2eme pc infecter acceuil internet derouter

Bonjour,
voici le rapport de hijacthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:21:55 AM, on 1/7/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HiYo\bin\HiYo.exe
C:\Program Files\UniKey v3.5\UniKey.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\HOME\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
C:\Documents and Settings\HOME\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\HOME\My Documents\piere\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.yahoo.com/?p=us
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: (no name) - {60212a44-0000-443b-8310-eb96712d8fba} - C:\WINDOWS\system32\apctui.dll (file missing)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [\\PENTIUM4\EPSON Stylus C67 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAP.EXE /P34 "\\PENTIUM4\EPSON Stylus C67 Series" /O6 "USB002" /M "Stylus C67"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [EPSON Stylus C67 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAP.EXE /P23 "EPSON Stylus C67 Series" /O6 "USB001" /M "Stylus C67"
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE lebeca web camera driver
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
O4 - HKCU\..\Run: [UniKey] C:\Program Files\UniKey v3.5\UniKey.exe
O4 - HKCU\..\Run: [mtd2002Svr] "C:\Program Files\mtd2002"\mtdserver.exe -f
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-21-1659004503-1425521274-839522115-1003\..\Run: [UniKey] C:\Program Files\UniKey v3.5\UniKey.exe (User '?')
O4 - HKUS\S-1-5-21-1659004503-1425521274-839522115-1003\..\Run: [mtd2002Svr] "C:\Program Files\mtd2002"\mtdserver.exe -f (User '?')
O4 - HKUS\S-1-5-21-1659004503-1425521274-839522115-1003\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User '?')
O4 - HKUS\S-1-5-21-1659004503-1425521274-839522115-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1659004503-1425521274-839522115-1003\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (User '?')
O4 - S-1-5-21-1659004503-1425521274-839522115-1003 Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\HOME\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe (User '?')
O4 - Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\HOME\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\windows\system32\mljggfc.dll
O20 - Winlogon Notify: apctui - apctui.dll (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

--
End of file - 8698 bytes
Configuration: Windows XP
Internet Explorer 7.0

45 réponses

Résumé de la discussion

Rapport HijackThis et suites d’outils antivirus décrivent une infection complexe sur Windows XP, avec des éléments au démarrage, des extensions de navigateur et des pilotes système modifiés. Plusieurs éléments ont été détectés comme Trojan.Vundo et Malware.Trace dans le registre et des clés système, avec des quarantaines et suppressions réalisées via Malwarebytes et Avast. Des composants visibles incluent des BHOs et barres d’outils Yahoo et Google, des entrées Run et des services Avast, certains éléments Windows Live et Live Search. En cas d’analyse complémentaire, la liste des antivirus consultés confirme la détection du fichier suspect et souligne l’intérêt d’un nettoyage approfondi et d’un reboot pour supprimer les éléments restants.

Bobot (l’IA à votre service)
  1. http://siri.urz.free.fr/Fix/SmitfraudFix.php

    4.Télécharger Smitfraudfix par S!RI :
    Décompresser l'archive
    Exécuter le en double cliquant sur Smitfraudfix.cmd
    Appuyer sur une touche pour continuer
    Arriver à l'invite de commande, saisir la lettre L afin de basculer le fix en langue française
    Au menu, choisir l’option 4 puis 1 : Recherche
    Poster le rapport ainsi généré dans le forum Virus/Sécurité (ou le cas échéant à la suite de votre message) :
    0
    1. SmitFraudFix v2.388

      Rapport fait à 11:52:18.84, Wed 01/07/2009
      Executé à partir de C:\Documents and Settings\HOME\My Documents\piere\SmitfraudFix
      OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
      Le type du système de fichiers est FAT32
      Fix executé en mode normal

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HOME

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\HOME\LOCALS~1\Temp

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HOME\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

      »»»»»»»»»»»»»»»»»»»»»»»»

      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      C:\Program Files\Google\googletoolbar1.dll PRESENT !

