Virus msn envoi des message tout seul

Bonjour,

Voila l'adresse msn envoi un message (avec virus) à tout mes contacts.

En parcourant le site j'ai vu qu'il fallait passer MsmFix ce que je tente de faire mais ça dure des heures.

Ma question est quelle est la durée d'un scan (choix R) de MSNfix?

D'avance merci
--
Si vous avez besoin de quelque chose, appelez-moi. Je vous dirai comment vous en passer.
Configuration: Windows Vista
Firefox 3.0.4 et Internet explorer 7

70 réponses

Résumé de la discussion

La problématique centrale concerne la durée et l’efficacité d’un scan via MSNFix en mode R sur une machine Windows Vista confrontée à des infections qui ont envoyé des messages infectés. Des réponses recommandent de repérer le processus PSEXESVC.EXE, d’employer SmitFraudFix en mode sans échec et d’envisager des outils complémentaires comme Chaos Shredder ou WS2Fix selon les symptômes. Certaines interventions incluent l’examen des rapports générés et l’identification de fichiers suspects, puis le nettoyage du système et l’élimination des entrées malveillantes dans le registre et les DNS. En cas de doute, l’exécution d’un diagnostic complet et la vérification des rapports de détection peuvent aider à confirmer l’absence de composants résiduels et à prévenir de futures remontées.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Télécharge le fichier d'installation d'HijackThis.

    Enregistre HJTInstall.exe sur ton bureau.

    Double-clique sur HJTInstall.exe pour lancer le programme

    Par défaut, il s'installera là :
    C:\Program Files\Trend Micro\HijackThis

    Accepte la licence en cliquant sur le bouton "I Accept"

    Choisis l'option "Do a system scan and save a log file"

    Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note

    Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

    Colle le rapport que tu viens de copier sur ce forum

    Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement

    Tutoriaux (ne fixe rien pour le moment !!)

    0
    1. Contributeur sécurité
      ça dépend, le scan peut être très long si tu vois du rouge c'est que tu es infecté.

      Ensuite tu me fera la suite. Merci.
      0
      1. Hello merci quelle rapidité

        Eu du rouge je vois rien juste une fenêtre dos qui dit:

        scan ...........

        et juste en dessous le curseur qui clignotte

        Je fais le rapport Hijack de suite ?

        PS Je suis sous vista
        0
    2. Contributeur sécurité
      répondre tu as désactivé le contrôle des compte pour msfix? la fenêtre rouge va apparaitre à la fin si tu es infecté.
      0
      1. Oui bien

        sur voila MSNfix a terminé et dit qu il n'a rien trouvé.

        Lorsque j ai demandé a afficher le rapport le programme c est fermé et pas de rapport

        Il se cache quelque part?
        0
    3. Voila le rapport Hijack

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 20:02:05, on 20.01.2009
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Program Files\Dell\DellDock\DellDock.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\DellTPad\Apoint.exe
      C:\Windows\OEM02Mon.exe
      C:\Windows\System32\igfxtray.exe
      C:\Windows\System32\hkcmd.exe
      C:\Windows\System32\igfxpers.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
      C:\Windows\System32\WLTRAY.EXE
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\Program Files\Dell\MediaDirect\PCMService.exe
      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
      C:\Program Files\Dell Support Center\bin\sprtcmd.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\HiYo\Bin\HiYo.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
      C:\Program Files\Digital Line Detect\DLG.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Dell\QuickSet\quickset.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\Program Files\DellTPad\ApMsgFwd.exe
      C:\Program Files\DellTPad\Apntex.exe
      C:\Program Files\DellTPad\HidFind.exe
      c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Users\Mélanie\Desktop\HiJackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.ch
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ch/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
      O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
      O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
      O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
      O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
      O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
      O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
      O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
      O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
      O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
      O4 - Global Startup: BTTray.lnk = ?
      O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
      O8 - Extra context menu item: Ajouter à Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O13 - Gopher Prefix:
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
      O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
      O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
      O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
      O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
      0
      1. J ai trouver ceci dans le dossier MSNfix:

