Trojan Fakeavalert.B - Page 2

  1. Contributeur sécurité
    vas voir dans la quarantaine de malwarebytes et supprimer tout ce qu'il y a dedans...

    Ensuite réessaye un examen complet
    0
    1. Bonsoir,

      Tout a été fait selon les instructions mais le Malwarebytes ne fonctionne pas en examen complet et le virus est toujours existant...C'est un coriace celui-la... :-)
      0
      1. Contributeur sécurité
        Bonsoir,

        refais un nouveau rapport hijackthis stp
        0
        1. Voilà. Merci d'avance

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 23:19:35, on 8/02/2009
          Platform: Windows Vista SP1 (WinNT 6.00.1905)
          MSIE: Internet Explorer v8.00 (8.00.6001.18372)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Common Files\Symantec Shared\ccApp.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
          C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
          C:\Windows\system32\taskeng.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Analog Devices\Core\smax4pnp.exe
          C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
          C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Beeline Mobile office\GlobeTrotter Connect\GlobeTrotter Connect.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Program Files\SpyNoMore\SNM.exe
          C:\Program Files\uTorrent\uTorrent.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/?p=us
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O1 - Hosts: ::1 localhost
          O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
          O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
          O2 - BHO: (no name) - {43686290-E166-4A4A-B622-69EC2F96A182} - C:\Windows\system32\geBrrQjJ.dll (file missing)
          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
          O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
          O3 - Toolbar: Afficher Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
          O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
          O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
          O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
          O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
          O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
          O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
          O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
          O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')
          O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
          O4 - Global Startup: GlobeTrotter Connect.lnk = C:\Program Files\Beeline Mobile office\GlobeTrotter Connect\GlobeTrotter Connect.exe
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
          O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
          O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
          O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
          O13 - Gopher Prefix:
          O15 - Trusted Zone: https://accounts.google.com/ServiceLogin?passive=1209600&continue=https://get.google.com/albumarchive&followup=https://get.google.com/albumarchive
          O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
          O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/39.24/uploader2.cab
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
          O20 - AppInit_DLLs: ujhkxv.dll byeyhc.dll
          O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: ccEvtMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: ccSetMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
          O23 - Service: GtFlashSwitch - OptionNV - C:\Program Files\Common Files\GtFlashSwitch\GtFlashSwitch.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\Windows\system32\ibmpmsvc.exe
          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE
          O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
          O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
          O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
          O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
          O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
          O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
          O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe
          O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
          O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
          O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
          0
          1. Contributeur sécurité
            Pourrais-tu me dire exactement où se trouve ce trojan fakealert ??
            0
            1. Bonjour,

              Que dois-je faire pour connaître cet emplacement?

              Merci
              0
              1. Contributeur sécurité
                Bonjour,

                Tu dis que le virus est toujours présent... As-tu eu une alerte de ton antivirus ??
                0
                1. Oui, Norton m'indique maintenant que des corrections manuelles sont requises pour Trojqn Fakeavalet.B, Trojan Horse, W32 SPybot.Worm....
                  0
                  1. Contributeur sécurité
                    Et vois-tu leurs emplacements ??
                    0
                    1. Contributeur sécurité
                      ▶ Télécharge RogueRemover

                      ▶ Voici un tutoriel qui te guidera pour savoir l'utiliser

                      ▶ signales ce qu'il a supprimé et refais un nouveau rapport hijackthis stp.
                      0
                      1. C'est fait et rien n'a été detecté...

                        Merci
                        0
                        1. Contributeur sécurité
                          Fais ceci :

                          Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                          ▶ Va dans démarrer puis panneau de configuration
                          ▶ Double Clique sur l'icône "Comptes d'utilisateurs"
                          ▶ Clique ensuite sur désactiver et valide.