      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="My Current Home Page"

      »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      o4Patch
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      Agent.OMZ.Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"="c:\\windows\\system32\\mljggfc.dll"

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» RK

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

      »»»»»»»»»»»»»»»»»»»»»»»» Fin
      0
      1. Télécharge SDFix sur ton bureau :
        http://downloads.andymanchesta.com/RemovalTools/SDFix.exe.

        --->Double-clique sur SDFix.exe et choisis "Install" .

        ( tuto ici : https://www.malekal.com/slenfbot-still-an-other-irc-bot/ )

        Puis une fois l'installe faite, redémarre en mode sans échec .

        Comment aller en Mode sans échec :
        1) Redémarre ton ordi
        2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
        3) Tu verras un écran avec options de démarrage apparaître
        4) Choisis la première option : Sans Échec, et valide avec "Entrée"
        5) Choisis ton compte habituel, et non Administrateur (si besoin ... )

        /!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

        Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
        --->Tapes Y pour lancer le script ...
        Le Fix supprime les services du virus et nettoie le registre, de ce fait un redémarrage est nécessaire , donc :
        presse une touche pour redémarrer quand il te le sera demandé .

        Le PC va mettre du temps avant de démarrer ( c'est normal), après le chargement du Bureau presse une touche lorsque "Finished" s'affiche .

        Le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier C:\SDFix sous le nom "Report.txt".

        Poste ce dernier dans ta prochaine réponse.

        + 1 log hijackthis
        0
        1. rapport sdfix

          [b]SDFix: Version 1.240 [/b]
          Run by HOME on Wed 01/07/2009 at 12:54

          Microsoft Windows XP [Version 5.1.2600]
          Running From: C:\SDFix

          [b]Checking Services [/b]:

          Restoring Default Security Values
          Restoring Default Hosts File
          Restoring Missing Security Center Service
          Restoring Missing SharedAccess Service

          Rebooting

          [b]Checking Files [/b]:

          Trojan Files Found:

          C:\Documents and Settings\HOME\Application Data\tmp42.tmp.exe - Deleted

          Removing Temp Files

          [b]ADS Check [/b]:

          [b]Final Check [/b]:

          catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2009-01-07 13:12:44
          Windows 5.1.2600 Service Pack 2 FAT NTAPI

          scanning hidden processes ...

          scanning hidden services ...

          scanning hidden autostart entries ...

          scanning hidden files ...

          scan completed successfully
          hidden processes: 0
          hidden services: 0
          hidden files: 0

          [b]Remaining Services [/b]:

          Authorized Application Key Export:

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
          "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
          "C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
          "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
          "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
          "C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
          "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

          [b]Remaining Files [/b]:

          File Backups: - C:\SDFix\backups\backups.zip

          [b]Files with Hidden Attributes [/b]:

          Fri 23 Apr 1999 93,890 ..SH. --- "C:\COMMAND.COM"
          Fri 24 Aug 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
          Fri 24 Jan 2003 65,952 ..SHR --- "C:\Program Files\Autodesk\Autodesk Express Viewer\Setup.exe"
          Mon 3 Nov 2008 1,311,784 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\4b688ce5ed2083968f07f818707a88a4\BIT11C.tmp"
          Mon 3 Nov 2008 817,704 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\01bf5ce4c3ad726a5ff713631bfd6dab\BIT11E.tmp"
          Mon 3 Nov 2008 657,960 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\6a9bb7b4ce735297a73f4bd7161e4f9c\BIT11F.tmp"
          Mon 3 Nov 2008 1,465,384 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\1abb4643eccf67e5ec8b2a16ba5befb7\BIT125.tmp"
          Mon 3 Nov 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b5a0d96b7c12dd2c0335206a1ae160ae\download\BIT130.tmp"
          Mon 3 Nov 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\a17b5df07c4dfb0b394eabad42d90933\download\BIT131.tmp"
          Mon 3 Nov 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\8205df9ffac774969e61b38f516f1b94\download\BIT132.tmp"
          Mon 3 Nov 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\588786e399909bbe558853aada5a75c8\download\BIT133.tmp"
          Mon 3 Nov 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\74a19a19cc31989be4bb0df6ac36d839\download\BIT134.tmp"
          Tue 30 Dec 2008 7,798 A..H. --- "C:\Documents and Settings\HOME\Application Data\Microsoft\Office\Shortcut Bar\Off2.tmp"

