[VIRUS]contamination par Serwab

Rebonjour à tous, après une première contamination, me revoila avec un nouveau virus SERWAB, internet explorer vient de le detecter, l'ordinateur est au ralenti, et l'explorateur se ferme de temps en temps. J'ai effectuer un petit nettoyage avec CCleaner, et donc je voudrais savoir si quelqu'un pourrai m'aider à nettoyer mon ordinateur de cette saleté virulante. J'ai une question: est ce qu'un virus contamine également des documents personnels comme des photos, films, fichiers photoshops...? merci d'avance pour votre aide
Configuration: Windows XP
Internet Explorer 6.0

6 réponses

  1. Coucou, ya t-il des chasseurs de virus serwab?
    0
    1. Salut

      Oui, il se peut qu'un virus contamine tes fichiers persos.

      Télécharge SmitfraudFix (enregistre le sur le "bureau")
      http://siri.urz.free.fr/Fix/SmitfraudFix.zip

      décompresse SmitfraudFix
      Lance le fichier SmitfraudFix ou SmitfraudFix.cmd et choisit l option 1 copie le rapport ici

      ________________________________________________________

      Télécharge HijackThis :
      --->hijackthis
      Installe le dans son propre dossier :
      - clic droit sur le bureau, tu choisis "nouveau dossier" puis installe-le à l'intérieur.
      Double-clic sur HijackThis , clic sur "do a system scan and save logfile"
      Puis copie et colle le rapport ici stp
      0
      1. Salut boule pat, comment ca va? le pere noel t'a ramené un nouveau clavier? C'est la deuxieme fois que tu me viens en aide, et je t'en remercie bien. Voici le rapport de Smitfraudfix:

        SmitFraudFix v2.134

        Rapport fait à 12:31:18,64, 24/01/2007
        Executé à partir de C:\Documents and Settings\SEB\Bureau\SmitfraudFix
        OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
        Le type du système de fichiers est NTFS
        Fix executé en mode normal

        »»»»»»»»»»»»»»»»»»»»»»»» C:\

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\SEB

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\SEB\Application Data

        »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

        »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\SEB\Favoris

        »»»»»»»»»»»»»»»»»»»»»»»» Bureau

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

        »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

        »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
        "Source"="About:Home"
        "SubscribedURL"="About:Home"
        "FriendlyName"="Ma page d'accueil"

        »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
        "AppInit_DLLs"=""

        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
        "System"=""

        »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

        »»»»»»»»»»»»»»»»»»»»»»»» Fin

        Et voici maintenant le rapport Hijackthis:

        Logfile of HijackThis v1.99.1
        Scan saved at 12:38:16, on 24/01/2007
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
        C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
        C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
        C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
        C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
        C:\Program Files\Dell\Media Experience\DMXLauncher.exe
        C:\WINDOWS\system32\dla\tfswctrl.exe
        C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
        C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
        C:\Program Files\Broadcom\BACS\BacsTray.exe
        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        C:\Program Files\BroadJump\Client Foundation\CFD.exe
        C:\WINDOWS\system32\qttask.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\stsystra.exe
        C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
        C:\Program Files\Club-Internet\Agent Wi-Fi V2.1\McciTrayApp.exe
        C:\WINDOWS\system32\rundll32.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Skype\Phone\Skype.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
        C:\WINDOWS\system32\drivers\CDAC11BA.EXE
        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
        C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
        C:\Program Files\Club-Internet\Le Compagnon Club\bin\lecompagnonclub.exe
        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
        C:\Program Files\Club-Internet\Le Compagnon Club\bin\mpbtn.exe
        C:\PROGRA~1\Motive\ASSTCO~1\MOTIVE~1.EXE
        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
        C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
        C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Autodesk Network License Manager\lmgrd.exe
        C:\WINDOWS\system32\MsPMSPSv.exe
        C:\Program Files\Autodesk Network License Manager\adskflex.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
        C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
        C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
        C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Documents and Settings\SEB\Bureau\Nouveau dossier\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
        O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
        O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [ShowLOMControl]
        O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
        O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
        O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
        O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
        O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
        O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
        O4 - HKLM\..\Run: [bacstray] C:\Program Files\Broadcom\BACS\BacsTray.exe
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
        O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
        O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
        O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
        O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
        O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
        O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
        O4 - HKLM\..\Run: [Club-Internet_McciTrayApp] C:\Program Files\Club-Internet\Agent Wi-Fi V2.1\McciTrayApp.exe
        O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
        O4 - Global Startup: Accélérateur de démarrage AutoCAD.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
        O4 - Global Startup: Bluetooth Manager.lnk = ?
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O4 - Global Startup: LE COMPAGNON CLUB.lnk = C:\Program Files\Club-Internet\Le Compagnon Club\bin\matcli.exe
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
        O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - https://www.f-secure.com/en/home/support
        O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
        O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
        O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
        O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
        O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
        O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
        O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
        O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
        O23 - Service: Viz 2005 - Macrovision Corporation - C:\Program Files\Autodesk Network License Manager\lmgrd.exe
        O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