                          Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques :

                          ▶ Télécharge Toolscleaner sur ton Bureau

                          ▶ Double-clique sur ToolsCleaner2.exe et laisse le travailler
                          ▶ Clique sur Recherche et laisse le scan se terminer.
                          ▶ Clique sur Suppression pour finaliser.
                          ▶ Tu peux, si tu le souhaites, te servir des Options facultatives.
                          ▶ Clique sur Quitter, pour que le rapport puisse se créer.
                          ▶ Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse
                          0
                          1. Voilà:

                            [ Rapport ToolsCleaner version 2.3.0 (par A.Rothstein & dj QUIOU) ]

                            -->- Recherche:

                            C:\lopR.txt: trouvé !
                            C:\Lop SD: trouvé !
                            C:\Program Files\Trend Micro\HijackThis: trouvé !
                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
                            C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
                            C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
                            C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
                            C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
                            C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
                            C:\Users\JFV\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: trouvé !
                            C:\Users\JFV\Desktop\HijackThis.lnk: trouvé !
                            C:\Users\JFV\Desktop\LopSD.exe: trouvé !
                            C:\Users\JFV\Documents\Mes téléchargements\HJTInstall.exe: trouvé !
                            C:\Users\JFV\Documents\Mes téléchargements\SmitFraudFix.exe: trouvé !
                            C:\Users\JFV\Documents\Mes téléchargements\SmitFraudfix: trouvé !

                            ---------------------------------
                            -->- Suppression:

                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
                            C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: supprimé !
                            C:\Users\JFV\Desktop\HijackThis.lnk: supprimé !
                            C:\Users\JFV\Desktop\LopSD.exe: supprimé !
                            C:\Users\JFV\Documents\Mes téléchargements\HJTInstall.exe: supprimé !
                            C:\Users\JFV\Documents\Mes téléchargements\SmitFraudFix.exe: supprimé !
                            C:\lopR.txt: supprimé !
                            C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
                            C:\Lop SD: supprimé !
                            C:\Program Files\Trend Micro\HijackThis: supprimé !
                            C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: supprimé !
                            C:\Users\JFV\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: supprimé !
                            C:\Users\JFV\Documents\Mes téléchargements\SmitFraudfix: supprimé !

                            Fichiers temporaires nettoyés !
                            Corbeille vidée!
                            Sauvegarde du registre crée !
                            0
                            1. Contributeur sécurité
                              Ok maintenant refais ceci stp :

                              Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                              ▶ Va dans démarrer puis panneau de configuration
                              ▶ Double Clique sur l'icône "Comptes d'utilisateurs"
                              ▶ Clique ensuite sur désactiver et valide.

                              ensuite :

                              Option 1 - Recherche :

                              ▶ télécharge smitfraudfix et enregistre le sur le bureau

                              ▶ Ensuite double clique sur smitfraudfix puis exécuter

                              ▶ Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.

                              (attention : N utilises pas l option 2 si je ne te l ai pas demandé !!)

                              ▶ copier/coller le rapport dans la réponse.

                              Voici un tutoriel sonore et animé en cas de problème d'utilisation

                              (Attention : "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool".
                              Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains,
                              cet utilitaire pourrait arrêter des logiciels de sécurité.)

                              0
                              1. SmitFraudFix v2.394

                                Scan done at 14:01:03,49, lun. 09/02/2009
                                Run from C:\Users\JFV\Desktop\SmitfraudFix
                                OS: Microsoft Windows [Version 6.0.6001] - Windows_NT
                                The filesystem type is NTFS
                                Fix run in normal mode