        [C:\Windows\system32\WindowsAnytimeUpgrade.exe] 626F198768F67A0FEB3AD909E638F551
        [C:\Windows\system32\WinFXDocObj.exe] 14F0C0AAEF23C111371F808A6911E998
        [C:\Windows\system32\wininit.exe] 101BA3EA053480BB5D957EF37C06B5ED
        [C:\Windows\system32\winload.exe] BB82A604FCC5A930696962A27F1C9760
        [C:\Windows\system32\winlogon.exe] C2610B6BDBEFC053BBDAB4F1B965CB24
        [C:\Windows\system32\winresume.exe] E3770E54B0864B93DF82C2E35F5AB20D
        [C:\Windows\system32\winrs.exe] 24AB1404A479AFEEC112079D9AF12A0D
        [C:\Windows\system32\winrshost.exe] 8F26CCF26436315033192266A7135FF5
        [C:\Windows\system32\WinSAT.exe] 550E83EEE739D1C25A49E70F038EC816
        [C:\Windows\system32\WINSPOOL.EXE] 0B4B94B78123E8035B84105BC024F9F8
        [C:\Windows\system32\winver.exe] EEE1CE328E50D4391D9CE7624286CEB0
        0
        1. Contributeur sécurité
          Fait ceci et poste moi le rapport qui va suivre.

          Télécharge GenProc sur ton bureau (Attention le fichier est un fichier zip)
          Dézippe le dossier, double-clique sur GenProc.bat
          En final, poste le contenu du rapport qui s'affiche.
          Comment utiliser GenProc

          Pour ceux qui ont vista, ne pas oublier de désactiver Le contrôle des comptes utilisateurs
          0
          1. Hello voila le rapport d'analyse GenProc

            Rapport GenProc 2.345 [1] - 21.01.2009 - Windows Vista

            GenProc n'a détecté aucune infection caractéristique et suggère de suivre la procédure suivante :

            Poste un rapport Nod32 https://www.eset.com/ (il faut utiliser Internet Explorer)
            - coche toutes les cases à chaque fois, et lorsque c'est terminé, colle le rapport :
            - C:\Program Files\EsetOnlineScanner\log.txt

            __________________________________________________________________________________________________________

            Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
            0
            1. Contributeur sécurité
              Telecharge malwarebytes

              Tu l´instale; le programme va se mettre automatiquement a jour.

              Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

              Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".

              Puis click sur "rechercher".

              Laisse le scanner le pc...

              Si des elements on ete trouvés > click sur supprimer la selection.

              si il t´es demandé de redemarrer > click sur "yes".

              A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
              Copie et colle le rapport stp.

              PS : les rapport sont aussi rangé dans l onglet rapport/log

              Tutoriaux
              0
              1. Hello voila le rapport malware qui n a rien trouvé

                Malwarebytes' Anti-Malware 1.33
                Version de la base de données: 1674
                Windows 6.0.6001 Service Pack 1

                21.01.2009 18:07:31
                mbam-log-2009-01-21 (18-07-31).txt

                Type de recherche: Examen complet (C:\|)
                Eléments examinés: 131130
                Temps écoulé: 1 hour(s), 10 minute(s), 53 second(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 0
                Clé(s) du Registre infectée(s): 0
                Valeur(s) du Registre infectée(s): 0
                Elément(s) de données du Registre infecté(s): 0
                Dossier(s) infecté(s): 0
                Fichier(s) infecté(s): 0

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Clé(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Valeur(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Elément(s) de données du Registre infecté(s):
                (Aucun élément nuisible détecté)

                Dossier(s) infecté(s):
                (Aucun élément nuisible détecté)

                Fichier(s) infecté(s):
                (Aucun élément nuisible détecté)
                0
                1. Contributeur sécurité
                  * Télécharger ComboFix (par sUBs) sur le Bureau.
                  * Double-cliquer combofix.exe.
                  * Il est vivement recommandé d'installer la Console de récupération !
                  * Appuyer sur la touche Y (Yes) pour démarrer le scan.
                  * Le rapport sera crée dans: C:\Combofix.txt.
                  * Refaire un rapport HijackThis, et fixer les lignes correspondantes comme indiqué plus haut.

                  Le tutoriel officiel se trouve à cette adresse :
                  https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
                  0
                  1. voila le rappor combofix

                    tu dis de fixer les ligne avec hijack correspondante mais les quels?

                    ComboFix 09-01-20.05 - Mélanie 2009-01-21 18:42:16.1 - NTFSx86
                    Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.3061.1436 [GMT 1:00]
                    Lancé depuis: c:\users\Mélanie\Desktop\ComboFix.exe
                    AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
                    FW: Kaspersky Internet Security *disabled*
                    * Un nouveau point de restauration a été créé
                    .

                    ((((((((((((((((((((((((((((( Fichiers créés du 2008-12-21 au 2009-01-21 ))))))))))))))))))))))))))))))))))))
                    .

