Trojan Startpage + iau.exe et autres

Bonjour tout le monde,

Je me bat depuis hier contre ce virus qui visiblement a fait des petits ou n est pas venu seul.

J ai fait un scan avec Clamwin en mode sans echec qui m a certifié que le fichier se.dll (qui contient le virus) avait été purgé. Mais quand je reviens en mode normal, il est encore là !

Par ailleurs, j ai également le iau.exe qui n est pas seul et qui n arrete pas d ouvrir des fenetres genre "site de rencontres avec des russes".

De plus mon explorer ne marche plus, j'utilise firefox actuellement.

J ai utilisé adaware et spybot en mode sans echec mais les problemes persistent.

Voici le rapport de hijackthis, quelqu'un pourrait-il m'aider et me dire quelles applications virées, sachant que les iau.exe, issas.exe, mservice.exe (j en oublie) reviennent sans cesse.

Merci pour votre aide.

Logfile of HijackThis v1.99.1
Scan saved at 13:22:01, on 01/09/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
E:\av\AVWUPSRV.EXE
E:\kerio\Personal Firewall 4\kpf4ss.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
c:\fotowin\RTETPISv.exe
C:\WINDOWS\System32\svchost.exe
E:\kerio\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\WANADOO\CnxMon.exe
C:\PROGRA~1\WANADOO\TaskbarIcon.exe
C:\WINDOWS\tppaldr.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
E:\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\ClamWin\bin\ClamTray.exe
C:\WINDOWS\System32\ctfmon.exe
E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\WINDOWS\System32\devldr32.exe
E:\kerio\Personal Firewall 4\kpf4gui.exe
C:\PROGRA~1\WANADOO\EspaceWanadoo.exe
C:\PROGRA~1\WANADOO\ComComp.exe
C:\PROGRA~1\WANADOO\Watch.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
E:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ALEXAL~1\LOCALS~1\Temp\se.dll/space.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ALEXAL~1\LOCALS~1\Temp\se.dll/space.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://127.0.0.1:80
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\acrobat\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1EB44D95-6A8B-43CD-815E-65D68540FCCB} - C:\WINDOWS\System32\kcol.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\downloaded program files\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\downloaded program files\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Intense Registry Service] IntEdReg.exe /CHECK
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\WANADOO\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\WANADOO\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\WANADOO\TaskbarIcon.exe
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] E:\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\ALEXAL~1\LOCALS~1\Temp\se.dll,DllInstall
O4 - HKLM\..\Run: [Microsoft Internet Acceleration Utility] iau.exe
O4 - HKLM\..\Run: [Internet Connection Wizard] stisvsq.exe
O4 - HKLM\..\Run: [Games Acceleration] svshost.exe
O4 - HKLM\..\Run: [Internet Mail and News] msqdevl.exe
O4 - HKLM\..\Run: [Microsoft Management Console] lssas.exe
O4 - HKLM\..\Run: [Multimedia extensions] mservice.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Microsoft Internet Acceleration Utility] iau.exe
O4 - HKCU\..\Run: [Internet Connection Wizard] stisvsq.exe
O4 - HKCU\..\Run: [Games Acceleration] svshost.exe
O4 - HKCU\..\Run: [Internet Mail and News] msqdevl.exe
O4 - HKCU\..\Run: [Microsoft Management Console] lssas.exe
O4 - HKCU\..\Run: [Multimedia extensions] mservice.exe
O4 - Global Startup: Microsoft Office.lnk = E:\office\Office10\OSA.EXE
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: &Google Search - res://c:\windows\downloaded program files\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\office\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Pages liées - res://c:\windows\downloaded program files\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\windows\downloaded program files\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Télécharger avec &BitSpirit - C:\Program Files\BitSpirit\bsurl.htm
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\windows\downloaded program files\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20040428/qtinstall.info.apple.com/saba/fr/win/QuickTimeInstaller.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{418D4212-379B-410A-993F-BA455AF296B1}: NameServer = 80.10.246.130 80.10.246.3
O18 - Filter: text/html - {A6816ABA-DEAD-4874-BDFB-758A7311FF9F} - C:\WINDOWS\System32\kcol.dll
O18 - Filter: text/plain - {A6816ABA-DEAD-4874-BDFB-758A7311FF9F} - C:\WINDOWS\System32\kcol.dll
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - E:\av\AVWUPSRV.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - E:\kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: RTE : Partage TAPI (RTETAPIService) - RTE Software - c:\fotowin\RTETPISv.exe

