Rootkit pilote masqué

Bonjour à tous,
J'ai un rootkit, que AVG 8 n'arrive pas à éliminer. Il se trouve dans : C:\Windows\system32\drivers\mchlnjDrv.sys. Le pilote est masqué.
L'orsque je fais supprimer ou réparer il m'indique que l'accès est refusé. En faisant un nouveau scan le rootkit n'est plus le même. il peut s'appeler: apyeqty7.sys.
J'ai essayé sans succès de le supprimer avec VirusKeeper (il ne le trouve pas).

HELP ! Que dois-je faire pour le supprimer?

Merci d'avance pour votre aide.
(Mon Pc fonctionne sous Vista avec internet explorer8 ).

Voiçi un rapport fait avec HijackThis .
http://www.trendsecure.com/portal/en-US/tools/security_tools­­/hijackthis/download
Do a system scan and save a logfile.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:46:58, on 23/06/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFont­Cache.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\ltmoh\ltmoh.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe­
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
c:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
c:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office 07 vieux\Office\Winword.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.fr/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hugedomains.com/domain_profile.cfm?d=cooxer&e=com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
O4 - HKCU\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://gruatbaur.spaces.live.com/PhotoUpload/VistaMsnPUpldfr-fr.cab
O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} (IPSUploader4 Control) - http://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader4.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.mypix.com/fr/fr/importer/ImageUploader4.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - c:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - c:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

End of file - 13581 bytes

Configuration: Windows Vista Internet Explorer 8.0
Configuration: Windows Vista Internet Explorer 7.0

14 réponses

  1. Contributeur sécurité
    salut,

    tu as trois logiciels de protection...(antispyware)
    1)tu n'es pas mieux protégé pour autant
    2)tu ralentis considérablement ton PC
    3)tu risques des plantages

    plus d'info ici: https://forum.malekal.com/viewtopic.php?f=45&t=4650

    bref tu dois faire du ménage dans tes logiciels de protection

    désinstalle spyware doctor et spybot

    Télécharge random's system information tool (RSIT) par random/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.
    Clique "Continue" à l'écran Disclaimer.

    Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT va le télécharger (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.
    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    0
    1. Merci pour tes conseils,

      1/ Ménage fait
      -J'ai éffacé Spybot, et spyware doctor + viruskeeper installés à l'occasion pour tanter de me débarasser de ce Rootkit.
      2/ Rapports de RSIT

      LOG
      Logfile of random's system information tool 1.06 (written by random/random)
      Run by maison at 2009-06-24 11:45:16
      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
      System drive C: has 34 GB (44%) free of 76 GB
      Total RAM: 3061 MB (55% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:45:24, on 24/06/2009
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Windows\System32\igfxtray.exe
      C:\Windows\System32\hkcmd.exe
      C:\Windows\System32\igfxpers.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
      C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
      C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
      C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
      C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
      C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
      C:\Program Files\AVG\AVG8\avgtray.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
      C:\Program Files\ltmoh\ltmoh.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
      C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
      C:\Program Files\Windows Mail\WinMail.exe
      C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
      C:\Windows\system32\wuauclt.exe
      C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
      C:\Users\maison\Desktop\RSIT.exe
      C:\Program Files\Trend Micro\HijackThis\maison.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.fr/?gws_rd=ssl
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hugedomains.com/domain_profile.cfm?d=cooxer&e=com
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
      R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
      O1 - Hosts: ::1 localhost
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
      O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
      O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
      O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
      O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
      O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
      O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
      O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
      O4 - HKCU\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
      O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
      O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
      O13 - Gopher Prefix:
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
      O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://gruatbaur.spaces.live.com/PhotoUpload/VistaMsnPUpldfr-fr.cab
      O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} (IPSUploader4 Control) - http://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader4.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.mypix.com/fr/fr/importer/ImageUploader4.cab
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O20 - AppInit_DLLs: avgrsstx.dll
      O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
      O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
      O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - c:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
      O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - c:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
      O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
      0
      1. Contributeur sécurité
        bien,

        tu as trois infections différentes

        /!\IMPORTANT/!\
        Désactive l'UAC (User Account Control ou Contrôle de Compte Utilisateur) le temps de la désinfection,tu le réactiveras après ta désinfection:
        • Va dans Panneau de Configuration puis Comptes d'Utilisateurs.
        • Clique sur "Activer" ou "désactiver" le contrôle des comptes utilisateurs.
        • Décoche la case "Utiliser le contrôle des comptes utilisateurs pour vous aider à protéger votre ordinateur".
        • Clique sur OK pour enregistrer la modification et redémarre ton PC lorsque cela t'est demandé.