                    2009-01-15 19:09 . 2008-12-16 03:42 288,768 --a------ c:\windows\System32\drivers\srv.sys
                    2009-01-07 18:18 . 2009-01-07 18:18 <REP> d-------- c:\users\Mélanie\AppData\Roaming\Scatlaws
                    2009-01-03 12:03 . 2009-01-03 12:03 <REP> d-------- c:\windows\System32\Kaspersky Lab
                    2009-01-03 12:02 . 2009-01-19 21:02 <REP> d-------- c:\windows\BDOSCAN8
                    2008-12-29 12:00 . 2008-12-29 12:10 96,976 --a------ c:\windows\System32\drivers\klin.dat
                    2008-12-29 12:00 . 2008-12-29 12:10 87,855 --a------ c:\windows\System32\drivers\klick.dat
                    2008-12-29 11:59 . 2009-01-20 18:24 <REP> d-------- c:\users\All Users\Kaspersky Lab
                    2008-12-29 11:59 . 2009-01-20 18:24 <REP> d-------- c:\programdata\Kaspersky Lab
                    2008-12-29 11:59 . 2008-12-29 11:59 <REP> d-------- c:\program files\Kaspersky Lab
                    2008-12-29 11:59 . 2009-01-21 18:40 2,627,104 --ahs---- c:\windows\System32\drivers\fidbox.dat
                    2008-12-29 11:59 . 2009-01-21 16:29 393,248 --ahs---- c:\windows\System32\drivers\fidbox2.dat
                    2008-12-29 11:59 . 2009-01-21 18:40 22,624 --ahs---- c:\windows\System32\drivers\fidbox.idx
                    2008-12-29 11:59 . 2009-01-21 16:27 2,424 --ahs---- c:\windows\System32\drivers\fidbox2.idx
                    2008-12-29 11:58 . 2008-12-29 11:58 <REP> d-------- c:\users\All Users\Kaspersky Lab Setup Files
                    2008-12-29 11:58 . 2008-12-29 11:58 <REP> d-------- c:\programdata\Kaspersky Lab Setup Files
                    2008-12-26 12:19 . 2008-12-26 12:19 <REP> dr------- c:\windows\System32\config\systemprofile\Music