19 réponses

  1. Contributeur
    salut

    commence par la

    tu les telecharge et tu les mets a jour et tu les faits tourner

    1/Spybot S&D 1.4 <<nouvelle version
    http://www.safer-networking.org/fr/index.html

    Démo d’utilisation (merci à Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

    2/Ad-Aware SE 1.06 <<nouvelle version
    http://www.lavasoftusa.com/software/adaware/
    -Une aide:
    http://www.tutopat.com/viewtopic.php?t=1191
    - installe le patch français, tu pourras le trouver ici:
    http://download.lavasoft.de.edgesuite.net/public/pllangs.exe
    et une petite vidéo d'utilisation ici:(merci à Moe31 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/adawrevid.asf

    3/Clean Up 40:
    http://pageperso.aol.fr/balltrap34/CleanUp40.exe
    -aide en image:(merci à Balltrap34)
    http://pageperso.aol.fr/balltrap34/democleanup.htm
    0
    1. merci pour ton aide, mais j ai toujours ce virus sur le dos.

      J ai téléchargé la dernière version de Adaware qui identifie les problemes me propose de les effacer mais une fois que c est fait, mon teatimer de spybot me previent qu il y a des tentatives de modifs sur mon disc provenant de startpage.

      par ailleurs, j ai fait un cleanup qui a viré plein de trucs de mon PC mais le probleme persiste toujours.

      Existe-t-il d autres solutions ?

      encore merci
      0
      1. Bonjour,

        Méthode à suivre dans l'ordre...

        ***
        Désactive le temps de la manip, le Tea timer de Spybot
        lance Spybot >mode avancé> outils >> résident
        Décoche la case résident "tea timer"
        referme Spybot
        ----------------------------------------------------------------------------
        ¤Télécharge ces logiciels mais que tu n‘utilises pas tout de suite:

        1/Spybot S&D 1.4 <<nouvelle version
        http://www.safer-networking.org/fr/index.html

        Démo d’utilisation (merci à Balltrap34 pour cette réalisation)
        http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

        2/Ad-Aware SE 1.06 <<nouvelle version
        http://www.lavasoftusa.com/software/adaware/
        -Une aide:
        http://www.tutopat.com/viewtopic.php?t=1191
        - installe le patch français, tu pourras le trouver ici:
        http://download.lavasoft.de.edgesuite.net/public/pllangs.exe
        et une petite vidéo d'utilisation ici:(merci à Moe31 pour cette réalisation)
        http://pageperso.aol.fr/balltrap34/adawrevid.asf

        3/Clean Up 40:
        http://pageperso.aol.fr/balltrap34/CleanUp40.exe
        -aide en image:(merci à Balltrap34)
        http://pageperso.aol.fr/balltrap34/democleanup.htm

        10/Pour se.dll
        http://www.trojaner-info.de/files/SpSeHjfix112.exe

        ----------------------------------------------------------------------------
        ¤Démarre en mode sans échec :
        Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
        Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
        Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
        (Si F8 ne marche pas utilise la touche F5)
        ----------------------------------------------------------------------------
        ¤Affiche tous les fichiers et dossiers :
        Clique sur démarrer/panneau de configuration/outil/option des dossiers/affichage

        Coche « afficher les fichiers et dossiers cachés »

        Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

        Décoche « masquer les extensions dont le type est connu »
        Puis fais «Ok» pour valider les changements.

