Protection bar

Résolu
Bonjour,
Je suis nouveau sur ce forum et j'espere que quelqu'un pourra m'aider, j'ai la protection bar sur le net et je n'arrive pas a mon débarrasser. Que faire ?

Mon anti virus est Kaspersky.
Le rapport d'analyse est :

C:\Program Files\Video ActiveX Object\iesplugin.dll/PE_Patch, découvert : cheval de Troie Trojan-Downloader.Win32.Zlob.bdi

Merci pour votre aide.
Configuration: Windows XP
Internet Explorer 7.0

13 réponses

  1. Modérateur
    Salut

    # Télécharge ceci: (merci a S!RI pour ce petit programme).

    http://siri.urz.free.fr/Fix/SmitfraudFix.zip

    Exécute le, Double click sur Smitfraudfix.cmd choisit l’option 1,
    voila a quoi cela ressemble : http://siri.urz.free.fr/Fix/SmitfraudFix.php
    il va générer un rapport : copie/colle le sur le poste stp.

    ++
    0
    1. SmitFraudFix v2.132

      Rapport fait à 21:21:07,31, 06/01/2007
      Executé à partir de C:\Documents and Settings\Fabrice\Bureau\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode normal

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Fabrice

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Fabrice\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
      0
      1. Modérateur
        re

        ton rappprt est incomplé !

        poste en un autre stp

        ++
        0
        1. SmitFraudFix v2.132

          Rapport fait à 21:21:07,31, 06/01/2007
          Executé à partir de C:\Documents and Settings\Fabrice\Bureau\SmitfraudFix
          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
          Le type du système de fichiers est NTFS
          Fix executé en mode normal

          »»»»»»»»»»»»»»»»»»»»»»»» C:\

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Fabrice

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Fabrice\Application Data

          »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

          C:\DOCUME~1\ALLUSE~1\MENUDM~1\Online Security Guide.url PRESENT !
          C:\DOCUME~1\ALLUSE~1\MENUDM~1\Security Troubleshooting.url PRESENT !

          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Fabrice\Favoris

          »»»»»»»»»»»»»»»»»»»»»»»» Bureau

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

          C:\Program Files\Video ActiveX Object\ PRESENT !

          »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

          »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
          "Source"="About:Home"
          "SubscribedURL"="About:Home"
          "FriendlyName"="Ma page d'accueil"

          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
          "{951a98d0-dad6-4a77-8280-a494279a884b}"="beeper"

          [HKEY_CLASSES_ROOT\CLSID\{951a98d0-dad6-4a77-8280-a494279a884b}\InProcServer32]
          @="C:\WINDOWS\system32\vwfps.dll"

          [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{951a98d0-dad6-4a77-8280-a494279a884b}\InProcServer32]
          @="C:\WINDOWS\system32\vwfps.dll"

          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLs"=""

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "System"=""

          »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

          »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

          »»»»»»»»»»»»»»»»»»»»»»»» Fin
          0
          1. Modérateur
            Merci :-)

            # Démarre en mode sans échec :
            Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
            Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
            Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
            (Si F8 ne marche pas utilise la touche F5).
            ----------------------------------------------------------------------------
            # Relance le programme Smitfraud :
            Cette fois choisit l’option 2, répond oui a tous ;
            Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

            ensuite :

            Télécharge ceci sur ton bureau :

            Lien : hijackthis

            Démo : http://pageperso.aol.fr/balltrap34/demohijack.htm

            Choisir l'option "do a scan and a logfile", et faire un copier/coller du rapport ainsi générer sur le forum.

            @+
            0
            1. SmitFraudFix v2.132

              Rapport fait à 21:58:02,81, 06/01/2007
              Executé à partir de C:\Documents and Settings\Fabrice\Bureau\SmitfraudFix
              OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
              Le type du système de fichiers est NTFS
              Fix executé en mode sans echec

              »»»»»»»»»»»»»»»»»»»»»»»» Avant SmitFraudFix
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
              "{951a98d0-dad6-4a77-8280-a494279a884b}"="beeper"

              [HKEY_CLASSES_ROOT\CLSID\{951a98d0-dad6-4a77-8280-a494279a884b}\InProcServer32]
              @="C:\WINDOWS\system32\vwfps.dll"

              [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{951a98d0-dad6-4a77-8280-a494279a884b}\InProcServer32]
              @="C:\WINDOWS\system32\vwfps.dll"

              »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

              »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

              GenericRenosFix by S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

              C:\DOCUME~1\ALLUSE~1\MENUDM~1\Online Security Guide.url supprimé
              C:\DOCUME~1\ALLUSE~1\MENUDM~1\Security Troubleshooting.url supprimé
              C:\Program Files\Video ActiveX Object\ supprimé

              »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
              "System"=""

              »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

              Nettoyage terminé.

              »»»»»»»»»»»»»»»»»»»»»»»» Après SmitFraudFix
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll

              »»»»»»»»»»»»»»»»»»»»»»»» Fin
              0
              1. Logfile of HijackThis v1.99.1
                Scan saved at 22:09:39, on 06/01/2007
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.5730.0011)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
                C:\WINDOWS\system32\pctspk.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\RunDll32.exe
                C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
                C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                C:\Program Files\Lexmark 4300 Series\lxcemon.exe
                C:\Program Files\Lexmark 4300 Series\ezprint.exe
                C:\WINDOWS\system32\LVCOMSX.EXE
                C:\Program Files\Logitech\Video\LogiTray.exe
                C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
                C:\Program Files\DAEMON Tools\daemon.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\ATI Multimedia\main\launchpd.exe
                C:\Program Files\MSN Messenger\MsnMsgr.Exe
                C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                C:\Program Files\Logitech\Video\FxSvr2.exe
                C:\WINDOWS\system32\lxcecoms.exe
                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                C:\Program Files\WinRAR\WinRAR.exe
                C:\DOCUME~1\Fabrice\LOCALS~1\Temp\Rar$EX00.984\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
                O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
                O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16
                O4 - HKLM\..\Run: [lxcemon.exe] "C:\Program Files\Lexmark 4300 Series\lxcemon.exe"
                O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 4300 Series\ezprint.exe"
                O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
                O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
                O4 - HKLM\..\Run: [WhenUSearchWHSE] "C:\Program Files\WhenUSearch\whse.exe"
                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
                O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?a5f64f605fe74a658fe510461535bd9e
                O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?a5f64f605fe74a658fe510461535bd9e
                O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O11 - Options group: [INTERNATIONAL] International*
                O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                O17 - HKLM\System\CCS\Services\Tcpip\..\{EF6565C1-AD06-4A5C-8B7F-475797B3D940}: NameServer = 213.36.80.1 213.36.80.1
                O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
                O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
                O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
                O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe

                Merci pour ton aide t'es un AS.
                0
                1. Modérateur
                  re

                  c'est pas il, c'est elle ;-))

                  fais le 1/ et 2/ de ce lien stp

                  virus methode preliminaire de desinfection version fr

                  @+
                  0
                  1. Oupsss...
                    désolé et merci pour ton aide.
                    0
                    1. Green t'es un super bon pote, j'voulais encore te le dire :P
                      0
                      1. Grand fou :$ ... pa d'vant tout l'monde j'suis timide ^^

                        Bises (k)
                        0