                    .
                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    2009-01-21 17:42 5,505,024 --sha-w c:\users\Mélanie\NTUSER.DAT
                    2009-01-21 17:42 5,505,024 --sha-w c:\users\Mélanie\NTUSER.DAT
                    2009-01-21 15:46 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
                    2009-01-19 19:54 --------- d-----w c:\programdata\Spybot - Search & Destroy
                    2009-01-16 17:33 --------- d-----w c:\programdata\Microsoft Help
                    2009-01-16 17:33 --------- d-----w c:\program files\Windows Mail
                    2009-01-14 15:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
                    2009-01-14 15:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
                    2009-01-10 13:02 --------- d-----w c:\users\Mélanie\AppData\Roaming\LimeWire
                    2009-01-10 10:40 --------- d-----w c:\users\Mélanie\AppData\Roaming\HP
                    2009-01-07 18:09 --------- d-----w c:\program files\Google
                    2009-01-07 17:18 --------- d-----w c:\users\Mélanie\AppData\Roaming\Scatlaws
                    2008-12-29 10:53 --------- d-----w c:\program files\Norton Internet Security
                    2008-12-29 10:52 --------- d-----w c:\programdata\Norton
                    2008-12-29 10:52 --------- d-----w c:\program files\Common Files\Symantec Shared
                    2008-12-15 18:02 --------- d-s---w c:\users\Mélanie\AppData\Roaming\Microsoft
                    2008-12-10 19:28 --------- d-----w c:\program files\PhotoFiltre
                    2008-12-09 19:47 --------- d-----w c:\users\Mélanie\AppData\Roaming\Adobe
                    2008-12-09 19:24 --------- d--h--w c:\program files\InstallShield Installation Information
                    2008-12-09 19:24 --------- d-----w c:\program files\Serif
                    2008-12-06 09:17 --------- d-----w c:\users\Mélanie\AppData\Roaming\HiYo
                    2008-12-06 09:17 --------- d-----w c:\programdata\HiYo
                    2008-12-06 09:17 --------- d-----w c:\program files\HiYo
                    2008-12-06 08:52 --------- d-----w c:\program files\LimeWire
                    2008-12-06 08:43 --------- d-----w c:\programdata\eMule
                    2008-12-06 08:43 --------- d-----w c:\program files\eMule
                    2008-12-03 16:32 --------- d-----w c:\program files\Spybot - Search & Destroy
                    2008-12-02 18:26 --------- d-----w c:\programdata\Lavasoft
                    2008-12-02 18:25 --------- d-----w c:\program files\Lavasoft
                    2008-12-02 18:24 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
                    2008-12-02 18:17 --------- d-----w c:\programdata\TEMP
                    2008-12-02 18:17 --------- d-----w c:\program files\SpywareBlaster
                    2008-12-02 18:06 --------- d-----w c:\users\Mélanie\AppData\Roaming\Malwarebytes
                    2008-12-02 18:06 --------- d-----w c:\programdata\Malwarebytes
                    2008-12-01 18:22 --------- d-----w c:\users\Mélanie\AppData\Roaming\TeamViewer
                    2008-11-30 19:32 --------- d-----w c:\programdata\Symantec
                    2008-11-30 19:29 --------- d-----w c:\programdata\PCSettings
                    2008-11-30 19:29 --------- d-----w c:\programdata\NortonInstaller
                    2008-11-30 19:27 --------- d-----w c:\programdata\Symantec Temporary Files
                    2008-11-29 14:39 --------- d-----w c:\users\Mélanie\AppData\Roaming\Creative
                    2008-11-28 19:05 --------- d-----w c:\programdata\WindowsSearch
                    2008-11-27 18:01 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
                    2008-11-27 17:54 --------- d-----w c:\users\Mélanie\AppData\Roaming\Apple Computer
                    2008-11-27 17:54 --------- d-----w c:\programdata\Apple Computer
                    2008-11-27 17:54 --------- d-----w c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
                    2008-11-27 17:54 --------- d-----w c:\program files\iTunes
                    2008-11-27 17:54 --------- d-----w c:\program files\iPod
                    2008-11-27 17:54 --------- d-----w c:\program files\Common Files\Apple
                    2008-11-27 17:53 --------- d-----w c:\program files\QuickTime
                    2008-11-27 17:53 --------- d-----w c:\program files\Bonjour
                    2008-11-27 17:52 --------- d-----w c:\programdata\Apple
                    2008-11-27 17:52 --------- d-----w c:\program files\Apple Software Update
                    2008-11-24 20:08 --------- d-----w c:\users\Mélanie\AppData\Roaming\Macromedia
                    2008-11-24 19:53 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
                    2008-11-24 19:53 --------- d-----w c:\program files\Windows Live
                    2008-11-24 19:52 --------- d-----w c:\program files\MSXML 4.0
                    2008-11-24 19:51 --------- d-----w c:\programdata\WLInstaller
                    2008-11-24 19:50 --------- d-----w c:\program files\Microsoft Silverlight
                    2008-11-24 19:40 --------- d-----w c:\programdata\Dell
                    2008-11-24 19:32 --------- d-----w c:\programdata\HP
                    2008-11-24 19:27 --------- d-----w c:\program files\CCleaner
                    2008-11-24 19:24 --------- d-----w c:\programdata\WEBREG
                    2008-11-24 19:23 --------- d-----w c:\programdata\HPSSUPPLY
                    2008-11-24 19:23 --------- d-----w c:\program files\HP
                    2008-11-24 19:22 --------- d-----w c:\program files\Common Files\HP
                    2008-11-24 19:19 --------- d-----w c:\program files\Hewlett-Packard
                    2008-11-24 19:19 --------- d-----w c:\program files\Common Files\Hewlett-Packard
                    2008-11-24 18:52 --------- d-----w c:\users\Mélanie\AppData\Roaming\Mozilla
                    2008-11-24 18:49 --------- d-----w c:\users\Mélanie\AppData\Roaming\Google
                    2008-11-24 18:11 --------- d-----w c:\users\Mélanie\AppData\Roaming\Symantec
                    2008-11-24 18:10 81,920 ----a-w c:\windows\BurnImage.exe
                    2008-11-24 18:10 720,896 ----a-w c:\windows\IMAPIShellExt.dll
                    2008-11-24 18:10 --------- d-----w c:\users\Mélanie\AppData\Roaming\Identities
                    2008-11-24 18:10 --------- d-----w c:\users\Mélanie\AppData\Roaming\Dell
                    2008-11-24 18:06 --------- d-sh--w c:\programdata\Modèles
                    2008-11-24 18:06 --------- d-sh--w c:\programdata\Menu Démarrer
                    2008-11-24 18:06 --------- d-sh--w c:\programdata\Favoris
                    2008-11-24 18:06 --------- d-sh--w c:\programdata\Documents
                    2008-11-24 18:06 --------- d-sh--w c:\programdata\Bureau
                    2008-11-24 18:06 --------- d-sh--w c:\programdata\Application Data
                    2008-11-24 18:06 --------- d-sh--w c:\program files\Fichiers communs
                    2008-11-01 03:44 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
                    2008-11-01 03:44 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
                    2008-11-01 03:44 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
                    2008-11-01 03:44 28,672 ----a-w c:\windows\System32\Apphlpdm.dll
                    2008-11-01 03:44 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
                    2008-11-01 03:44 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
                    2008-11-01 01:21 4,240,384 ----a-w c:\windows\System32\GameUXLegacyGDFs.dll
                    2008-10-29 06:29 2,927,104 ----a-w c:\windows\explorer.exe
                    2008-10-22 03:57 241,152 ----a-w c:\windows\System32\PortableDeviceApi.dll
                    2008-10-22 01:22 2,048 ----a-w c:\windows\System32\tzres.dll
                    2008-10-21 05:25 296,960 ----a-w c:\windows\System32\gdi32.dll
                    2008-10-21 05:25 1,645,568 ----a-w c:\windows\System32\connect.dll
                    2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
                    2008-09-16 07:28 76 --sha-r c:\windows\CT4CET.bin
                    .