        aide en cas de problèmes

        on commence

        Télécharge et installe UsbFix de C_XX & Chiquitine29

        Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d avoir été infectées sans les ouvrir

        # Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisi "éxécuter en tant qu'administrateur" .

        # choisi l'option 2 ( Suppression )

        # Ton bureau disparaitra et le pc redémarrera .

        # Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

        # Ensuite,poste le rapport UsbFix.txt qui apparaitra avec le bureau .

        # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

        ensuite

        Télécharge SmitFraudfix de S!Ri, balltrap34 et moe31
        http://siri.urz.free.fr/Fix/SmitfraudFix.zip -
        en cas de problème avec le premier lien,
        mirroir: http://72.232.135.12/siri/SmitfraudFix.php

        voila à quoi cela ressemble : http://siri.urz.free.fr/Fix/SmitfraudFix.php
        une aide en vidéo (merci à balltrap34)
        http://pagesperso-orange.fr/rginformatique/section%20virus/smitfraudfix.htm

        Désactive les logiciels de protections(antivirus et antispyware)
        -- Fais un clic droit puis Extraire tout sur le fichier SmitfraudFix.zip, cela va tout décompresser dans un nouveau dossier SmitFraudfix
        -- Ouvre le dossier SmitfraudFix double-clique sur SmitfraudFix.cmd (le .cmd peut ne pas être présent)
        -- Choisis l'option 1 et appuie sur Entrée
        -- Réponds o (Oui) aux deux questions suivantes si elles sont posées
        -- Un rapport sera généré; sauvegarde le dans un dossier.
        -- Copie/colle le contenu du rapport ici
        0
        1. Ok fait.
          Sauf que je n'ai pas réussit à enlever AVG8 et windows defender (même s'ils n'apparaissent pas dans la barre des programmes en cours, le centre de sécurité me dit qu'ils sont activés).

          Rapport 1 :USBFix

          ############################## [ UsbFix V3.033 ]

          # User : maison (Administrateurs) # PC-DE-MAISON
          # Update on 15/06/09 by C_XX
          # Start at: 12:49:15 | 24/06/2009
          # Website : http://pagesperso-orange.fr/NosTools/usbfix.html

          # Intel(R) Core(TM)2 Duo CPU T5750 @ 2.00GHz
          # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
          # Internet Explorer 8.0.6001.18783
          # Windows Firewall Status : Enabled
          # AV : AVG Anti-Virus 8.0 [ Enabled | Updated ]

          # C:\ # Disque fixe local # 74,45 Go (32,89 Go free) [Vista] # NTFS
          # D:\ # Disque fixe local # 39,06 Go (2,54 Go free) [disque C] # NTFS
          # E:\ # Disque fixe local # 73,13 Go (6,43 Go free) [Disque 2 PC] # NTFS
          # F:\ # Disque CD-ROM
          # G:\ # Disque fixe local # 298,09 Go (108,48 Go free) [My Passport] # NTFS
          # H:\ # Disque fixe local # 193,82 Go (62,97 Go free) [DISQUE 193 GO] # NTFS

          ############################## [ Processus actifs ]

          C:\Windows\System32\smss.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\services.exe
          C:\Windows\system32\lsass.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\winlogon.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\LogonUI.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\SLsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\userinit.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Windows\System32\spoolsv.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\runonce.exe
          C:\Windows\system32\conime.exe
          C:\Windows\system32\agrsmsvc.exe
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
          C:\Windows\system32\taskeng.exe
          C:\PROGRA~1\AVG\AVG8\avgam.exe
          C:\Windows\system32\svchost.exe
          C:\PROGRA~1\AVG\AVG8\avgrsx.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
          C:\PROGRA~1\AVG\AVG8\avgnsx.exe
          C:\Windows\system32\TODDSrv.exe
          c:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
          c:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
          C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\SearchIndexer.exe
          C:\PROGRA~1\AVG\AVG8\avgemc.exe
          C:\Program Files\AVG\AVG8\avgcsrvx.exe
          C:\Windows\system32\wbem\wmiprvse.exe