                                »»»»»»»»»»»»»»»»»»»»»»»» Process

                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\wininit.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\services.exe
                                C:\Windows\system32\lsass.exe
                                C:\Windows\system32\lsm.exe
                                C:\Windows\system32\winlogon.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\ibmpmsvc.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\Ati2evxx.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\SLsvc.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\Ati2evxx.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\spoolsv.exe
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\Explorer.EXE
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\AEADISRV.EXE
                                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                C:\Program Files\Bonjour\mDNSResponder.exe
                                C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Program Files\Common Files\GtFlashSwitch\GtFlashSwitch.exe
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
                                C:\Program Files\Java\jre6\bin\jusched.exe
                                C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                                C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                                C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
                                C:\Windows\system32\IoctlSvc.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\PSIService.exe
                                c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
                                C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\SearchIndexer.exe
                                C:\Windows\system32\DRIVERS\xaudio.exe
                                C:\Program Files\Lenovo\System Update\SUService.exe
                                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
                                C:\Program Files\iTunes\iTunesHelper.exe
                                C:\Program Files\Analog Devices\Core\smax4pnp.exe
                                C:\Program Files\Google\Gmail Notifier\gnotify.exe
                                C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
                                C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
                                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                C:\Program Files\Beeline Mobile office\GlobeTrotter Connect\GlobeTrotter Connect.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
                                C:\Program Files\iPod\bin\iPodService.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                C:\Program Files\Windows Media Player\wmpnscfg.exe
                                C:\Program Files\Windows Media Player\wmpnetwk.exe
                                C:\Program Files\Mozilla Firefox\firefox.exe
                                C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                                C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                                C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
                                C:\Program Files\Megaupload\Mega Manager\MegaManager.exe
                                C:\Program Files\VideoLAN\VLC\vlc.exe
                                C:\Program Files\SmartVoip.com\SmartVoip\SmartVoip.exe
                                C:\Windows\system32\SearchProtocolHost.exe
                                C:\Windows\system32\SearchFilterHost.exe
                                C:\Windows\system32\conime.exe
                                C:\Windows\system32\wbem\wmiprvse.exe
                                C:\Windows\system32\DllHost.exe
                                C:\Users\JFV\Desktop\SmitfraudFix\Policies.exe
                                C:\Windows\system32\cmd.exe
                                C:\Windows\system32\DllHost.exe

                                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\JFV

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\JFV\AppData\Local\Temp

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\JFV\Application Data

                                »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\JFV\FAVORI~1

                                »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                                »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                                »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                                »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                                !!!Attention, following keys are not inevitably infected!!!

                                o4Patch
                                Credits: Malware Analysis & Diagnostic
                                Code: S!Ri

                                »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                                !!!Attention, following keys are not inevitably infected!!!

                                IEDFix
                                Credits: Malware Analysis & Diagnostic
                                Code: S!Ri

                                »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                                !!!Attention, following keys are not inevitably infected!!!

                                Agent.OMZ.Fix
                                Credits: Malware Analysis & Diagnostic
                                Code: S!Ri

                                »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                                !!!Attention, following keys are not inevitably infected!!!

                                VACFix
                                Credits: Malware Analysis & Diagnostic
                                Code: S!Ri

                                »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                                !!!Attention, following keys are not inevitably infected!!!

                                404Fix
                                Credits: Malware Analysis & Diagnostic
                                Code: S!Ri

                                »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                                !!!Attention, following keys are not inevitably infected!!!

                                SrchSTS.exe by S!Ri
                                Search SharedTaskScheduler's .dll

                                »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                                !!!Attention, following keys are not inevitably infected!!!

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                                "LoadAppInit_DLLs"=dword:00000000
                                "AppInit_DLLs"="ujhkxv.dll byeyhc.dll"

                                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                                !!!Attention, following keys are not inevitably infected!!!

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                "Userinit"="C:\\Windows\\system32\\userinit.exe,"

                                »»»»»»»»»»»»»»»»»»»»»»»» RK

                                »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                Description: Intel(R) PRO/Wireless 3945ABG Network Connection
                                DNS Server Search Order: 192.168.1.1

                                HKLM\SYSTEM\CCS\Services\Tcpip\..\{CA43C17D-9E57-4C1F-B15B-7A322B0B04B5}: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CCS\Services\Tcpip\..\{CE060DBA-FDFA-4396-9CC3-F5DFC8D32E21}: DhcpNameServer=217.118.66.243 217.118.66.244
                                HKLM\SYSTEM\CS1\Services\Tcpip\..\{CA43C17D-9E57-4C1F-B15B-7A322B0B04B5}: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS2\Services\Tcpip\..\{CA43C17D-9E57-4C1F-B15B-7A322B0B04B5}: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS2\Services\Tcpip\..\{CE060DBA-FDFA-4396-9CC3-F5DFC8D32E21}: DhcpNameServer=217.118.66.243 217.118.66.244
                                HKLM\SYSTEM\CS3\Services\Tcpip\..\{CA43C17D-9E57-4C1F-B15B-7A322B0B04B5}: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS3\Services\Tcpip\..\{CE060DBA-FDFA-4396-9CC3-F5DFC8D32E21}: DhcpNameServer=217.118.66.243 217.118.66.244
                                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                                »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                                »»»»»»»»»»»»»»»»»»»»»»»» End
                                0
                                1. Contributeur sécurité
                                  Option 2 - Nettoyage :