                    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    .
                    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                    REGEDIT4

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
                    "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
                    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-29 17920]
                    "Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-05-04 167936]
                    "OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2008-03-04 36864]
                    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-06 141848]
                    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-06 166424]
                    "Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-06 133656]
                    "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
                    "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-07-03 3563520]
                    "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-16 29744]
                    "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
                    "PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320]
                    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
                    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
                    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
                    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
                    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
                    "HiYo"="c:\program files\HiYo\bin\HiYo.exe" [2008-10-23 300336]
                    "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 201992]

                    c:\users\M‚lanie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                    Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-07-15 1226024]

                    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
                    BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-03 703280]
                    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-09-16 50688]
                    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
                    QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-02-22 1193240]

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                    "EnableLUA"= 0 (0x0)
                    "EnableUIADesktopToggle"= 0 (0x0)

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
                    2008-09-16 08:51 10536 c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                    "AppInit_DLLs"=G G G G

                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
                    @="Driver"

                    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                    "DisableMonitoring"=dword:00000001

                    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
                    "DisableMonitoring"=dword:00000001

                    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                    "DisableMonitoring"=dword:00000001

                    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                    "DisableMonitoring"=dword:00000001

                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
                    "EnableFirewall"= 0 (0x0)

                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
                    "{E6871D8B-E5E2-46DC-A12E-8E9CA227E58C}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
                    "{9B328CEC-9316-4F78-A06A-C99613F00CD1}"= c:\program files\Dell\MediaDirect\MediaDirect.exe:Dell MediaDirect
                    "{6B5F4C97-EF94-445E-8EF5-BF403856D385}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
                    "{2FB4CB90-F5B1-49B6-80CA-C307F52FBBF4}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
                    "{CBDE61CB-5FC1-4336-9BDA-BF5CD5943132}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
                    "{F43BDC6A-60C4-4C32-AF55-625E600596D2}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
                    "{7779ECAA-9C62-4731-A539-02335CF2C49A}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
                    "{B1CB125E-0A97-4445-BD95-65A12C43CBE5}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
                    "{9808BB9D-BD35-45D2-A195-CDCD81999DD0}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
                    "{8026AD0C-B187-4B1D-9667-DA849FA76418}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes

                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
                    "EnableFirewall"= 0 (0x0)

                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
                    "EnableFirewall"= 0 (0x0)

                    R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [2008-01-29 32784]
                    R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [2008-03-26 20496]
                    R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\System32\drivers\IntcHdmi.sys [2008-09-16 111616]
                    R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\System32\drivers\klfltdev.sys [2008-03-13 26640]
                    R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [2008-09-16 235648]
                    R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [2008-09-16 7424]
                    R4 AESTFilters;Andrea ST Filters Service;c:\windows\System32\AEstSrv.exe [2008-09-16 73728]
                    R4 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-05-02 161048]

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                    bthsvcs REG_MULTI_SZ BthServ
                    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
                    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
                    .
                    .
                    ------- Examen supplémentaire -------
                    .
                    uStart Page = hxxp://www.google.ch/
                    uInternet Settings,ProxyOverride = *.local
                    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
                    IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                    IE: Envoyer l'&image au périphérique Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                    DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                    FF - ProfilePath - c:\users\Mélanie\AppData\Roaming\Mozilla\Firefox\Profiles\u6ugfx74.default\
                    .

