Infecté par virus Win32:Agent-ACJD

Bonjour, mon ordi est infecté par le virus Win32:Agent-ACJD j'ai donc télécharger hijackthis pour relever les problèmes voici ce que le scan affiche :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:30:01, on 19/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\EoRezo\EoEngine.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\Controle Parental\bin\OPTGui.exe
C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Users\bertin\AppData\Local\yaqcuqu.exe
C:\Users\bertin\Program Files\DNA\btdna.exe
C:\Windows\ehome\ehmsas.exe
C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\bertin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZA864KU1\HiJackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.fr.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: EoBho - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll
O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb127\Dealio.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb127\Dealio.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
O4 - HKLM\..\Run: [Setresolution] C:\ACERSW\config\1680x1050.cmd
O4 - HKLM\..\Run: [Apanel] C:\ACERSW\config\NewSetApanel.cmd
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [OPTENET_GUI] C:\PROGRA~1\CONTRO~1\bin\optgui.exe
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [DACSMiniApp] C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [yaqcuqu] "c:\users\bertin\appdata\local\yaqcuqu.exe" yaqcuqu
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\bertin\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Sommaire de OneNote.onetoc2
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Compare Prices with &Dealio - C:\Users\bertin\AppData\LocalLow\Dealio\kb127\res\DealioSearch.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
O13 - Gopher Prefix:
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Service Google Update (gupdate1c991181ca94620) (gupdate1c991181ca94620) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Orange Contrôle Parental (OPTENET_FILTER) - Orange - C:\Program Files\Controle Parental\bin\optproxy.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

--
End of file - 10736 bytes

merci d'avance pour votre aide
Configuration: Windows Vista
Internet Explorer 7.0

9 réponses

  1. Contributeur sécurité
    salut ; tu a plusieurs infections

    on va essayer de nettoyer tout sa s'il est pas trop tard

    Tu utilises vista, tu dois donc aussi désactiver l'UAC avant d'utiliser ces logiciels.

    - Vas dans démarrer puis panneau de configuration
    - Double Clique sur l'icône "Comptes d'utilisateurs"
    - Clique ensuite sur désactiver et valide.

    Regarde ici pour savoir comment désactiver l'UAC sous vista ==> ICI
    http://www.bibou0007.com/windows-vista-f102/tutorial-desactiver-l-uac-sur-vista-t132.htm

    1/ telecharger :

    http://siri.urz.free.fr/Fix/SmitfraudFix.php

    1clic droit et excuter en tant qu'administrateur . puis sélectionne 1 et appuyer sur entrée afin de créer le rapport des infection présentes

    Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...)

    Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
    Mais C.. de penser que ­tu es libre...Merci a australe13
    0
    1. voici mon rapport effectué par smitfraudfix. Merci d'avance pour vos conseils
      SmitFraudFix v2.398

      Scan done at 15:30:28,72, 19/02/2009
      Run from C:\Users\bertin\Desktop\SmitfraudFix
      OS: Microsoft Windows [version 6.0.6001] - Windows_NT
      The filesystem type is NTFS
      Fix run in normal mode

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\Windows\system32\csrss.exe
      C:\Windows\system32\wininit.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\services.exe
      C:\Windows\system32\lsass.exe
      C:\Windows\system32\lsm.exe
      C:\Windows\system32\winlogon.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\nvvsvc.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\SLsvc.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\rundll32.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\Windows\System32\spoolsv.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
      C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
      C:\Windows\system32\svchost.exe
      C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
      C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\Program Files\Google\Update\GoogleUpdate.exe
      C:\Program Files\Controle Parental\bin\optproxy.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\SearchIndexer.exe
      C:\Windows\system32\WUDFHost.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Windows\RtHDVCpl.exe
      C:\Acer\Empowering Technology\SysMonitor.exe
      C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\Search Settings\SearchSettings.exe
      C:\Program Files\EoRezo\EoEngine.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\Windows\WindowsMobile\wmdSync.exe
      C:\Program Files\Controle Parental\bin\OPTGui.exe
      C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
      C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
      C:\Windows\System32\rundll32.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Users\bertin\AppData\Local\yaqcuqu.exe
      C:\Windows\ehome\ehmsas.exe
      C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\mobsync.exe
      C:\Program Files\DNA\btdna.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Windows\system32\cmd.exe
      C:\Windows\system32\conime.exe
      C:\Program Files\OrangeHSS\Launcher\Launcher.exe
      C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
      C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
      C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
      C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
      C:\Windows\system32\wbem\wmiprvse.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\bertin

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\bertin\AppData\Local\Temp

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\bertin\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\bertin\Pictures\FAVORI~1

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      C:\Program Files\Google\googletoolbar1.dll FOUND !