          ################## [ Fichiers # Dossiers infectieux ]

          Supprimé ! D:\recycler\S-1-5-21-606747145-162531612-682003330-1003\Dc128\WDIRNOP.COM
          Supprimé ! D:\recycler\S-1-5-21-606747145-162531612-682003330-1003\Dc128\VBE\WDIRNOP.COM

          ################## [ Registre # Clés Run infectieuses ]

          ################## [ Registre # Mountpoints2 ]

          Supprimé ! HKCU\...\Explorer\MountPoints2\{2c2273ab-9395-11dd-9803-001e3354c3a3}\Shell\AutoRun\Command
          Supprimé ! HKCU\...\Explorer\MountPoints2\{56191b46-b3bc-11dd-8087-001e3354c3a3}\Shell\AutoRun\Command
          Supprimé ! HKCU\...\Explorer\MountPoints2\{7176b545-df35-11dd-bb9e-001e3354c3a3}\Shell\AutoRun\Command

          ################## [ Listing des fichiers présent ]

          [18/09/2006 23:43|--a------|24] - C:\autoexec.bat
          [21/01/2008 04:24|-rahs----|333203] - C:\bootmgr
          [25/02/2008 11:45|-ra-s----|8192] - C:\BOOTSECT.BAK
          [18/09/2006 23:43|--a------|10] - C:\config.sys
          [11/09/2008 18:19|--ah-----|5428] - C:\ffastun.ffa
          [11/09/2008 18:19|--ah-----|450560] - C:\ffastun.ffl
          [11/09/2008 18:19|--ah-----|217088] - C:\ffastun.ffo
          [11/09/2008 18:19|--ah-----|4169728] - C:\ffastun0.ffx
          [?|?|?] - C:\hiberfil.sys
          [09/09/2008 17:35|-rahs----|0] - C:\IO.SYS
          [09/09/2008 17:35|-rahs----|0] - C:\MSDOS.SYS
          [29/02/2004 17:44|--a------|52576] - C:\orange.bmp
          [?|?|?] - C:\pagefile.sys
          [25/02/2008 12:27|--a------|651] - C:\RHDSetup.log
          [26/02/2008 11:10|--ah-----|123] - C:\SWSTAMP.TXT
          [24/06/2009 12:50|--a------|4223] - C:\UsbFix.txt
          [26/02/2008 10:18|--a----t-|23120] - C:\_wdsuef.dmp
          [17/09/2008 12:36|--a------|45] - D:\atel.txt
          [23/12/2006 16:59|--a------|0] - D:\AUTOEXEC.BAT
          [23/12/2006 16:54|---hs----|212] - D:\boot.ini
          [02/10/2001 18:15|-rahs----|4952] - D:\Bootfont.bin
          [23/12/2006 16:59|--a------|0] - D:\CONFIG.SYS
          [31/01/2007 23:41|--ah-----|5535] - D:\ffastun.ffa
          [31/01/2007 23:41|--ah-----|2523136] - D:\ffastun.ffl
          [31/01/2007 23:41|--ah-----|1282048] - D:\ffastun.ffo
          [31/01/2007 23:41|--ah-----|2162688] - D:\ffastun0.ffx
          [23/12/2006 16:59|-rahs----|0] - D:\IO.SYS
          [23/12/2006 16:59|-rahs----|0] - D:\MSDOS.SYS
          [03/08/2004 22:38|-rahs----|47564] - D:\NTDETECT.COM
          [03/08/2004 22:59|-rahs----|251712] - D:\ntldr
          [26/11/2008 21:15|--ahs----|805306368] - D:\pagefile.sys
          [11/09/2008 18:18|--ah-----|4379] - E:\ffastun.ffa
          [11/09/2008 18:18|--ah-----|40960] - E:\ffastun.ffl
          [11/09/2008 18:18|--ah-----|32768] - E:\ffastun.ffo
          [11/09/2008 18:18|--ah-----|45056] - E:\ffastun0.ffx
          [28/03/2008 07:36|--a------|11] - E:\R08511FR.tag
          [28/04/2009 14:11|--a------|4523520] - G:\WDSync_v7_1_020.exe

          ################## [ Vaccination ]

          # C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
          # D:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
          # E:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
          # G:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
          # H:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.