          [b]Finished![/b]
          0
          1. rapport log hijackthis

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 13:16:18, on 1/7/2009
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.5730.0013)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\system32\drivers\CDAC11BA.EXE
            C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\WINDOWS\system32\WgaTray.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\system32\notepad.exe
            C:\WINDOWS\SOUNDMAN.EXE
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\WINDOWS\VM_STI.EXE
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\HiYo\bin\HiYo.exe
            C:\Program Files\UniKey v3.5\UniKey.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
            C:\Documents and Settings\HOME\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
            C:\Documents and Settings\HOME\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Documents and Settings\HOME\My Documents\piere\HiJackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.yahoo.com/?p=us
            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll
            O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
            O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
            O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
            O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [\\PENTIUM4\EPSON Stylus C67 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAP.EXE /P34 "\\PENTIUM4\EPSON Stylus C67 Series" /O6 "USB002" /M "Stylus C67"
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [EPSON Stylus C67 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAP.EXE /P23 "EPSON Stylus C67 Series" /O6 "USB001" /M "Stylus C67"
            O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE lebeca web camera driver
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
            O4 - HKCU\..\Run: [UniKey] C:\Program Files\UniKey v3.5\UniKey.exe
            O4 - HKCU\..\Run: [mtd2002Svr] "C:\Program Files\mtd2002"\mtdserver.exe -f
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
            O4 - HKUS\S-1-5-21-1659004503-1425521274-839522115-1003\..\Run: [UniKey] C:\Program Files\UniKey v3.5\UniKey.exe (User '?')
            O4 - HKUS\S-1-5-21-1659004503-1425521274-839522115-1003\..\Run: [mtd2002Svr] "C:\Program Files\mtd2002"\mtdserver.exe -f (User '?')
            O4 - HKUS\S-1-5-21-1659004503-1425521274-839522115-1003\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User '?')
            O4 - HKUS\S-1-5-21-1659004503-1425521274-839522115-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
            O4 - HKUS\S-1-5-21-1659004503-1425521274-839522115-1003\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (User '?')
            O4 - S-1-5-21-1659004503-1425521274-839522115-1003 Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\HOME\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe (User '?')
            O4 - Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\HOME\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
            O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
            O20 - AppInit_DLLs: c:\windows\system32\mljggfc.dll
            O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            0
            1. un truc bizard
              je voul\ais regarder le journal de tf 1 sur tf1 .fr et des que je me connecte cela me fait perdre ma connexion reseau
              je suis obliger de relancer Modem speed touch pour reconnection internet ??
              cela le fait avec ce PC mais pas avec l autre qui avait le meme probleme que celui la
              detournement de la page acceuil internet
              c est quoi le probleme
              0
              1. Nettoyage :
                Démarre en mode sans échec :
                Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
                Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                (Si F8 ne marche pas utilise la touche F5).

                http://www.coupdepoucepc.com/modules/news/article.php?storyi­d=253
                http://www.micro-astuce.com/depannage/demarrer-mode-sans-ech­ec

                ------------------------------------------------------------­----------------
                Relance le programme Smitfraud,
                Cette fois choisit l’option 2, répond oui a tous ;
                Sauvegarde le rapport,
                Redémarre en mode normal,
                copie/colle le rapport sauvegardé sur le forum

                process.exe
                est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
                http://www.beyondlogic.org/consulting/processutil/processuti­l.htm

                ensuite :

                ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

                ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
                http://oldtimer.geekstogo.com/OTMoveIt3.exe

                ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

                ---> Copie (Ctrl+C) le texte suivant ci-dessous :

                :processes
                explorer.exe

                :reg
                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                "AppInit_DLLS"=""

                :commands
                [purity]
                [emptytemp]
                [start explorer]
                [reboot]

                ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

                Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                Accepte en cliquant sur YES.

                ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
                Le nom du rapport correspond au moment de sa création : date_heure.log

                0
                1. ========== PROCESSES ==========
                  Process explorer.exe killed successfully.
                  ========== REGISTRY ==========
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\"AppInit_DLLS"|"" /E : value set successfully!
                  ========== COMMANDS ==========
                  User's Temp folder emptied.
                  User's Temporary Internet Files folder emptied.
                  User's Internet Explorer cache folder emptied.
                  Local Service Temp folder emptied.
                  Local Service Temporary Internet Files folder emptied.
                  File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_580.dat scheduled to be deleted on reboot.
                  Windows Temp folder emptied.
                  Temp folders emptied.
                  Explorer started successfully

                  OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01072009_215400
                  0
                  1. je peux avoir le rapport de smitfraudfix option nettoyage stp ?
                    0
                    1. excuse moi mais j ai été obligé d arreter l ordi car il est dans la chambre de mon fils
                      nous vivons au vietnam et il est 22h19 et demain il a l 'ecole
                      il faut qu'il dorme
                      demain matin 8h soit 2h en france je serais connecté et je te renvoi le rapport
                      merci pour ta comprehension

                      j ai un autre PC que je viens de recuperer chez des amis
                      je l ai connecter a mon routeur
                      j ai demander google et le meme probleme est survenu
                      n y aurait t il plutot pas un probleme dans le routeur
                      quand je demande une adresse google ./fr
                      il me route ailleur quelques fois
                      0
                      1. je pense qu il faut le desinfecter aussi mais finissons celui ci d'abord
                        0
                        1. ok je fais quoi apres
                          je ne pourrais le faire que demain vers 8 h GMT +5
                          0
                          1. ben je te dirai a la reception du rapport de smitfraudfix option nettoyage
                            0
                            1. SmitFraudFix v2.388

                              Scan done at 21:39:32.09, Wed 01/07/2009
                              Run from C:\Documents and Settings\HOME\My Documents\piere\SmitfraudFix
                              OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
                              The filesystem type is FAT32
                              Fix run in safe mode

                              »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                              !!!Attention, following keys are not inevitably infected!!!

                              SrchSTS.exe by S!Ri
                              Search SharedTaskScheduler's .dll

                              »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                              »»»»»»»»»»»»»»»»»»»»»»»» hosts

                              127.0.0.1 localhost

                              »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                              VACFix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                              S!Ri's WS2Fix: LSP not Found.

                              »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                              GenericRenosFix by S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                              C:\Program Files\Google\googletoolbar1.dll Deleted

                              »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                              IEDFix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

                              Agent.OMZ.Fix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                              404Fix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» RK

                              »»»»»»»»»»»»»»»»»»»»»»»» DNS

                              »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

                              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                              !!!Attention, following keys are not inevitably infected!!!

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                              "System"=""

                              »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                              Registry Cleaning done.

                              »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                              !!!Attention, following keys are not inevitably infected!!!

                              SrchSTS.exe by S!Ri
                              Search SharedTaskScheduler's .dll

                              »»»»»»»»»»»»»»»»»»»»»»»» End
                              0
                              1. bonjour ,

                                Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

                                -> http://images.malwareremoval.com/random/RSIT.exe

                                ! Déconnecte toi et ferme toutes tes applications en cours !

                                Double-clique sur " RSIT.exe " pour le lancer .

                                -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

                                * Devant l'option "List files/folders created ..." , tu choisis : 2 months

                                * clique ensuite sur " Continue " pour lancer l'analyse ...

                                -> laisse faire le scan et ne touche pas au PC ...

                                Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

                                Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

                                Important : poste un rapport, puis l'autre dans la réponse suivante ...
                                Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum ...
                                Et si "log.txt" seul, ne passe pas non plus , fais le en 2 fois ... merci ...

                                ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )

                                0
                                1. j ai fait ce que tu m as dit mais le programme ne veut pas se lancrer

                                  une fenetre me dit INCORRECT NUMBER of PARAMETRE IN FUNCTION CALL

                                  ?? :)
                                  0
                                  • 1
                                  • 2
                                  • 3