        Et appliquer !
        ----------------------------------------------------------------------------
        ¤Vide tes fichiers temps et tempory internet file:
        utilise ceci pour le faire (tu as téléchargé avant)
        http://pageperso.aol.fr/balltrap34/CleanUp40.exe
        ----------------------------------------------------------------------------
        ¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ALEXAL~1\LOCALS~1\Temp\se.dll/space.html

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ALEXAL~1\LOCALS~1\Temp\se.dll/space.html

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank

        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://127.0.0.1:80

        O1 - Hosts: localhost 127.0.0.1

        O2 - BHO: (no name) - {1EB44D95-6A8B-43CD-815E-65D68540FCCB} - C:\WINDOWS\System32\kcol.dll

        O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\ALEXAL~1\LOCALS~1\Temp\se.dll,DllInstall

        O4 - HKLM\..\Run: [Microsoft Internet Acceleration Utility] iau.exe

        O4 - HKLM\..\Run: [Internet Connection Wizard] stisvsq.exe

        O4 - HKLM\..\Run: [Games Acceleration] svshost.exe

        O4 - HKLM\..\Run: [Internet Mail and News] msqdevl.exe

        O4 - HKLM\..\Run: [Microsoft Management Console] lssas.exe

        O4 - HKLM\..\Run: [Multimedia extensions] mservice.exe

        O4 - HKCU\..\Run: [Microsoft Internet Acceleration Utility] iau.exe

        O4 - HKCU\..\Run: [Internet Connection Wizard] stisvsq.exe

        O4 - HKCU\..\Run: [Games Acceleration] svshost.exe

        O4 - HKCU\..\Run: [Internet Mail and News] msqdevl.exe

        O4 - HKCU\..\Run: [Microsoft Management Console] lssas.exe

        O4 - HKCU\..\Run: [Multimedia extensions] mservice.exe

        O18 - Filter: text/html - {A6816ABA-DEAD-4874-BDFB-758A7311FF9F} - C:\WINDOWS\System32\kcol.dll

        O18 - Filter: text/plain - {A6816ABA-DEAD-4874-BDFB-758A7311FF9F} - C:\WINDOWS\System32\kcol.dll

        ----------------------------------------------------------------------------
        ¤Recherche et supprime ceci:
        attention seulement les fichiers (si présents)

        iau.exe
        stisvsq.exe
        svshost.exe <--CONFOND PAS AVEC svchost.exe QUI LUI EST BON
        msqdevl.exe
        lssas.exe <--attention !! Cela la est avec un i alors que le bon est dans le systeme 32 avec un l
        mservice.exe

        ---------------------------------
        Utilise le prog 10, suivant ton os, c est a dire celui qui correpond a XP
        ----------------------------------------------------------------------------
        ¤ Passe Ad-Aware et vire tout ce qu’il trouve
        ----------------------------------------------------------------------------
        ¤ Passe Spybot et vire tout ce qu’il trouve
        ----------------------------------------------------------------------------
        > Tu vides ta poubelle et tu redémarres en mode normal et refait un HijackThis

        Précise tes soucis s’il en reste....

        Tiens-moi au courant

        a+
        0
        1. merci pour toutes ces infos, je vais m y mettre tout de suite.

          Juste une question: qu est ce que le prog 10 ? il s agit de se.dll ?
          0
          1. Salut,

            Je viens de faire exactement ce que tu m as dit, mais malheureusement des que je connecte sur Internet, tous les problemes reviennent instantanement.

            Par ailleurs, je ne peux toujours pas utiliser internet explorer.

            Voici le rapport de Hijack, une fois revenu en mode normal et connecté a l'internet:

