Impossible ouverture de Mozilla ou d'Iexploer

Résolu
Bonjour,
A l'ouverture de firefox ou d'internet explorer apparait la page comme s'il n'y avait pas de connexion. Avec un autre PC tout fonctionne normalement la connexion est normale.
Certainement une infection, mais laquelle ? Comment procéder pour résoudre le problème, j'ai déjà passé MalwarebytesAntimalware qui m'a détecté et supprimé ou mis en quarantaine plusieurs infections, le problème n'est pas résolu je n'arrive toujours pas avoir accès à internet.
Par avance merci de votre aide.
Configuration: Windows XP
Firefox 3.5.6

20 réponses

  1. Contributeur sécurité
    Salut savoyantoine

    On va vérifier cela, télécharge RSIT (de random/random) sur le bureau ici :
    http://images.malwareremoval.com/random/RSIT.exe

    - Double clique sur RSIT.exe qui est sur le bureau
    - Clique sur Continue dans la fenêtre
    - RSIT téléchargera HijackThis si il n’est pas présent où détecté, alors il faudra accepter la licence
    - Poste le contenue des deux rapports, log.txt et info.txt(réduit dans la barre des tâches) à la fin de l’analyse

    Les rapports sont dans le dossier ici C:\rsit

    @++ :)
    0
    1. Salut dédétraqué,
      Je n'ai pas donné toutes les précisions nécessaires lors de mon premier post. Il s'agit d'un PC portable ASUS, en l'occurrence celui de mon fils, OS: Vista.
      J'utilise mon PC pour télécharger les utilitaires et ensuite les installer sur l'autre PC, c'est ce que j'avais fait avec Malwarebyte.
      A++
      0
      1. Contributeur sécurité
        Salut savoyantoine

        Effectivement faudras aussi télécharger et installer HJT avant le scan avec RSIT :
        http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe

        @++ :)
        0
        1. Voici le rapport de rsit,

          Logfile of random's system information tool 1.06 (written by random/random)
          Run by client at 2009-12-27 19:07:50
          Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
          System drive C: has 57 GB (47%) free of 119 GB
          Total RAM: 3036 MB (62% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 19:09:01, on 27/12/2009
          Platform: Windows Vista SP2 (WinNT 6.00.1906)
          MSIE: Internet Explorer v8.00 (8.00.6001.18865)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\HP\HP Software Update\hpwuschd2.exe
          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
          C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Windows\system32\wbem\unsecapp.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
          C:\Users\client\RSIT.exe
          C:\Program Files\trend micro\client.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.sfr.fr/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: (no name) - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - (no file)
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O1 - Hosts: ::1 localhost
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Aide à la navigation SFR - {0F6E720A-1A6B-40E1-A294-1D4D19F156C8} - C:\Program Files\SFR\Kit\SFRNavErrorHelper.dll
          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O3 - Toolbar: (no name) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - (no file)
          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [Skytel] Skytel.exe
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
          O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
          O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
          O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - (no file)
          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
          O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
          O13 - Gopher Prefix:
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
          O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
          0
          1. Contributeur sécurité
            Salut savoyantoine

            Poste moi le rapport de MalwareByte's, il peut être retrouvé sous l'onglet Rapports/logs du logiciel.

            Désactive le contrôle des comptes utilisateurs UAC (tu le réactiveras après le scan):

            - Va dans démarrer puis panneau de configuration
            - Double Clique sur l'icône "Comptes d'utilisateurs"
            - Clique ensuite sur désactiver et valide.

            [*]Télécharge AD-Remover (de Cyrildu17 / C_XX) sur ton Bureau.
            http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe

            Déconnecte-toi et ferme toutes applications en cours

            [*]Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program files).
            [*]Faire un clique droit sur l'icône AD-Remover située sur ton Bureau et choisir exécuter en tant qu'administrateur.
            [*]Au menu principal, choisis l'option L.
            [*]Poste le rapport qui apparaît à la fin.