      »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

      »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
      !!!Attention, following keys are not inevitably infected!!!

      o4Patch
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, following keys are not inevitably infected!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
      !!!Attention, following keys are not inevitably infected!!!

      Agent.OMZ.Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, following keys are not inevitably infected!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
      !!!Attention, following keys are not inevitably infected!!!

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, following keys are not inevitably infected!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, following keys are not inevitably infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""
      "LoadAppInit_DLLs"=dword:00000000

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
      !!!Attention, following keys are not inevitably infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "Userinit"="C:\\Windows\\system32\\userinit.exe,"

      »»»»»»»»»»»»»»»»»»»»»»»» RK

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: SiS191 Ethernet Controller
      DNS Server Search Order: 192.168.1.1

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{C2B218E3-51B5-434A-8775-34E10D41BD45}: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{C2B218E3-51B5-434A-8775-34E10D41BD45}: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{C2B218E3-51B5-434A-8775-34E10D41BD45}: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

      »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

      »»»»»»»»»»»»»»»»»»»»»»»» End
      0
      1. Contributeur sécurité
        Redémarrer l'ordinateur en mode sans échec pour cela (tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter)

        clic droit et exécute en tant qu'administrateur sur smitfraudfix.cmd

        Sélectionner 2 pour supprimer les fichiers responsables de l'infection.
        A la question Voulez-vous nettoyer le registre ? répondre O (oui) afin de débloquer le fond d'écran et supprimer les clés de démarrage automatique de l'infection.

        Le fix déterminera si le fichier wininet.dll est infecté. A la question Corriger le fichier infecté ? répondre O (oui) pour remplacer le fichier corrompu.

        Redémarrer en mode normal et poster le rapport

        sa va te faire disparaitre le fond d'écran de bureau
        0
        1. j'ai bien démarrerl'ordi en mode sans échec et fait les démarches à suivre voici le rapport
          SmitFraudFix v2.398

          Rapport fait à 19:42:35,60, 19/02/2009
          Executé à partir de C:\Users\bertin\Desktop\SmitfraudFix
          OS: Microsoft Windows [version 6.0.6001] - Windows_NT
          Le type du système de fichiers est NTFS
          Fix executé en mode sans echec

          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

          »»»»»»»»»»»»»»»»»»»»»»»» hosts

          127.0.0.1 localhost
          ::1 localhost

          »»»»»»»»»»»»»»»»»»»»»»»» VACFix

          VACFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

          S!Ri's WS2Fix: LSP not Found.

          »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

          GenericRenosFix by S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

          IEDFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

          Agent.OMZ.Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

          404Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» RK

          »»»»»»»»»»»»»»»»»»»»»»»» DNS

          HKLM\SYSTEM\CCS\Services\Tcpip\..\{C2B218E3-51B5-434A-8775-34E10D41BD45}: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{C2B218E3-51B5-434A-8775-34E10D41BD45}: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS3\Services\Tcpip\..\{C2B218E3-51B5-434A-8775-34E10D41BD45}: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

          »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

          »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

          Nettoyage terminé.

          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» Fin
          0
          1. Contributeur sécurité
            Télécharges http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe ( de Cyrildu17 / C_XX ) sur ton bureau :

            /!\ Déconnectes toi et fermes toutes applications en cours

            ●un clic droit et exécuter en tant qu'administrateur sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )

            ● un clic droit et exécuter en tant qu'administrateur sur l'icône Ad-remover située sur ton bureau
            ● Au menu principal choisi l'option "A"
            ● Postes le rapport qui apparait à la fin .

            ( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

            (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

            Note :

            "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
            Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
            Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...)
            0
            1. ------- LOGFILE OF AD-REMOVER 1.1.1.3 | ONLY XP/VISTA -------

              Updated by C_XX on 15/02/2009 at 10:20

              Start at: 20:03:36 | Thu 19/02/2009 | Boot mode: Normal Boot
              Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
              Operating System: Microsoft® Windows Vista™ Home Premium Service Pack 1 (version 6.0.6001)
              Computer Name: PC-DE-BERTIN
              Current User: bertin - Administrator
              Drive(s):
              - C:\ (File System: NTFS)
              - D:\ (File System: NTFS)
              System Drive: C:\
              Windows Directory: C:\Windows\
              System Directory: C:\Windows\System32\

              --- Running Processes: 81
              --- User Account Control is DISABLE

              +-----------------| Boonty/Boonty Games Elements Found:

              .
              .
              C:\Program Files\BoontyGames
              C:\Program Files\BoontyGames\Components

              +-----------------| Eorezo Elements Found:

              HKCR\AppID\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}
              HKCR\AppID\EoRezoBHO.DLL
              HKCR\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}
              HKCR\EoRezoBHO.EoBho
              HKCR\EoRezoBHO.EoBho.1
              HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
              HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
              HKCR\Typelib\{B6ACB3F1-6A83-432C-B854-3E1056F87F4E}
              HKCU\Software\EoRezo
              HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
              HKLM\Software\EoRezo
              HKLM\Software\Classes\AppID\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}
              HKLM\Software\Classes\AppID\EoRezoBHO.DLL
              HKLM\Software\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}
              HKLM\Software\Classes\EoRezoBHO.EoBho
              HKLM\Software\Classes\EoRezoBHO.EoBho.1
              HKLM\Software\Classes\TypeLib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
              HKLM\Software\Classes\TypeLib\{B6ACB3F1-6A83-432C-B854-3E1056F87F4E}
              HKLM\Software\Classes\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
              HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
              HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\eoEngine_is1
              HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Eoengine
              .
              C:\Program Files\EoRezo
              C:\Program Files\EoRezo\EoAdv
              C:\Program Files\EoRezo\lang
              C:\Users\bertin\AppData\Roaming\EoRezo
              C:\Users\bertin\AppData\Roaming\EoRezo\db
              C:\Users\bertin\AppData\Roaming\EoRezo\eoDesktop
              C:\Users\bertin\AppData\Roaming\EoRezo\eoStats
              C:\Users\gwada971bertina@hotm\AppData\Roaming\Eorezo
              C:\Users\gwada971bertina@hotm\AppData\Roaming\Eorezo\db
              C:\Users\Invit‚\AppData\Roaming\Eorezo
              C:\Users\Invit‚\AppData\Roaming\Eorezo\db
              C:\Users\bertin\AppData\Roaming\Microsoft\Windows\Cookies\bertin@eorezo[2].txt
              C:\Users\gwada971bertina@hotm\AppData\Roaming\Microsoft\Windows\Cookies\gwada971bertina@hotm@eorezo[1].txt
              C:\Users\Invit‚\AppData\Roaming\Microsoft\Windows\Cookies\invit‚@eorezo[1].txt

              +-----------------| Infected Poker Softwares Elements Found:

              .

              +-----------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements Found:

              .
              HKCR\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239}
              HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
              .

              +-----------------| It's TV Elements Found:

              .

              +-----------------| Sweetim Elements Found:

              .

              +-----------------| Added Scan:

              ---- Mozilla FireFox Version [Unable to get version] ----

              ProfilePath: 0bnn2hcp.default
              .
              Prefs.js: Browser.Search.DefaultEngineName: "Yahoo"
              Prefs.js: Browser.Search.SelectedEngine: "Yahoo"
              Prefs.js: Browser.Search.DefaultUrl: "hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query="
              .
              (Prefs.js) FOUND: user_pref("browser.startup.homepage", "http://lo.st#");
              .
              .
              .
              .

              ---- Internet Explorer Version 7.0.6001.18000 ----

              +-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

              Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

              +-[HKEY_USERS\S-1-5-21-3050582356-4211933416-910971510-1000\..\Internet Explorer\Main]

              Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

              +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

              Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
              Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home

              +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

              Tabs: hxxp://www.lo.st/?tabs

              +---------------------------------------------------------------------------+

              [~4832 Bytes] - "C:\Ad-Report-Scan-19.02.2009.log"
              -

              End at: 20:05:30 | 19/02/2009
              .
              +-----------------| E.O.F - 99 Lines
              .
              0
              1. Contributeur sécurité
                tu relance ad-remover et tu choisie l'option B

                dans la fenêtre qui s'ouvre tu coche tout sauf sweetim et tu fait supprimer
                0
                1. ------- LOGFILE OF AD-REMOVER 1.1.1.3 | ONLY XP/VISTA -------