                    **************************************************************************

                    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2009-01-21 18:43:59
                    Windows 6.0.6001 Service Pack 1 NTFS

                    Recherche de processus cachés ...

                    Recherche d'éléments en démarrage automatique cachés ...

                    Recherche de fichiers cachés ...

                    Scan terminé avec succès
                    Fichiers cachés: 0

                    **************************************************************************
                    .
                    --------------------- DLLs chargées dans les processus actifs ---------------------

                    - - - - - - - > 'winlogon.exe'(752)
                    c:\progra~1\KASPER~1\KASPER~1\adialhk.dll
                    c:\progra~1\KASPER~1\KASPER~1\kloehk.dll

                    - - - - - - - > 'lsass.exe'(768)
                    c:\progra~1\KASPER~1\KASPER~1\adialhk.dll
                    c:\progra~1\KASPER~1\KASPER~1\kloehk.dll
                    .
                    Heure de fin: 2009-01-21 18:46:34
                    ComboFix-quarantined-files.txt 2009-01-21 17:46:29

                    Avant-CF: 237'763'530'752 octets libres
                    Après-CF: 237,653,438,464 octets libres

                    Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
                    241 --- E O F --- 2009-01-19 18:58:05
                    0
                2. le rapport hijack

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 18:49:40, on 21.01.2009
                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                  MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\Program Files\Dell\DellDock\DellDock.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Program Files\DellTPad\Apoint.exe
                  C:\Windows\OEM02Mon.exe
                  C:\Windows\System32\igfxtray.exe
                  C:\Windows\System32\hkcmd.exe
                  C:\Windows\System32\igfxpers.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                  C:\Windows\System32\WLTRAY.EXE
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\Program Files\Dell\MediaDirect\PCMService.exe
                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                  C:\Program Files\Dell Support Center\bin\sprtcmd.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\Program Files\HiYo\Bin\HiYo.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Windows\system32\igfxsrvc.exe
                  C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                  C:\Program Files\Digital Line Detect\DLG.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\Dell\QuickSet\quickset.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\Program Files\DellTPad\ApMsgFwd.exe
                  C:\Program Files\DellTPad\Apntex.exe
                  C:\Program Files\DellTPad\HidFind.exe
                  c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                  C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
                  C:\Program Files\Creative Live! Cam\VideoFX\StartFX.exe
                  C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
                  C:\Windows\Explorer.exe
                  C:\Windows\system32\notepad.exe
                  C:\Windows\system32\rundll32.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Users\Mélanie\Desktop\HiJackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ch/?gws_rd=ssl
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                  O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                  O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
                  O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
                  O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                  O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
                  O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                  O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
                  O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
                  O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
                  O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
                  O4 - Global Startup: BTTray.lnk = ?
                  O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
                  O8 - Extra context menu item: Ajouter à Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                  O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                  O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                  O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                  O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                  O13 - Gopher Prefix:
                  O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                  O20 - AppInit_DLLs: G G G G
                  O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
                  O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                  O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
                  O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                  O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                  O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
                  O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                  0
                  1. Contributeur sécurité
                    Téléchargez SmitfraudFix et enregistrez-le sur le bureau
                    * Ensuite, double cliquez sur SmitfraudFix puis sur Exécuter. (Sous Vista : clic droit sur SmitfraudFix et sélectionnez "Exécuter en tant qu'administrateur")
                    * Sélectionnez 1 pour créer un rapport des fichiers responsables de l'infection.
                    * A la fin de l'analyse, un rapport va être généré...Enregistrez-le sur le bureau.

                    Regarde bien le tuto qui est avec

                    /!\ Postez le rapport sur le forum pour savoir si la suppression peut être lancée.