                                  ▶ redémarre le PC en mode sans échec

                                  ▶ Double cliquer sur smitfraudfix

                                  ▶ Sélectionner 2 pour supprimer les fichiers responsables de l'infection.

                                  ▶ A la question Voulez-vous nettoyer le registre ? répondre O (oui) afin de débloquer le fond d'écran et supprimer les clés de démarrage automatique de l'infection.

                                  Le fix déterminera si le fichier wininet.dll est infecté. A la question Corriger le fichier infecté ? répondre O (oui) pour remplacer le fichier corrompu.

                                  ▶ Enregistre le rapport sur ton bureau

                                  ▶ Redémarrer en mode normal et poster le rapport.

                                  Ensuite refais une analyse avec Malwarebytes stp
                                  0
                                  1. voilà

                                    SmitFraudFix v2.394

                                    Scan done at 14:26:21,80, lun. 09/02/2009
                                    Run from C:\Users\JFV\Desktop\SmitfraudFix
                                    OS: Microsoft Windows [Version 6.0.6001] - Windows_NT
                                    The filesystem type is NTFS
                                    Fix run in safe mode

                                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                                    !!!Attention, following keys are not inevitably infected!!!

                                    SrchSTS.exe by S!Ri
                                    Search SharedTaskScheduler's .dll

                                    »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                    127.0.0.1 localhost
                                    ::1 localhost

                                    »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                                    VACFix
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                                    S!Ri's WS2Fix: LSP not Found.
                                    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                                    GenericRenosFix by S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                                    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                                    IEDFix
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

                                    Agent.OMZ.Fix
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                                    404Fix
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» RK

                                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{CA43C17D-9E57-4C1F-B15B-7A322B0B04B5}: DhcpNameServer=192.168.1.1
                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{CE060DBA-FDFA-4396-9CC3-F5DFC8D32E21}: DhcpNameServer=217.118.66.243 217.118.66.244
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{CA43C17D-9E57-4C1F-B15B-7A322B0B04B5}: DhcpNameServer=192.168.1.1
                                    HKLM\SYSTEM\CS2\Services\Tcpip\..\{CA43C17D-9E57-4C1F-B15B-7A322B0B04B5}: DhcpNameServer=192.168.1.1
                                    HKLM\SYSTEM\CS2\Services\Tcpip\..\{CE060DBA-FDFA-4396-9CC3-F5DFC8D32E21}: DhcpNameServer=217.118.66.243 217.118.66.244
                                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{CA43C17D-9E57-4C1F-B15B-7A322B0B04B5}: DhcpNameServer=192.168.1.1
                                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{CE060DBA-FDFA-4396-9CC3-F5DFC8D32E21}: DhcpNameServer=217.118.66.243 217.118.66.244
                                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                    HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                                    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

                                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                                    !!!Attention, following keys are not inevitably infected!!!

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                                    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                                    Registry Cleaning done.

                                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                                    !!!Attention, following keys are not inevitably infected!!!

                                    SrchSTS.exe by S!Ri
                                    Search SharedTaskScheduler's .dll

                                    »»»»»»»»»»»»»»»»»»»»»»»» End
                                    0
                                    1. Bonjour,

                                      J'espère que vous avez passé un bon week-end. Mon problème de virus n'étant toujours pas résolu, je reviens vers vous pour une solution éventuelle. Mon antivirus le détecte toujours.

                                      Merci d'avance
                                      0
                                      Précédent
                                      • 1
                                      • 2