                  Updated by C_XX on 15/02/2009 at 10:20

                  *** LIMITED TO ***

                  Boonty/BoontyGames
                  Eorezo
                  Infected Poker Softwares
                  FunWebProduct/MyWay/MyWebSearch
                  It's TV

                  ******************

                  Start at: 20:18:25 | Thu 19/02/2009 | Boot mode: Normal Boot
                  Option: CLEAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
                  Operating System: Microsoft® Windows Vista™ Home Premium Service Pack 1 (version 6.0.6001)
                  Computer Name: PC-DE-BERTIN
                  Current User: bertin - Administrator
                  Drive(s):
                  - C:\ (File System: NTFS)
                  - D:\ (File System: NTFS)
                  System Drive: C:\
                  Windows Directory: C:\Windows\
                  System Directory: C:\Windows\System32\

                  --- Running Processes: 76
                  --- User Account Control is DISABLE

                  (!) ---- IE start pages/Tabs reset

                  +--------------------| Boonty/Boonty Games Elements Deleted :

                  .
                  .
                  C:\Program Files\BoontyGames

                  +-----------------| Eorezo Elements Deleted :

                  HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Eoengine
                  HKCR\AppID\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}
                  HKCR\AppID\EoRezoBHO.DLL
                  HKCR\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}
                  HKCR\EoRezoBHO.EoBho
                  HKCR\EoRezoBHO.EoBho.1
                  HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
                  HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
                  HKCR\Typelib\{B6ACB3F1-6A83-432C-B854-3E1056F87F4E}
                  HKCU\Software\EoRezo
                  HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
                  HKLM\Software\EoRezo
                  HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
                  HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\eoEngine_is1
                  .
                  C:\Program Files\EoRezo
                  C:\Users\bertin\AppData\Roaming\EoRezo
                  C:\Users\gwada971bertina@hotm\AppData\Roaming\Eorezo
                  C:\Users\Invit‚\AppData\Roaming\Eorezo
                  C:\Users\bertin\AppData\Roaming\Microsoft\Windows\Cookies\bertin@eorezo[2].txt
                  C:\Users\gwada971bertina@hotm\AppData\Roaming\Microsoft\Windows\Cookies\gwada971bertina@hotm@eorezo[1].txt
                  C:\Users\Invit‚\AppData\Roaming\Microsoft\Windows\Cookies\invit‚@eorezo[1].txt

                  +-----------------| Infected Poker Softwares Elements Deleted :

                  .

                  +-----------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements Deleted :

                  .
                  HKCR\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239}
                  HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
                  .

                  +-----------------| It's TV Elements Deleted :

                  .

                  (!) ---- Temp files deleted.
                  (!) ---- Recycle bin emptied in all drives.

                  +-----------------| Added Scan :

                  ---- Mozilla FireFox Version [Unable to get version] ----

                  ProfilePath: 0bnn2hcp.default
                  .
                  Prefs.js: Browser.Search.DefaultEngineName: "Yahoo"
                  Prefs.js: Browser.Search.SelectedEngine: "Yahoo"
                  Prefs.js: Browser.Search.DefaultUrl: "hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query="
                  .
                  (Prefs.js) REMOVED: user_pref("browser.startup.homepage", "http://lo.st#");
                  .
                  .
                  .
                  .

                  ---- Internet Explorer Version 7.0.6001.18000 ----

                  +-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

                  Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                  Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                  Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                  +-[HKEY_USERS\S-1-5-21-3050582356-4211933416-910971510-1000\..\Internet Explorer\Main]

                  Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                  Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                  Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                  +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

                  Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                  Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Search bar: hxxp://search.msn.com/spbasic.htm
                  Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Start page: hxxp://fr.msn.com/

                  +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

                  Tabs: hxxp://ieframe.dll/tabswelcome.htm

                  +---------------------------------------------------------------------------+

                  [~4514 Bytes] - "C:\Ad-Report-Clean-19.02.2009.log"
                  [~4964 Bytes] - "C:\Ad-Report-Scan-19.02.2009.log"
                  -
                  C:\Program Files\Ad-remover\TOOLS\BACKUP\19.02.2009 - Prefs.js

                  End at: 20:19:52 | 19/02/2009
                  .
                  +-----------------| E.O.F - 96 Lines
                  .
                  0
                  1. Contributeur sécurité
                    tu peut mettre un nouveau rapport hijackthis stp
                    0