          ################## [ ! Fin du rapport # UsbFix V3.033 ! ]

          Rapport 2 : Smitfraudfix
          SmitFraudFix v2.422

          Scan done at 13:06:05,14, 24/06/2009
          Run from C:\Users\maison\Desktop\smitfraudfix\SmitfraudFix
          OS: Microsoft Windows [version 6.0.6001] - Windows_NT
          The filesystem type is NTFS
          Fix run in normal mode

          »»»»»»»»»»»»»»»»»»»»»»»» Process

          C:\Windows\system32\csrss.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\services.exe
          C:\Windows\system32\lsass.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\winlogon.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\SLsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\System32\spoolsv.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\conime.exe
          C:\Windows\system32\agrsmsvc.exe
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
          C:\Windows\system32\taskeng.exe
          C:\PROGRA~1\AVG\AVG8\avgam.exe
          C:\Windows\system32\svchost.exe
          C:\PROGRA~1\AVG\AVG8\avgrsx.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
          C:\PROGRA~1\AVG\AVG8\avgnsx.exe
          C:\Windows\system32\TODDSrv.exe
          c:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
          c:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
          C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\SearchIndexer.exe
          C:\PROGRA~1\AVG\AVG8\avgemc.exe
          C:\Program Files\AVG\AVG8\avgcsrvx.exe
          C:\Windows\explorer.exe
          C:\Windows\system32\notepad.exe
          C:\Windows\system32\wuauclt.exe
          C:\Program Files\Windows Mail\WinMail.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\cmd.exe
          C:\Windows\system32\SearchProtocolHost.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Windows\system32\wbem\wmiprvse.exe

          »»»»»»»»»»»»»»»»»»»»»»»» hosts

          »»»»»»»»»»»»»»»»»»»»»»»» C:\

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

          C:\Windows\Tasks\At?.job FOUND !
          C:\Windows\Tasks\At??.job FOUND !

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\maison

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\maison\AppData\Local\Temp

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\maison\Application Data

          »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\maison\FAVORI~1

          »»»»»»»»»»»»»»»»»»»»»»»» Desktop

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

          »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

          »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

          »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
          !!!Attention, following keys are not inevitably infected!!!

          o4Patch
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
          !!!Attention, following keys are not inevitably infected!!!

          IEDFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
          !!!Attention, following keys are not inevitably infected!!!

          Agent.OMZ.Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» VACFix
          !!!Attention, following keys are not inevitably infected!!!

          VACFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
          !!!Attention, following keys are not inevitably infected!!!

          404Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
          !!!Attention, following keys are not inevitably infected!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
          !!!Attention, following keys are not inevitably infected!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLs"="avgrsstx.dll"
          "LoadAppInit_DLLs"=dword:00000001

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
          !!!Attention, following keys are not inevitably infected!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "Userinit"="C:\\Windows\\system32\\userinit.exe,"

          »»»»»»»»»»»»»»»»»»»»»»»» RK

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

          »»»»»»»»»»»»»»»»»»»»»»»» DNS

          Description: Intel(R) PRO/Wireless 3945ABG Network Connection
          DNS Server Search Order: 212.27.40.240
          DNS Server Search Order: 212.27.40.241

          HKLM\SYSTEM\CCS\Services\Tcpip\..\{A81F8CA1-7440-4468-9002-D8701C7F65C1}: DhcpNameServer=212.27.40.240 212.27.40.241
          HKLM\SYSTEM\CCS\Services\Tcpip\..\{DF105378-B675-40A8-822F-390003D3DE3B}: DhcpNameServer=212.27.40.240 212.27.40.241
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{A81F8CA1-7440-4468-9002-D8701C7F65C1}: DhcpNameServer=212.27.40.240 212.27.40.241
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{DF105378-B675-40A8-822F-390003D3DE3B}: DhcpNameServer=212.27.40.240 212.27.40.241
          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241

