Besoin d'aide !

salut a tous

mon fond d'ecran vient detre remplacé par une jolie page bleue me disant qu'iE a eu une erreur fatale du a un trojan
impossible de la degager ( l'option dans le panneau de config a meme disparu

j'ai lancé spybot et ad aware mais aucun changement

merci de votre aide car ca m'inquiete

3 réponses

  1. Contributeur sécurité
    salut
    fait ceci
    HijackThis (ici) http://www.florensac-chasse-trap.com/
    section virus

    telecharge le et met le dans son propre dossier ex/c :hj

    clik sur do a systeme scan et save a logfile
    et copier coller le rapport
    0
    1. Scan saved at 21:55:17, on 29/05/2005
      Platform: Windows XP SP1 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Sygate\SPF\smc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\slserv.exe
      C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
      C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
      C:\WINDOWS\System32\wbem\wmiprvse.exe
      C:\WINDOWS\System32\msole32.exe
      C:\WINDOWS\System32\shnlog.exe
      C:\WINDOWS\popuper.exe
      C:\ATI-CPanel\atiptaxx.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
      C:\WINDOWS\System32\intmon.exe
      C:\WINDOWS\System32\intmonp.exe
      C:\WINDOWS\explorer.exe
      C:\Program Files\MSN Messenger\msnmsgr.exe
      C:\Program Files\BearShare\BearShare.exe
      C:\Program Files\BearShare\BearShare.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\hijakthis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.updatesearches.com/search.php?qq=%1
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.updatesearches.com/bar.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.updatesearches.com/search.php?qq=%1
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qfind.net/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.qfind.net/search.php?qq=%s
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.qfind.net/search.php?qq=%s
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qfind.net/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.updatesearches.com/search.php?qq=%1
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.updatesearches.com/search.php?qq=%1
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.qfind.net/search.php?qq=%s
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.qfind.net/search.php?qq=%s
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.updatesearches.com/search.php?qq=%1
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.updatesearches.com/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.qfind.net/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - Default URLSearchHook is missing
      O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINDOWS\System32\hpC996.tmp
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
      O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
      O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [MSN Messenger] C:\WINDOWS\System32\msmsgs.exe
      O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [WindowsFZ] C:\WINDOWS\System32\LogFiles\A5281300.so
      O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
      O4 - HKLM\..\RunOnce: [AAW] "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" "+b1"
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
      O9 - Extra button: Microsoft AntiSpyware helper - {2A6DBB34-41B3-4009-9E2E-7B9F09894029} - (no file) (HKCU)
      O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {2A6DBB34-41B3-4009-9E2E-7B9F09894029} - (no file) (HKCU)
      O9 - Extra button: Microsoft AntiSpyware helper - {90093462-A0D3-40AF-9018-C3A3998FAE6B} - (no file) (HKCU)
      O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {90093462-A0D3-40AF-9018-C3A3998FAE6B} - (no file) (HKCU)
      O9 - Extra button: Microsoft AntiSpyware helper - {97CBAC77-C9ED-4F81-B48A-8D35D11A00FE} - (no file) (HKCU)
      O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {97CBAC77-C9ED-4F81-B48A-8D35D11A00FE} - (no file) (HKCU)
      O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
      O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
      O16 - DPF: {2A6205D0-FC25-53AF-0D74-17AF24DA8B10} - http://216.118.71.185/1/rdgFR1828.exe
      O16 - DPF: {4FDD128C-9607-2400-820D-770D64AB8BC0} - http://216.118.71.185/1/rdgFR1828.exe
      O16 - DPF: {67652D8F-B874-5506-3329-626D25BC517B} - http://216.118.71.185/1/rdgFR1828.exe
      O16 - DPF: {755D3F33-3D33-26B0-05B9-518D0E6532E8} - http://216.118.71.185/1/rdgFR1828.exe
      O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://player.virtools.com/downloads/player/Install2.5/Installer.exe
      O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
      O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
      O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
      O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
      0
      1. Contributeur sécurité
        salut
        imprime ceci pour ne rien oublier et tous faire
        tous faire dans l ordre imperativement
        -------------------------
        tous da bord telecharge ces programmes si tu ne les a pas et met les a jour mais ne les utilise pas encore
        adaware (1)
        spyboot (2)
        (ici) http://www.florensac-chasse-trap.com/ section virus
        et aussi ceci
        CleanUp312.exe (3)