            (Le rapport est sauvegardé aussi sous C:\Ad-report(date).log)

            (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

            Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus comme une infection, ne pas en tenir compte, il s'agit d'un faux positif, continue la procédure

            Aide : https://kerio.probb.fr/t3786-tuto-ad-remover

            @++ :)
            0
            1. Salut dédétraqué,
              Nous avons abandonné la discussion hier soir, il a fallu que nous nous absentions, mais nous reprendrons surement en fin d'après-midi ce lundi, en attendant nous te remercions.
              0
              1. Contributeur sécurité
                Salut savoyantoine

                Pas de souci, a plus tard.

                @++ :)
                0
                1. Salut dédétraqué et merci de ta patience,

                  Je te poste le log Malware ci desous:

                  Malwarebytes' Anti-Malware 1.42
                  Version de la base de données: 3435
                  Windows 6.0.6002 Service Pack 2
                  Internet Explorer 8.0.6001.18865

                  26/12/2009 20:40:33
                  mbam-log-2009-12-26 (20-40-33).txt

                  Type de recherche: Examen complet (C:\|D:\|)
                  Eléments examinés: 247652
                  Temps écoulé: 1 hour(s), 9 minute(s), 52 second(s)

                  Processus mémoire infecté(s): 1
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 14
                  Valeur(s) du Registre infectée(s): 2
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 7
                  Fichier(s) infecté(s): 7

                  Processus mémoire infecté(s):
                  C:\Users\client\AppData\Roaming\EoRezo\SoftwareUpdate\SoftwareUpdateHP.exe (Rogue.Eorezo) -> Unloaded process successfully.

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  HKEY_CLASSES_ROOT\CLSID\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\TypeLib\{b6acb3f1-6a83-432c-b854-3e1056f87f4e} (Rogue.Eorezo) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{819db72d-1c28-4387-9778-e2ff3dc86f74} (Rogue.Eorezo) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{c7b76b90-3455-4ae6-a752-eac4d19689e5} (Rogue.Eorezo) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c7b76b90-3455-4ae6-a752-eac4d19689e5} (Rogue.Eorezo) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{c7b76b90-3455-4ae6-a752-eac4d19689e5} (Rogue.Eorezo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c7b76b90-3455-4ae6-a752-eac4d19689e5} (Rogue.Eorezo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo (Rogue.Eorezo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.

                  Valeur(s) du Registre infectée(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\softwarehelper (Rogue.Eorezo) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\2.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\SrchAstt (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\SrchAstt\2.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

                  Fichier(s) infecté(s):
                  C:\Users\client\AppData\Roaming\EoRezo\SoftwareUpdate\SoftwareUpdateHP.exe (Rogue.Eorezo) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\EoRezo\EoEngine.exe (Rogue.Eorezo) -> Quarantined and deleted successfully.
                  C:\Program Files\EoRezo\EoAdv\EoAdv.dll (Rogue.Eorezo) -> Quarantined and deleted successfully.
                  C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (Rogue.Eorezo) -> Quarantined and deleted successfully.
                  C:\Users\client\AppData\Roaming\EoRezo\SoftwareUpdate\SoftwareUpdate.exe (Rogue.Eorezo) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  0
                  1. Contributeur sécurité
                    Salut savoyantoine

                    Merci pour le rapport de MBAM, as-tu le rapport du scan que j'ai demandé?

                    @++ :)
                    0
                    1. Re bonjour dédétraqué,
                      Je te poste le log Adr

                      .
                      ======= RAPPORT D'AD-REMOVER 1.1.4.6_F | UNIQUEMENT XP/VISTA/7 =======
                      .
                      Mit à jour par C_XX le 26.12.2009 à 20:47
                      Contact: AdRemover.contact@gmail.com
                      Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                      .
                      Lancé à: 16:38:03, 28/12/2009 | Mode Normal | Option: CLEAN
                      Exécuté de: C:\Program Files\Ad-Remover\
                      Système d'exploitation: Microsoft® Windows Vista™ Home Premium Service Pack 2 v6.0.6002
                      Nom du PC: PC-DE-CLIENT | Utilisateur actuel: client

                      Bonnes fêtes de fin d'année à vous tous :)
                      .
                      ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                      .