          »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

          »»»»»»»»»»»»»»»»»»»»»»»» End
          0
          1. Contributeur sécurité
            Redémarre l'ordinateur en mode sans échec .
            Comment aller en Mode sans échec
            1) Redémarre ton ordi
            2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
            3) Tu verras un écran avec options de démarrage apparaître
            4) Choisis la première option : Sans Échec, et valide avec "Entrée"
            5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
            ( ps : n'oublies pas , en mode sans échec , pas de connexion ! Donc copie ou imprime bien les infos ci-dessous ...)

            *Double click sur SmitfraudFix.exe

            * Sélectionnes 2 et presses "Entrée" dans le menu pour supprimer les fichiers responsables de l'infection.

            * A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et presse Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection.

            ( Le correctif déterminera si le fichier wininet.dll est infecté.)

            * A la question: "Corriger le fichier infecté ?" répondre O (oui) et presser Entrée
            pour remplacer le fichier corrompu.

            * Un redémarrage sera peut être nécessaire pour terminer la procédure de nettoyage ( sinon fais le manuellement )

            Le rapport se trouve à la racine de C\:
            (dans le fichier "rapport.txt")
            0
            1. Ok fait.

              Je n'ai pas eu de question concernant
              le fichier wininet.dll infecté
              Pas fait:
              * A la question: "Corriger le fichier infecté ?" répondre O (oui) et presser Entrée
              pour remplacer le fichier corrompu.

              Pour info complémentaire:j'ai une mise à jour complémentaire pour la sécurité de Vista N°KB959426 depuis le 14/4/09 que je n'arrive pas à installer.

              Ci dessous le rapport.SmitFraudFix v2.422

              Scan done at 13:51:30,21, 24/06/2009
              Run from C:\Users\maison\Desktop\smitfraudfix\SmitfraudFix
              OS: Microsoft Windows [version 6.0.6001] - Windows_NT
              The filesystem type is NTFS
              Fix run in safe mode

              »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
              !!!Attention, following keys are not inevitably infected!!!

              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll

              »»»»»»»»»»»»»»»»»»»»»»»» Killing process

              »»»»»»»»»»»»»»»»»»»»»»»» hosts

              127.0.0.1 localhost
              ::1 localhost

              »»»»»»»»»»»»»»»»»»»»»»»» VACFix

              VACFix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

              S!Ri's WS2Fix: LSP not Found.

              »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

              GenericRenosFix by S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

              C:\Windows\Tasks\At?.job Deleted

              »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

              IEDFix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

              Agent.OMZ.Fix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

              404Fix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» RK

              »»»»»»»»»»»»»»»»»»»»»»»» DNS

              HKLM\SYSTEM\CCS\Services\Tcpip\..\{A81F8CA1-7440-4468-9002-D8701C7F65C1}: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CCS\Services\Tcpip\..\{DF105378-B675-40A8-822F-390003D3DE3B}: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CS1\Services\Tcpip\..\{A81F8CA1-7440-4468-9002-D8701C7F65C1}: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CS1\Services\Tcpip\..\{DF105378-B675-40A8-822F-390003D3DE3B}: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CS2\Services\Tcpip\..\{A81F8CA1-7440-4468-9002-D8701C7F65C1}: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CS2\Services\Tcpip\..\{DF105378-B675-40A8-822F-390003D3DE3B}: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241

              »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
              !!!Attention, following keys are not inevitably infected!!!

              »»»»»»»»»»»»»»»»»»»»»»»» RK.2

              »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

              Registry Cleaning done.

              »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
              !!!Attention, following keys are not inevitably infected!!!