                    En mode sans echec la suppression des fichiers présents.
                    0
                    1. Voila le rapport SmitFraudFX

                      SmitFraudFix v2.391

                      Rapport fait à 19:44:21.67, 21.01.2009
                      Executé à partir de C:\Users\Mélanie\Desktop\SmitfraudFix
                      OS: Microsoft Windows [version 6.0.6001] - Windows_NT
                      Le type du système de fichiers est NTFS
                      Fix executé en mode normal

                      »»»»»»»»»»»»»»»»»»»»»»»» Process

                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\wininit.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\services.exe
                      C:\Windows\system32\winlogon.exe
                      C:\Windows\system32\lsass.exe
                      C:\Windows\system32\lsm.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\SLsvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Dell\DellDock\DockLogin.exe
                      C:\Windows\System32\WLTRYSVC.EXE
                      C:\Windows\System32\bcmwltry.exe
                      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                      C:\Windows\system32\WLANExt.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Program Files\Dell\DellDock\DellDock.exe
                      C:\Windows\System32\spoolsv.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\Program Files\DellTPad\Apoint.exe
                      C:\Windows\OEM02Mon.exe
                      C:\Windows\System32\igfxtray.exe
                      C:\Windows\System32\hkcmd.exe
                      C:\Windows\System32\igfxpers.exe
                      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                      C:\Windows\System32\WLTRAY.EXE
                      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                      C:\Program Files\Dell\MediaDirect\PCMService.exe
                      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                      C:\Program Files\Dell Support Center\bin\sprtcmd.exe
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\Program Files\HiYo\Bin\HiYo.exe
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Windows\system32\igfxsrvc.exe
                      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                      C:\Program Files\Digital Line Detect\DLG.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                      C:\Program Files\Dell\QuickSet\quickset.exe
                      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                      C:\Program Files\DellTPad\ApMsgFwd.exe
                      C:\Program Files\DellTPad\Apntex.exe
                      C:\Program Files\DellTPad\HidFind.exe
                      C:\Windows\system32\aestsrv.exe
                      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                      C:\Windows\system32\STacSV.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\SearchIndexer.exe
                      C:\Windows\system32\DRIVERS\xaudio.exe
                      c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
                      C:\Program Files\Windows Media Player\wmpnetwk.exe
                      C:\Program Files\iPod\bin\iPodService.exe
                      C:\Windows\system32\wbem\wmiprvse.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Program Files\Windows Live\Messenger\usnsvc.exe
                      C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
                      C:\Program Files\Creative Live! Cam\VideoFX\StartFX.exe
                      C:\Windows\System32\svchost.exe
                      C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
                      C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
                      C:\Windows\Explorer.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Windows\system32\SearchProtocolHost.exe
                      C:\Windows\system32\SearchFilterHost.exe
                      C:\Windows\system32\cmd.exe
                      C:\Windows\system32\wbem\wmiprvse.exe

                      »»»»»»»»»»»»»»»»»»»»»»»» hosts

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Mélanie

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\MLANIE~1\AppData\Local\Temp

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Mélanie\Application Data

                      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\MLANIE~1\FAVORI~1

                      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                      C:\Program Files\Google\googletoolbar1.dll PRESENT !

                      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                      »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      o4Patch
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      IEDFix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      Agent.OMZ.Fix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      VACFix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      404Fix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                      "AppInit_DLLs"="G G G G"

                      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                      "Userinit"="C:\\Windows\\system32\\userinit.exe,"
                      "System"=""

                      »»»»»»»»»»»»»»»»»»»»»»»» RK

                      »»»»»»»»»»»»»»»»»»»»»»»» DNS

                      Description: Carte Mini de réseau local sans fil Wireless 1395 de Dell
                      DNS Server Search Order: 194.230.1.103
                      DNS Server Search Order: 194.230.1.39

                      HKLM\SYSTEM\CCS\Services\Tcpip\..\{04D3793E-1142-4A79-AC2D-7D8B9AC7961D}: DhcpNameServer=194.230.1.103 194.230.1.39
                      HKLM\SYSTEM\CS1\Services\Tcpip\..\{04D3793E-1142-4A79-AC2D-7D8B9AC7961D}: DhcpNameServer=194.230.1.103 194.230.1.39
                      HKLM\SYSTEM\CS2\Services\Tcpip\..\{04D3793E-1142-4A79-AC2D-7D8B9AC7961D}: DhcpNameServer=194.230.1.103 194.230.1.39
                      HKLM\SYSTEM\CS3\Services\Tcpip\..\{04D3793E-1142-4A79-AC2D-7D8B9AC7961D}: DhcpNameServer=194.230.1.71 194.230.1.39
                      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=194.230.1.103 194.230.1.39
                      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=194.230.1.103 194.230.1.39
                      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=194.230.1.103 194.230.1.39
                      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=194.230.1.71 194.230.1.39

                      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                      »»»»»»»»»»»»»»»»»»»»»»»» Fin

                      0
                      1. Contributeur sécurité
                        Redémarre en mode sans échec comme indiqué ici ; Choisis ta session courante.

