Pourriez-vous jeter un oeil sur mon analyse?

Bonsoir à tous et toutes,

bah voilà je vous raconte pour que vous compreniez mieux.

hier mon pc a déconné, il c mis à redemarrer sans cesse, ne voulant plus accéder à windows. au bout d'1 h j'ai reussi à le débloquer pour réaccéder à windows en mettant le cd d'installation dans le lecteur, j'ai lancé la réparation ( ca n'a rien fait) mais l'avantage c'est qu'à la fin de la restauration il me mettait c:/ comme dans l'invite de commande en me disant de taper exit mais moi j'ai tapé CHKDSK pour lancer un scan disque comme je ne pouvais le lancer de nul autre part...

ca a marché, ca l'a débloqué mais j'ai l'impression que qq chose traine encore dans les fichiers et en plus ma page internet de démarrage refuse de se changer, je pense à ce qu'on appelle HIJACK que j'ai lu dans divers posts ici.

je vous met mon analyse HIJACKTHIS ci dessous, pourriez vous me dire si qq chose n'est pas normal ? je vous remercie d'avance :

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Screen Watcher\watcher.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\a-squared Anti-Malware\a2guard.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [s-watch] C:\Program Files\Screen Watcher\watcher.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - C:\Documents and Settings\\Bureau\Noble Poker\casino.exe
O9 - Extra 'Tools' menuitem: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - C:\Documents and Settings\\Bureau\Noble Poker\casino.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} - https://www.snapfish.fr/2/home
O16 - DPF: {4427E1E4-A9A6-40B1-BEAA-3F5CDA2F7453} - http://fr.samsungmobile.com/play/photo/album_fra.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697516} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp6_mp3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AE77DE0C-DA97-4C58-AD62-F7B65D0F4558}: NameServer = 212.27.32.5,213.228.0.168
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

36 réponses

Résumé de la discussion

Un PC sous Windows XP montre des redémarrages incessants et l’impossibilité d’accéder durablement à Windows, obligeant à lancer une réparation depuis le CD et à effectuer un CHKDSK lors d’une restauration. Des inquiétudes sur une éventuelle infection, évoquées via HijackThis, émergent lorsque les éléments et les processus listés (services, autoruns et modules de navigateur) semblent indiquer une activité inhabituelle. Plusieurs conseils de nettoyage et d’analyse sont proposés, dont la suppression d’un programme problématique comme PartyPoker, l’utilisation d’outils tels que SmitfraudFix, Spybot, Ad-Aware et Ewido, puis CCleaner et un scan BitDefender en ligne. En cas d’échec, l’échange invite à approfondir l’inspection technique et à répéter certains outils, tout en envisageant éventuellement une réinstallation ou une réparation approfondie du système.

Bobot (l’IA à votre service)
  1. Contributeur
    bjr

    rapport incomplet

    manque le début
    0
    1. euh bah voilà ce qu'il manquait :

      Logfile of HijackThis v1.99.1
      Scan saved at 01:46:41, on 08/07/2006
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      merci d'avance.
      0
      1. Contributeur
        merci !!!
        à moins de recoller les 2 bouts
        très sympa !!

        Logfile of HijackThis v1.99.1
        Scan saved at 01:46:41, on 08/07/2006
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
        C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
        C:\WINDOWS\system32\drivers\CDAC11BA.EXE
        C:\Program Files\ewido\security suite\ewidoctrl.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\wdfmgr.exe
        C:\Program Files\Screen Watcher\watcher.exe
        C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\a-squared Anti-Malware\a2guard.exe
        C:\Program Files\Logitech\MouseWare\system\em_exec.exe
        C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\WINDOWS\system32\rundll32.exe
        C:\WINDOWS\system32\fxssvc.exe
        C:\WINDOWS\system32\ZoneLabs\vsmon.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe
        C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - (no file)
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O4 - HKLM\..\Run: [s-watch] C:\Program Files\Screen Watcher\watcher.exe
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
        O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
        O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
        O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
        O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
        O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - C:\Documents and Settings\\Bureau\Noble Poker\casino.exe
        O9 - Extra 'Tools' menuitem: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - C:\Documents and Settings\\Bureau\Noble Poker\casino.exe
        O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
        O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
        O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
        O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} - https://www.snapfish.fr/2/home
        O16 - DPF: {4427E1E4-A9A6-40B1-BEAA-3F5CDA2F7453} - http://fr.samsungmobile.com/play/photo/album_fra.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
        O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697516} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp6_mp3.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{AE77DE0C-DA97-4C58-AD62-F7B65D0F4558}: NameServer = 212.27.32.5,213.228.0.168
        O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
        O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
        O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
        O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