            Logfile of HijackThis v1.99.1
            Scan saved at 15:37:37, on 01/09/2005
            Platform: Windows XP SP1 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\LEXBCES.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\LEXPPS.EXE
            E:\av\AVWUPSRV.EXE
            E:\kerio\Personal Firewall 4\kpf4ss.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
            C:\WINDOWS\System32\nvsvc32.exe
            c:\fotowin\RTETPISv.exe
            E:\kerio\Personal Firewall 4\kpf4gui.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            E:\kerio\Personal Firewall 4\kpf4gui.exe
            C:\PROGRA~1\WANADOO\CnxMon.exe
            C:\PROGRA~1\WANADOO\TaskbarIcon.exe
            C:\WINDOWS\tppaldr.exe
            C:\Program Files\Java\jre1.5.0\bin\jusched.exe
            E:\Gmail Notifier\G001-1.0.25.0\gnotify.exe
            C:\Program Files\ClamWin\bin\ClamTray.exe
            C:\WINDOWS\System32\ctfmon.exe
            C:\WINDOWS\System32\devldr32.exe
            C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
            E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            C:\PROGRA~1\WANADOO\EspaceWanadoo.exe
            C:\PROGRA~1\WANADOO\ComComp.exe
            C:\PROGRA~1\WANADOO\Watch.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            E:\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ALEXAL~1\LOCALS~1\Temp\se.dll/space.html
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ALEXAL~1\LOCALS~1\Temp\se.dll/space.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
            R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://127.0.0.1:80
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\acrobat\Reader\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {1EB44D95-6A8B-43CD-815E-65D68540FCCB} - (no file)
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~2\SPYBOT~1\SDHelper.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\downloaded program files\googletoolbar1.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\downloaded program files\googletoolbar1.dll
            O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
            O4 - HKLM\..\Run: [Intense Registry Service] IntEdReg.exe /CHECK
            O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\WANADOO\CnxMon.exe
            O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\WANADOO\Watch.exe
            O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\WANADOO\TaskbarIcon.exe
            O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
            O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] E:\Gmail Notifier\G001-1.0.25.0\gnotify.exe
            O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
            O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon
            O4 - HKLM\..\Run: [Microsoft Internet Acceleration Utility] iau.exe
            O4 - HKLM\..\Run: [Internet Connection Wizard] stisvsq.exe
            O4 - HKLM\..\Run: [Games Acceleration] svshost.exe
            O4 - HKLM\..\Run: [Internet Mail and News] msqdevl.exe
            O4 - HKLM\..\Run: [Microsoft Management Console] lssas.exe
            O4 - HKLM\..\Run: [Multimedia extensions] mservice.exe
            O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\ALEXAL~1\LOCALS~1\Temp\se.dll,DllInstall
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
            O4 - HKCU\..\Run: [SpybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            O4 - HKCU\..\Run: [Microsoft Internet Acceleration Utility] iau.exe
            O4 - HKCU\..\Run: [Internet Connection Wizard] stisvsq.exe
            O4 - HKCU\..\Run: [Games Acceleration] svshost.exe
            O4 - HKCU\..\Run: [Internet Mail and News] msqdevl.exe
            O4 - HKCU\..\Run: [Microsoft Management Console] lssas.exe
            O4 - HKCU\..\Run: [Multimedia extensions] mservice.exe
            O4 - Global Startup: Microsoft Office.lnk = E:\office\Office10\OSA.EXE
            O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
            O8 - Extra context menu item: &Google Search - res://c:\windows\downloaded program files\GoogleToolbar1.dll/cmsearch.html
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\office\Office10\EXCEL.EXE/3000
            O8 - Extra context menu item: Pages liées - res://c:\windows\downloaded program files\GoogleToolbar1.dll/cmbacklinks.html
            O8 - Extra context menu item: Pages similaires - res://c:\windows\downloaded program files\GoogleToolbar1.dll/cmsimilar.html
            O8 - Extra context menu item: Télécharger avec &BitSpirit - C:\Program Files\BitSpirit\bsurl.htm
            O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\windows\downloaded program files\GoogleToolbar1.dll/cmcache.html
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
            O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
            O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20040428/qtinstall.info.apple.com/saba/fr/win/QuickTimeInstaller.exe
            O17 - HKLM\System\CCS\Services\Tcpip\..\{418D4212-379B-410A-993F-BA455AF296B1}: NameServer = 80.10.246.1 80.10.246.132
            O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - E:\av\AVWUPSRV.EXE
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - E:\kerio\Personal Firewall 4\kpf4ss.exe
            O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
            O23 - Service: RTE : Partage TAPI (RTETAPIService) - RTE Software - c:\fotowin\RTETPISv.exe

            Merci pour tous les conseils, j espere qu on trouvera la solution
            0
            1. Par ailleurs, adaware detecte plurieurs spyware dont CoolWWWsearch, quand je les elimine, spybot me previent dans la foulée qu il a bloqué des changements de modifs.

              Mais quand je relance adaware juste apres, il les detecte a nouveau. En gros, je pense que des qu on les retire, ils sont automatiquement reinstallé. Les changements demandés se font dans le brwser page.