                        Pis chois l'option 2 supression.
                        0
                        1. Ca c est fait voila le rapport

                          SmitFraudFix v2.391

                          Rapport fait à 20:05:24.25, 21.01.2009
                          Executé à partir de C:\Users\Mélanie\Desktop\SmitfraudFix
                          OS: Microsoft Windows [version 6.0.6001] - Windows_NT
                          Le type du système de fichiers est NTFS
                          Fix executé en mode sans echec

                          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                          »»»»»»»»»»»»»»»»»»»»»»»» hosts

                          127.0.0.1 localhost
                          ::1 localhost
                          127.0.0.1 www.007guard.com
                          127.0.0.1 007guard.com
                          127.0.0.1 008i.com
                          127.0.0.1 www.008k.com
                          127.0.0.1 008k.com
                          127.0.0.1 www.00hq.com
                          127.0.0.1 00hq.com
                          127.0.0.1 010402.com
                          ...

                          »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                          VACFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                          S!Ri's WS2Fix: LSP not Found.

                          »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                          GenericRenosFix by S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                          C:\Program Files\Google\googletoolbar1.dll supprimé

                          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                          IEDFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

                          Agent.OMZ.Fix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                          404Fix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» RK

                          »»»»»»»»»»»»»»»»»»»»»»»» DNS

                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{04D3793E-1142-4A79-AC2D-7D8B9AC7961D}: DhcpNameServer=194.230.1.103 194.230.1.39
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{04D3793E-1142-4A79-AC2D-7D8B9AC7961D}: DhcpNameServer=194.230.1.103 194.230.1.39
                          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=194.230.1.103 194.230.1.39
                          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=194.230.1.103 194.230.1.39

                          »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                          "System"=""

                          »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                          Nettoyage terminé.

                          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» Fin

                          0
                          1. Contributeur sécurité
                            maintenant un nouvel hijackthis.
                            0
                            1. Il suffit de demander le voila

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 20:18:39, on 21.01.2009
                              Platform: Windows Vista SP1 (WinNT 6.00.1905)
                              MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                              Boot mode: Normal

                              Running processes:
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\Explorer.EXE
                              C:\Program Files\Dell\DellDock\DellDock.exe
                              C:\Program Files\DellTPad\Apoint.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\OEM02Mon.exe
                              C:\Windows\System32\igfxtray.exe
                              C:\Windows\System32\hkcmd.exe
                              C:\Windows\System32\igfxpers.exe
                              C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                              C:\Windows\System32\WLTRAY.EXE
                              C:\Windows\system32\igfxsrvc.exe
                              C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                              C:\Program Files\Dell\MediaDirect\PCMService.exe
                              C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\Program Files\HiYo\Bin\HiYo.exe
                              C:\Program Files\Dell Support Center\bin\sprtcmd.exe
                              C:\Program Files\Windows Media Player\wmpnscfg.exe
                              C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                              C:\Program Files\Digital Line Detect\DLG.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              C:\Program Files\Dell\QuickSet\quickset.exe
                              C:\Program Files\DellTPad\ApMsgFwd.exe
                              C:\Program Files\DellTPad\Apntex.exe
                              C:\Program Files\DellTPad\HidFind.exe
                              C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                              c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
                              C:\Users\Mélanie\Desktop\HiJackThis.exe

                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              O1 - Hosts: ::1 localhost
                              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                              O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                              O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
                              O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
                              O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
                              O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
                              O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                              O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                              O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                              O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                              O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
                              O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                              O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
                              O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKLM\..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
                              O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
                              O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                              O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
                              O4 - Global Startup: BTTray.lnk = ?
                              O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
                              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
                              O8 - Extra context menu item: Ajouter à Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                              O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                              O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                              O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                              O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                              O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                              O13 - Gopher Prefix:
                              O20 - AppInit_DLLs: G G G G
                              O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
                              O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                              O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
                              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
                              O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                              O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                              O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
                              O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
                              O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
                              O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                              0
                              1. Hello message erreur 404

                                La page demandée ne se trouve plus à l'emplacement indiqué !

                                la demo non plus

                                Informations Produits

                                Les Services AOL Blogs et AOL PagesPerso sont désormais fermés. Veuillez nous en excuser.

                                as tu un autre lien ?
                                0
                                • 1
                                • 2
                                • 3
                                • 4