        0
        1. pardon de ne pas l'avoir collé ensemble.

          as tu trouvé qq chose d'anormal dans mon analyse?
          0
          1. Contributeur
            re
            installe ces 3 progr, si su n'as pas
            màj
            scan
            communique rapport du 3 em

            1/ -Ad-Aware (gratuit) :
            Tutorial et téléchargement ici :
            https://forums.cnetfrance.fr
            2/ - Spybot (gratuit) :
            http://telecharger.01net.com/windows/Internet/internet_utlitaire/fiches/26157.htm... demo d utilisation
            http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm
            3/ - Ewido (download)- gratuit même après 14 jours d’essai
            http://perso.wanadoo.fr/entraide-hijackthis/Ewido/
            Copie/COLLE le rapport généré sur ce forum
            0
            1. Contributeur
              re
              suis en train de lire en détail

              continue de nettoyer avec

              4/ - Ccleaner : ( nettoyeur de registre, cookies+temps+tempos+prefetch+historique+etc..)
              Télécharge ici :
              https://www.ccleaner.com/ccleaner/download
              Tutorial ici:
              https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
              =============
              puis
              5/ - Scan online avec BitDefender (fonctionne uniquement sous Internet Explorer en acceptant l’ activX)
              https://assiste.com/404_La_page_demandee_n_existe_pas.php
              http://www.bitdefender.fr/scan8/ie.html
              Copie/COLLE le rapport entier
              ============
              si tt cela est négatif il faudra sans doute chercher côté technique
              0
              1. Contributeur
                re
                je cherche tjrs où le bât blesse :

                en cas fais une moitié de ceci ;

                0/ - Smitfraudfix
                (A)-Télécharger ceci (merci a S!RI pour ce petit programme) :
                http://siri.urz.free.fr/Fix/SmitfraudFix.zip
                L'exécuter, puis double-cliquer sur Smitfraudfix.cmd
                Choisir l’option 1, elle va générer un rapport
                Copie-COLLE ce dernier dans un message sur le forum.
                Tutorial imagée à lire :
                http://siri.urz.free.fr/Fix/SmitfraudFix.php
                (B)-
                (C)-

                ==
                "kifkif el h'mar, dur dur de faire avancer"
                0
                1. j'ai deja fait tous ces nettoyages hier soir,en mode sans echec, dois je les refaire? ou seulement ceux que tu veux en rapport?
                  0
                  1. Salut,

                    Coller les rapports :
                    Bitdef et Simtfraud, serait une bonne idée.

                    Bye
                    0
                    1. Contributeur
                      bsr
                      marre de répéter ce qui est parfaitement écrit
                      je laisse la place à un autre
                      bon ouike
                      0
                      1. voici mon rapport ewido:

                        ---------------------------------------------------------
                        ewido anti-malware - Rapport de scan
                        ---------------------------------------------------------

                        + Créé le: 20:47:23, 08/07/2006
                        + Somme de contrôle: 9F7A61AC

                        + Résultats du scan:

                        C:\Program Files\Fichiers communs\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Nettoyer et sauvegarder
                        C:\WINDOWS\Noble Poker setup.exe -> Adware.Casino : Nettoyer et sauvegarder

                        ::Fin du rapport

                        et le rapport de SmitFraudFix v2.21
                        Rapport fait à 20:56:46,59 le 08/07/2006
                        Executé à partir de C:\Documents and Settings\Bureau\ordi\SmitfraudFix\SmitfraudFix\SmitfraudFix
                        OS: Microsoft Windows XP [version 5.1.2600]

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche ...\Application Data

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                        "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"

                        [HKEY_CLASSES_ROOT\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
                        @="%SystemRoot%\system32\browseui.dll"

                        [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
                        @="%SystemRoot%\system32\browseui.dll"

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                        "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"

                        [HKEY_CLASSES_ROOT\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
                        @="%SystemRoot%\system32\browseui.dll"

                        [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
                        @="%SystemRoot%\system32\browseui.dll"

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                        »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport

                        qu'en pensez vous?
                        0
                        1. On continue :

                          2°/ - Démarre en mode sans échec :

                          Pour cela, tu tapotes la touche F8 dès le début de l’allumage du PC sans t’arrêter
                          Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape ‘Entrée’ sur ton clavier.

                          Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres, c’est normal !
                          (Si F8 ne marche pas utilise la touche F5).