        et ceci
        http://www.bleepingcomputer.com/files/reg/smitfraud.reg

        ----------------
        desactive ta restauration systeme
        pour ça tu fais clic droit sur poste de travail
        propriété tu clique sur onglet restauration système
        tu coche la case désactiver la restauration et applique
        ------------

        demarre en mode sans echec
        mode sans echec pour cela tu tapote la touche f8
        des le debut de l allumage du pc sans t arreter
        une fenetre vas souvrir tute deplace avec les fleches du clavier sur demarreren mode sans echec
        une fois sur le bureau il ni auras pas toutes les couleurs et autres c est normal.si f8 ne marche pas utilise la touche f5
        -------------------------

        assure toi de ceci
        Affiche tous les fichiers et dossiers :
        cliquer sur démarrer/panneau de configuration/option des dossiers/affichage
        Cocher afficher les dossiers cacher

        Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

        Décocher masquer les extensions dont le type est connu
        Puis fais «Ok» pour valider les changements.

        Et appliquer
        ----------------------
        vide tes fichiers temps et tempory internet file sur tous les utilisateur
        utilise ceci pour le faire
        http://pageperso.aol.fr/Balltrap34/CleanUp312.exe

        --------------------
        relance hijack coche ces lignes et ensuite clik sur fix
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.updatesearches.com/search.php?qq=%1
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.updatesearches.com/bar.html
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.updatesearches.com/search.php?qq=%1
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qfind.net/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.qfind.net/search.php?qq=%s
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.qfind.net/search.php?qq=%s
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qfind.net/
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.updatesearches.com/search.php?qq=%1
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.updatesearches.com/search.php?qq=%1
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.qfind.net/search.php?qq=%s
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.qfind.net/search.php?qq=%s
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.updatesearches.com/search.php?qq=%1
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.updatesearches.com/
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.qfind.net/
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - Default URLSearchHook is missing
        O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINDOWS\System32\hpC996.tmp
        O4 - HKLM\..\Run: [WindowsFZ] C:\WINDOWS\System32\LogFiles\A5281300.so (ceci ne le fix pas si tu connait)
        O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
        O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
        O9 - Extra button: Microsoft AntiSpyware helper - {2A6DBB34-41B3-4009-9E2E-7B9F09894029} - (no file) (HKCU)
        O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {2A6DBB34-41B3-4009-9E2E-7B9F09894029} - (no file) (HKCU)
        O9 - Extra button: Microsoft AntiSpyware helper - {90093462-A0D3-40AF-9018-C3A3998FAE6B} - (no file) (HKCU)
        O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {90093462-A0D3-40AF-9018-C3A3998FAE6B} - (no file) (HKCU)
        O9 - Extra button: Microsoft AntiSpyware helper - {97CBAC77-C9ED-4F81-B48A-8D35D11A00FE} - (no file) (HKCU)
        O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {97CBAC77-C9ED-4F81-B48A-8D35D11A00FE} - (no file) (HKCU)
        O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
        O16 - DPF: {2A6205D0-FC25-53AF-0D74-17AF24DA8B10} - http://216.118.71.185/1/rdgFR1828.exe
        O16 - DPF: {4FDD128C-9607-2400-820D-770D64AB8BC0} - http://216.118.71.185/1/rdgFR1828.exe
        O16 - DPF: {67652D8F-B874-5506-3329-626D25BC517B} - http://216.118.71.185/1/rdgFR1828.exe
        O16 - DPF: {755D3F33-3D33-26B0-05B9-518D0E6532E8} - http://216.118.71.185/1/rdgFR1828.exe
        O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://player.virtools.com/downloads/player/Install2.5/Installer.exe

        ----------------------
        recherche et suppr ceci
        attention seulement les fichiers
        C:\WINDOWS\System32\hpC996.tmp
        C:\WINDOWS\System32\spoolsrv32.exe

        ---------------
        double clik sur le dernier prog que tu as telecharger
        et accepte
        --------------------

        passe adaware et vire tous se qu il trouve
        ----------
        passe spy boot et vire tous se qu il trouvent
        -------------

        tu vide ta poubelle et tu redemarre en mode normal et refait un hijack

        et precise ou en sont tes soucis

        --
        0