              Voila mes dernières observations.
              0
              1. ok ok,
                Tu es sur d avoir desactiver le tea timer de spybot avant de tout fixer et supprimer?
                0
                1. oui j avais desactivé le teatimer et je l ai rallumé apres
                  0
                  1. Desole, tu peux recommencer?
                    Desactive le tea timer !!!!!!!

                    ----------------------------------------------------------------------------
                    ¤Démarre en mode sans échec :
                    Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                    Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                    Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                    (Si F8 ne marche pas utilise la touche F5)
                    ----------------------------------------------------------------------------
                    ¤Affiche tous les fichiers et dossiers :
                    Clique sur démarrer/panneau de configuration/outil/option des dossiers/affichage

                    Coche « afficher les fichiers et dossiers cachés »

                    Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                    Décoche « masquer les extensions dont le type est connu »
                    Puis fais «Ok» pour valider les changements.

                    Et appliquer !
                    ----------------------------------------------------------------------------
                    ¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ALEXAL~1\LOCALS~1\Temp\se.dll/space.html

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank

                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ALEXAL~1\LOCALS~1\Temp\se.dll/space.html

                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://127.0.0.1:80

                    O1 - Hosts: localhost 127.0.0.1

                    O2 - BHO: (no name) - {1EB44D95-6A8B-43CD-815E-65D68540FCCB} - C:\WINDOWS\System32\kcol.dll

                    O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\ALEXAL~1\LOCALS~1\Temp\se.dll,DllInstall

                    O4 - HKLM\..\Run: [Microsoft Internet Acceleration Utility] iau.exe

                    O4 - HKLM\..\Run: [Internet Connection Wizard] stisvsq.exe

                    O4 - HKLM\..\Run: [Games Acceleration] svshost.exe

                    O4 - HKLM\..\Run: [Internet Mail and News] msqdevl.exe

                    O4 - HKLM\..\Run: [Microsoft Management Console] lssas.exe

                    O4 - HKLM\..\Run: [Multimedia extensions] mservice.exe

                    O4 - HKCU\..\Run: [Microsoft Internet Acceleration Utility] iau.exe

                    O4 - HKCU\..\Run: [Internet Connection Wizard] stisvsq.exe

                    O4 - HKCU\..\Run: [Games Acceleration] svshost.exe

                    O4 - HKCU\..\Run: [Internet Mail and News] msqdevl.exe

                    O4 - HKCU\..\Run: [Microsoft Management Console] lssas.exe

                    O4 - HKCU\..\Run: [Multimedia extensions] mservice.exe
                    ----------------------------------------------------------------------------
                    ¤Recherche et supprime ceci:
                    attention seulement les fichiers (si présents)

                    iau.exe
                    stisvsq.exe
                    svshost.exe <--CONFOND PAS AVEC svchost.exe QUI LUI EST BON
                    msqdevl.exe
                    lssas.exe <--attention !! Cela la est avec un i alors que le bon est dans le systeme 32 avec un l
                    mservice.exe

                    ---------------------------------
                    Utilise le prog 10, suivant ton os, c est a dire celui qui correpond a XP
                    ----------------------------------------------------------------------------
                    ¤Vide tes fichiers temps et tempory internet file:
                    utilise ceci pour le faire (tu as téléchargé avant)
                    http://pageperso.aol.fr/balltrap34/CleanUp40.exe
                    ----------------------------------------------------------------------------
                    Redemarre et reposte un hijack this

                    a+
                    0
                    1. ouf t de retour j'en suis heureuse merci.biz et a bientot.
                      0
                  2. j ai fait comme tu m as demandé et il semblerait que tout est rentré dans l'ordre :)

                    Je crois que le probleme venait du tea timer, aussi j ai desinstallé Spybot apres avoir fait toutes les manoeuvres que tu m avais indiqué.

                    Faut-il que je le reinstalle ?

                    Par ailleurs, mon internet explorer ne marche toujours pas, est ce tu sais comment je peux fixer le probleme ?

                    Enfin, j ai un soucis car j ai essayé de trouver le fichier lssas.exe (avec un L minuscule) dans le system32 mais il n y est pas - est ce grave ?