                          3°/ - Relance le programme Smitfraud,
                          Cette fois choisit l’option 2, répond OUI à tout ;
                          Sauvegarde le rapport, redémarre en mode normal,
                          Copie-COLLE le rapport sauvegardé sur le forum.

                          ENSUITE tu refais un HT

                          Bye
                          0
                          1. Contributeur
                            re
                            ce n était pas nécessaire !!
                            car rapport propre
                            0
                        2. c'est en mode sans echec que je me suis servi de smitfraudfix et je t'ai mis le rapport ci dessus.

                          et HT c koi stp?
                          0
                          1. Contributeur
                            HijackThis=HT
                            0
                        3. En principe on le voit si c'est sans échec ou pas.....

                          HT == HIJACKTHIS
                          0
                          1. Contributeur
                            smitfraud
                            option 1 tjrs en normal
                            option 2 tjrs en ss échec
                            0
                        4. je l'ai bien fait sans echec tu sais.

                          en tout cas, j'ai fait le HT comme tu as mis aussi et le voila mais en mode normal par contre :

                          Logfile of HijackThis v1.99.1
                          Scan saved at 22:16:31, on 08/07/2006
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                          C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                          C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                          C:\Program Files\ewido\security suite\ewidoctrl.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                          C:\Program Files\Screen Watcher\watcher.exe
                          C:\WINDOWS\system32\nvsvc32.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\wdfmgr.exe
                          C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
                          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                          C:\Program Files\a-squared Anti-Malware\a2guard.exe
                          C:\Program Files\Logitech\MouseWare\system\em_exec.exe
                          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                          C:\Program Files\MessengerPlus! 3\MsgPlus.exe
                          C:\WINDOWS\system32\rundll32.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\WINDOWS\system32\fxssvc.exe
                          C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                          C:\Program Files\MSN Messenger\msnmsgr.exe
                          C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                          O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - (no file)
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                          O4 - HKLM\..\Run: [s-watch] C:\Program Files\Screen Watcher\watcher.exe
                          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
                          O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                          O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
                          O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                          O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                          O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                          O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                          O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                          O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                          O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                          O9 - Extra button: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - C:\Documents and Settings\\Bureau\Noble Poker\casino.exe
                          O9 - Extra 'Tools' menuitem: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - C:\Documents and Settings\\Bureau\Noble Poker\casino.exe
                          O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
                          O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
                          O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
                          O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} - https://www.snapfish.fr/2/home
                          O16 - DPF: {4427E1E4-A9A6-40B1-BEAA-3F5CDA2F7453} - http://fr.samsungmobile.com/play/photo/album_fra.cab
                          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                          O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                          O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697516} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp6_mp3.cab
                          O17 - HKLM\System\CCS\Services\Tcpip\..\{AE77DE0C-DA97-4C58-AD62-F7B65D0F4558}: NameServer = 212.27.32.5,213.228.0.168
                          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                          O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                          O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                          O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                          O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                          O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                          O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                          0
                          1. Contributeur
                            re
                            virer un progr de merde :
                            PartyPoker via ajout/suppr
                            0
                            1. Contributeur
                              re
                              un coup de balai

                              cocher et fixer ds HJT :

                              O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
                              O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} - https://www.snapfish.fr/2/home
                              O16 - DPF: {4427E1E4-A9A6-40B1-BEAA-3F5CDA2F7453} - http://fr.samsungmobile.com/play/photo/album_fra.cab
                              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                              O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                              O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697516} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp6_mp3.cab
                              +
                              O4 - HKLM\..\Run: [s-watch] C:\Program Files\Screen Watcher\watcher.exe

                              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

                              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

                              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

                              O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe

                              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot

                              O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"

                              O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"

                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              ===========
                              suite dim soir.......
                              0
                              1. Coucou,

                                merci aranjuez31, j'ai fait ce que tu m'as dit, maintenant je fais koi ?

                                ma page de démarrage est inchangeable, j'attribue un site (yahoo) en démarrage mais ca ne se fixe pas, il me remet msn à chq fois, y a t il un rapport avec mon problème de reboot?

                                merci d'avance de votre aide
                                0
                                1. quelqu'un peut m'aider pour mon probleme de page de démarrage svp?
                                  0
                                  1. Contributeur sécurité
                                    Re

                                    Re-Télécharge ceci: (merci a S!RI pour ce programme).
                                    http://siri.urz.free.fr/Fix/SmitfraudFix.zip
                                    Exécute le, Double click sur Smitfraudfix.cmd choisit l’option 1, il va générer un rapport
                                    Copie/colle le sur le poste stp.
                                    ----------------------------------------------------------------------------
                                    0
                                    • 1
                                    • 2