2, 3 ou 4) sans l'avis/accord express de l'Helper qui vous as pris en charge sur le forum d'aide ou vous aurez exposer votre problème.

                      Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
                      0
                      1. voici le rapport:

                        Search Navipromo version 3.7.7 commencé le 19/05/2009 à 20:03:00,94

                        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                        !!! Postez ce rapport sur le forum pour le faire analyser !!!
                        !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                        Outil exécuté depuis C:\Program Files\navilog1

                        Mise à jour le 12.05.2009 à 18h00 par IL-MAFIOSO

                        Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                        X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU E2200 @ 2.20GHz )
                        BIOS : Phoenix - AwardBIOS v6.00PG
                        USER : valerie ( Administrator )
                        BOOT : Normal boot

                        C:\ (Local Disk) - NTFS - Total:286 Go (Free:184 Go)
                        D:\ (Local Disk) - NTFS - Total:12 Go (Free:1 Go)
                        E:\ (CD or DVD)
                        F:\ (USB)
                        G:\ (USB)
                        H:\ (USB)
                        I:\ (USB)
                        J:\ (USB)
                        K:\ (USB) - FAT - Total:990 Mo (Free:0 Go)
                        L:\ (USB) - FAT32 - Total:3868 Mo (Free:0 Go)
                        M:\ (USB) - FAT - Total:939 Mo (Free:0 Go)

                        Recherche executé en mode normal

                        *** Recherche dossiers dans "C:\Windows" ***

                        *** Recherche dossiers dans "C:\Program Files" ***

                        ...\Live-Player trouvé !

                        *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                        *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

                        *** Recherche dossiers dans "C:\ProgramData" ***

                        *** Recherche dossiers dans "c:\users\valerie\appdata\roaming\micros~1\windows\startm~1\programs" ***

                        *** Recherche dossiers dans "C:\Users\valerie\AppData\Local\virtualstore\Program Files" ***

                        *** Recherche dossiers dans "C:\Users\valerie\AppData\Local" ***

                        *** Recherche dossiers dans "C:\Users\TEMP\AppData\Local" ***

                        *** Recherche dossiers dans "C:\Users\valerie\AppData\Roaming" ***

                        *** Recherche dossiers dans "C:\Users\TEMP\appdata\roaming" ***

                        *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                        pour + d'infos : http://www.gmer.net

                        Scan Catchme non réalisé.
                        Droits limités sur la session actuelle.

                        *** Recherche avec GenericNaviSearch ***
                        !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                        !!! A vérifier impérativement avant toute suppression manuelle !!!

                        * Recherche dans "C:\Windows\system32" *

                        * Recherche dans "C:\Users\valerie\AppData\Local\Microsoft" *

                        * Recherche dans "C:\Users\valerie\AppData\Local\virtualstore\windows\system32" *

                        * Recherche dans "C:\Users\valerie\AppData\Local" *

                        * Recherche dans "C:\Users\TEMP\AppData\Local" *

                        *** Recherche fichiers ***

                        *** Recherche clés spécifiques dans le Registre ***
                        !! Les clés trouvées ne sont pas forcément infectées !!

                        *** Module de Recherche complémentaire ***
                        (Recherche fichiers spécifiques)

                        1)Recherche nouveaux fichiers Instant Access :

                        2)Recherche Heuristique :

                        * Dans "C:\Windows\system32" :

                        * Dans "C:\Users\valerie\AppData\Local\Microsoft" :

                        * Dans "C:\Users\valerie\AppData\Local\virtualstore\windows\system32" :

                        * Dans "C:\Users\valerie\AppData\Local" :

                        * Dans "C:\Users\TEMP\AppData\Local" :

                        3)Recherche Certificats :

                        Certificat Egroup absent !
                        Certificat Electronic-Group absent !
                        Certificat Montorgueil absent !
                        Certificat OOO-Favorit absent !
                        Certificat Sunny-Day-Design-Ltd absent !

                        4)Recherche autres dossiers et fichiers connus :

                        *** Analyse terminée le 19/05/2009 à 20:04:04,74 ***
                        0
                        1. je ne sais plus répondre sur l'autre forum
                          0
                          1. re maintenant impossible d'ouvrir orange
                            0