                    Encore merci pour tes precieux conseils
                    0
                    1. re,
                      remet un hijack this

                      a+
                      0
                      1. le voila:

                        Logfile of HijackThis v1.99.1
                        Scan saved at 17:20:51, on 01/09/2005
                        Platform: Windows XP SP1 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\LEXBCES.EXE
                        C:\WINDOWS\system32\LEXPPS.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        E:\av\AVWUPSRV.EXE
                        E:\kerio\Personal Firewall 4\kpf4ss.exe
                        C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                        C:\WINDOWS\System32\nvsvc32.exe
                        c:\fotowin\RTETPISv.exe
                        E:\kerio\Personal Firewall 4\kpf4gui.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\PROGRA~1\WANADOO\CnxMon.exe
                        C:\PROGRA~1\WANADOO\TaskbarIcon.exe
                        C:\WINDOWS\tppaldr.exe
                        E:\kerio\Personal Firewall 4\kpf4gui.exe
                        C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                        E:\Gmail Notifier\G001-1.0.25.0\gnotify.exe
                        C:\WINDOWS\System32\devldr32.exe
                        C:\Program Files\ClamWin\bin\ClamTray.exe
                        C:\WINDOWS\System32\ctfmon.exe
                        C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                        C:\PROGRA~1\WANADOO\EspaceWanadoo.exe
                        C:\PROGRA~1\WANADOO\ComComp.exe
                        C:\PROGRA~1\WANADOO\Watch.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\Program Files\Messenger\msmsgs.exe
                        E:\HijackThis.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://127.0.0.1:80
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\acrobat\Reader\ActiveX\AcroIEHelper.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\downloaded program files\googletoolbar1.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\downloaded program files\googletoolbar1.dll
                        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                        O4 - HKLM\..\Run: [Intense Registry Service] IntEdReg.exe /CHECK
                        O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\WANADOO\CnxMon.exe
                        O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\WANADOO\Watch.exe
                        O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\WANADOO\TaskbarIcon.exe
                        O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                        O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] E:\Gmail Notifier\G001-1.0.25.0\gnotify.exe
                        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                        O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon
                        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                        O4 - Global Startup: Microsoft Office.lnk = E:\office\Office10\OSA.EXE
                        O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                        O8 - Extra context menu item: &Google Search - res://c:\windows\downloaded program files\GoogleToolbar1.dll/cmsearch.html
                        O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\office\Office10\EXCEL.EXE/3000
                        O8 - Extra context menu item: Pages liées - res://c:\windows\downloaded program files\GoogleToolbar1.dll/cmbacklinks.html
                        O8 - Extra context menu item: Pages similaires - res://c:\windows\downloaded program files\GoogleToolbar1.dll/cmsimilar.html
                        O8 - Extra context menu item: Télécharger avec &BitSpirit - C:\Program Files\BitSpirit\bsurl.htm
                        O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\windows\downloaded program files\GoogleToolbar1.dll/cmcache.html
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                        O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
                        O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20040428/qtinstall.info.apple.com/saba/fr/win/QuickTimeInstaller.exe
                        O17 - HKLM\System\CCS\Services\Tcpip\..\{418D4212-379B-410A-993F-BA455AF296B1}: NameServer = 80.10.246.130 80.10.246.3
                        O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - E:\av\AVWUPSRV.EXE
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                        O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - E:\kerio\Personal Firewall 4\kpf4ss.exe
                        O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                        O23 - Service: RTE : Partage TAPI (RTETAPIService) - RTE Software - c:\fotowin\RTETPISv.exe
                        0
                        1. salut quentin

                          Content de relire à nouveau tes posts ici.

                          a+++
                          0
                          1. salut Olivier
                            j ai eu un remord lol

                            a+
                            0
                            1. tu as bien fait de revenir.
                              Ca allait faire un sacré vide si tu partais..

                              a+
                              0
                              1. et bien mon internet explorer ne marche pas, il n arrive pas a se connecter sur internet, alors que firefox marche tres bien.

                                Malheureusement, j ai pas mal de trucs qui fontionne avec explorer dont messenger. Donc j aimerai le reparer si possible.

                                Le mieux a mon avis serait de le reinstaller depuis zero, seulement, je ne sais pas comment faire :(

                                Autrement, je ne trouve pas le fichier lssas.exe (bien avec un L et pas un i), est ce grave ?

                                Merci encore
                                0