                      C:\Users\client\AppData\Roaming\Mozilla\FireFox\Profiles\oou3a66u.default\searchplugins\ask.xml
                      C:\Program Files\Mozilla FireFox\Components\AskSearch.js
                      C:\Program Files\EoRezo
                      C:\Users\client\AppData\Roaming\EoRezo

                      (!) -- Fichiers temporaires supprimés.

                      .
                      HKCU\software\appdatalow\software\Fun Web Products
                      HKCU\software\appdatalow\software\MyWebSearch
                      HKCU\software\EoRezo
                      HKCU\software\microsoft\internet explorer\searchscopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
                      HKLM\Software\Classes\AppID\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}
                      HKLM\software\classes\appid\EoRezoBHO.DLL
                      HKLM\software\classes\EoRezoBHO.EoBHO
                      HKLM\software\classes\EoRezoBHO.EoBHO.1
                      HKLM\software\microsoft\shared tools\msconfig\startupreg\EoEngine
                      HKU\.default\software\EoRezo
                      .
                      ============== Scan additionnel ==============
                      .
                      .
                      * Mozilla FireFox Version 3.0.16 [fr] *
                      .
                      Nom du profil: oou3a66u.default (client)
                      .
                      (client, prefs.js) Browser.download.dir, C:\Users\client\Downloads
                      (client, prefs.js) Browser.download.lastDir, C:\Users\client\Desktop\nicolas\nico
                      (client, prefs.js) Browser.search.defaultenginename, Ask
                      (client, prefs.js) Browser.search.selectedEngine, Google
                      (client, prefs.js) Browser.startup.homepage, hxxp://lo.st#home
                      (client, prefs.js) Extensions.enabledItems, {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.5.1.1,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.16
                      (client, prefs.js) Keyword.URL, hxxp://redirecterror.sfr.fr/?q=
                      .
                      (client, prefs.js) EFFACE - Browser.startup.homepage, hxxp://lo.st#home
                      (client, prefs.js) EFFACE - Extensions.snipit.chromeURL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q={searchTerms}&crm=1
                      .
                      (client, user.js) Keyword.URL, hxxp://redirecterror.sfr.fr/?q=
                      .
                      .
                      * Internet Explorer Version 8.0.6001.18865 *
                      .
                      [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                      .
                      Do404Search: 01000000
                      Local Page: C:\Windows\system32\blank.htm
                      Show_ToolBar: yes
                      Enable Browser Extensions: yes
                      Start Page: hxxp://fr.msn.com/
                      Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                      Search Bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                      Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                      .
                      [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                      .
                      Start Page: hxxp://fr.msn.com/
                      Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                      Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                      Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                      Delete_Temp_Files_On_Exit: yes
                      Local Page: C:\Windows\System32\blank.htm
                      Search bar: hxxp://search.msn.com/spbasic.htm
                      .
                      [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                      .
                      Tabs: res://ieframe.dll/tabswelcome.htm
                      .
                      ===================================
                      .
                      3485 Octet(s) - C:\Ad-Report-CLEAN[1].log
                      .
                      0 Fichier(s) - C:\Users\client\AppData\Local\Temp
                      1 Fichier(s) - C:\Windows\Temp
                      7 Fichier(s) - C:\Windows\Prefetch
                      .
                      20 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
                      58 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
                      .
                      Fin à: 16:53:31 | 28/12/2009 - CLEAN[1]
                      .
                      ============== E.O.F ==============
                      .
                      0
                      1. Contributeur sécurité
                        Salut savoyantoine

                        Supprime ce dossier C:\rsit

                        Refais un scan avec RSIT et poste le rapport log.txt seulement à la fin de l’analyse

                        Le rapport est dans le dossier ici C:\rsit

                        @++ :)
                        0
                        1. Bonsoir dédétraqué,

                          Comme tu me le demandais hier soir, je te joins ci-après le log du dernier scan de RSIT:

                          Logfile of random's system information tool 1.06 (written by random/random)
                          Run by client at 2009-12-29 20:38:07
                          Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
                          System drive C: has 55 GB (46%) free of 119 GB
                          Total RAM: 3036 MB (63% free)