              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll

              »»»»»»»»»»»»»»»»»»»»»»»» End
              0
              1. Contributeur sécurité
                pour tes updates on va voir après car souvent ce sont les malwares qui empêche leurs bon fonctionnement

                regarde si tu peux supprimer manuellement ce fichier
                C:\x
                0
                1. Désolé pour le retard

                  Ok j'ai réussi à effacer le fichier X
                  0
                  1. Contributeur sécurité
                    c'est bon,

                    fais un scan avec avg
                    si il détecte qq chose tu postes le rapport stp
                    0
                    1. Ok AVG ne détecte plus rien.

                      Malheureusement j'ai toujours une mise à jour complémentaire importante pour la sécurité de Vista N°KB959426 depuis le 14/4/09 que je n'arrive pas à installer. Il me dit qu'il s'agit d'une erreur code 80073712.

                      Je te remercie pour tous ces conseils.
                      0
                      1. Contributeur sécurité
                        bizarre cette histoire d'update qui va pas

                        Télécharge Zeb-Restore(par l'équipe de Zebulon.fr)

                        http://telechargement.zebulon.fr/zeb-restore.html

                        enregistre ce fichier sur le bureau.

                        - Clic droit Zeb-Restore.zip ==> Extraire tout choisis comme lieu d'enregistrement le bureau.
                        - Ouvre le dossier ZR_1.0.0.37 ==> double clic sur Zeb-Restore.exe
                        - Coche la case devant : Windows update
                        - Ne coche aucune autre case
                        - Clique sur Restaurer
                        - Redémarre ton PC+++

                        dis moi quoi?
                        0
                        1. Salut chimay8,

                          Sympa ce pti logiciel.

                          Ca te derange si je te prends ton canned ?
                          0
                        2. Contributeur sécurité
                          @raphy00non,non,
                          vas-y fonce
                          0
                        3. @chimay8(bruit de moteur) :p
                          0
                      2. Bonjour,
                        Super Zeb-Restore m'a permis de faire la mise à jour.

                        Merci et Encore MERCI.

                        Félicitation pour tes conseils et ta pédagogie.

                        Je suis intrigué.
                        Es tu un bénévole mordu d'informatique qui vole au secour des personnes perdues comme moi? Ou es tu un professionnel de la hotline?

                        @+ merci.
                        0
                        1. Contributeur sécurité
                          un bénévole mordu d'informatique qui vole au secour des personnes perdues comme moi?

                          ta trouvé
                          ;)

                          mais je suis pas tout seul!!

                          on termine

                          Télécharge OTCleanIT de Old Timer.
                          http://www.geekstogo.com/forum/files/file/403-otc-oldtimers-clean-it/
                          Double-clique sur OTCleanIt.exe.
                          Cliquez sur le bouton "CleanUp!" .
                          Sélectionnez Oui lorsque la demande " processus de nettoyage?" s'affiche.
                          Si tu es invité à redémarrer le PC au cours de l'assainissement, sélectionne Oui.
                          L'outil va se supprimer lui-même une fois la fin de l'opération.
                          Sinon supprime le manuellement.

                          ensuite

                          Télécharges : - CCleaner (n'installe pas la barre d'outil Yahoo)
                          https://www.pcastuces.com/logitheque/ccleaner.htm
                          Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corrigé ton registre .Lors de l'installation, avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 première.
                          Une fois le prg instalé et lancé, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures"( Par la suite, laisse-le avec ses réglages par défaut. C'est tout ).

                          Un tuto ( aide ):
                          http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

                          ---> Utilisation:
                          ! déconnectes toi et fermes toutes applications en cours !
                          * vas dans "nettoyeur" : fait analyse puis nettoyage
                          * vas dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .

                          ( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )

                          ***très important***

                          Suppression des points de restauration :
                          sous vista
                          https://www.01net.com/actualites/
                          http://www.commentcamarche.net/faq/sujet 13214 desactiver reactiver la restauration systeme de vista

                          Ne pas oublier de créer un nouveau point de restauration en procédant comme indiqué sur le lien ci-dessous

                          https://www.vulgarisation-informatique.com/creer-point-restauration.php

                          si tu n as pas d autres soucis change le statut du sujet en resolu stp
                          te tracasse pas si tu peux pas le faire

                          je ne peux que vous inciter à lire les liens ci-dessous
                          0