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 20:38:24, on 29/12/2009
                          Platform: Windows Vista SP2 (WinNT 6.00.1906)
                          MSIE: Internet Explorer v8.00 (8.00.6001.18865)
                          Boot mode: Normal

                          Running processes:
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\Explorer.EXE
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\RtHDVCpl.exe
                          C:\Program Files\HP\HP Software Update\hpwuschd2.exe
                          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                          C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\Windows\System32\mobsync.exe
                          C:\Program Files\Windows Media Player\wmpnscfg.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          C:\Windows\system32\wbem\unsecapp.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
                          C:\Users\client\RSIT.exe
                          C:\Program Files\trend micro\client.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                          R3 - URLSearchHook: (no name) - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - (no file)
                          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O1 - Hosts: ::1 localhost
                          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O2 - BHO: Aide à la navigation SFR - {0F6E720A-1A6B-40E1-A294-1D4D19F156C8} - C:\Program Files\SFR\Kit\SFRNavErrorHelper.dll
                          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O3 - Toolbar: (no name) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - (no file)
                          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                          O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
                          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                          O4 - HKCU\..\Run: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
                          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                          O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
                          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
                          O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - (no file)
                          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                          O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                          O13 - Gopher Prefix:
                          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                          O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
                          O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                          O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                          0
                          1. Contributeur sécurité
                            Salut savoyantoine

                            Et maintenant cela dit quoi pour internet?

                            @++ :)
                            0
                            1. Salut dédétraqué,

                              Un essai de navigation sera effectué dans la journée et je te tiendrais informer de l'évolution du problème.

                              A+
                              0
                              1. Salut dédétraqué,
                                L'essai de navigation a été réalisé, malheureusement aucun changement est à noter, nous sommes toujours dans la panade. Toujours impossible d'obtenir une page web.
                                A+
                                0
                                1. Contributeur sécurité
                                  Salut savoyantoine

                                  On va creuser un peu plus, télécharge combofix.exe (de sUBs) sur le bureau :

                                  http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                                  http://www.geekstogo.com/forum/files/file/197-combofix-by-subs/

                                  Important Désactive ton Antivirus et antispyware avant le scan avec Combofix :
                                  https://forum.pcastuces.com/default.asp

                                  ==> Sauvegarde ton travail et ferme toutes les fenêtres actives, il peut y avoir un redémarrage du PC. Ne lance aucun programme tant que Combofix n’est pas fini. <==

                                  Double clique sur combofix.exe, clique sur OUI et valide par Entrée

                                  Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                                  NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                                  Combofix est détecté par certains antivirus comme une infection, ne pas en tenir compte, il s'agit d'un faux positif, continue la procédure

                                  @++ :)
                                  0
                                  1. salut dédétraqué,
                                    Je te présente mes meilleurs vœux pour cette nouvelle année, mon fils n' a pas eu la patience de poursuivre notre recherche il a préférer porter son ordi chez un pro.
                                    Je te tiendrais (ainsi que le forum) informé de ce qui l'empêchait d'ouvrir IE et FF et je marquerais comme résolu notre discussion lorsque toutes les infos me seront communiquées.
                                    En attendant je te remercie de ton aide précieuse.
                                    0
                                    1. Contributeur sécurité
                                      Salut savoyantoine

                                      Mes meilleurs vœux également pour toi et ta famille.

                                      Bon dommage, OK j'attends de tes nouvelles pour savoir la suite de ce PC.

                                      @++ :)
                                      0
                                      1. Salut dédétraqué,

                                        Désolé, mon fils n'a pas su me redire exactement quels étaient le ou les virus qui bloquaient l'ouverture de IE8 et de FF.
                                        Le pro lui a nettoyé tout ce qui trainait et son PC tourne normalement.
                                        En tout cas merci de ton aide.
                                        0
                                        1. Contributeur sécurité
                                          Salut savoyantoine

                                          OK merci pour l'info

                                          @++ :)
                                          0