        A toi de jouer boulepat, merci encore
        0
    2. Slaut Petpou

      Non, même pas juste une souris qu'il lui restait dans l'fond !
      Le clavier fait de la résistance !

      ¤ Tu peux jeter smitfraudfix

      ¤ Désinstalle ces deux programmes, car ils sont loin d'être à jour et comporte des failles, on les réinstallera à la fin de la manip

      - Adobe Acrobat
      - Java (tout ce que tu vois)

      ¤ Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked"

      R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      O4 - HKLM\..\Run: [ShowLOMControl]
      O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
      O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - Global Startup: Accélérateur de démarrage AutoCAD.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

      ¤ Je ne sais plus les logiciels anti-spywares que tu as donc en voici une liste si tu ne les as pas télécharge les et scanne complétement ton PC et supprime tout ce qu'ils pourraient te trouver :

      SpyBot-Search & Destroy: (gratuit en Français)
      --->Spybot
      Si tu as besoin d'aide avec Sybot regarde ce tutoriel:
      http://www.tutoriaux-excalibur.com/spybot.htm

      A² squared: (gratuit en Français)(fait un scan rusé et colle le rapport ici stp)
      --->A-squared
      Si tu as besoin d'aide avec A-squared regarde ce tutoriel:
      https://kerio.probb.fr/t223-tuto-pour-a-squared-free

      Ad-Aware SE Personal: (en Anglais disponible en Français, gratuit)
      --->Ad-aware
      Si tu as besoin d'aide pour ad-Aware regarde ce tutoriel:
      https://kerio.probb.fr/t207-tutoriel-pour-ad-aware-anti-spyware

      Télécharge, installe puis met à jour ce logiciel(Ewido), une fois que c'est fait, fais un scan complet de ton système, supprime (delete) tout ce qu'il te trouve puis colle le rapport ici stp
      Ewido: (en Anglais reste gratuit après la période d'essai)
      --->Ewido
      Si tu as besoin d'aide avec Ewido(devenu AVG-antispyware) regarde ce tutoriel:
      http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html

      ¤ Fait ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2(en haut) va se mettre à clignoter, clique dessus et choisit "accepter l'active X" pour faire fonctionner le scan anti-virus.
      Une fois qu'il a terminé colle le rapport ici stp

      _Online Scanner
      _Kaspersky Online Scanner
      _My Computer

      https://www.kaspersky.fr/downloads

      A+++

      0
      1. Salut boulepat, ya du boulot a ce que je vois, alors je t'envoie tout d'abord les lignes de HijackThis que je n'ai pas trouver après la désinstallation de Acrobat et de Java:

        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
        O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

        Et je te renvoie la suite un peu plus tard, merci
        0
        1. Petit problème, quand j'ai voulu fixer les lignes que tu m'as signalé, ce message est apparu:

          unexpected error occured!
          Error #52 (nom ou numéro de fichiers incorrect) in Sub GetLongPath (.exe).
          Please send a report to merijn@spywareinfo.com, mentionning what you were doing, and what version of Windows you have;
          This message has been copied to your clipboard.

          J'ai surement du effectuer une connerie, car j'ai voulue désinstaller Kerio entre temps. J'avait installer auparavant Avast et Kerio
          0
          1. Salut

            Pas grave continue la suite ;-)
            0
            1. Salut Boulepat, désolé je me suis absenté pendant en peyit bout de temps, mais me revoila penché sur la machine, en matière d'antispyware j'avais installer Kerio et Avast, j'ai eu quelques petit probleme avec Kerio, donc je l'ai désinstallé. pour Avast j'ai l'impression qu'il ne sert à rien, je vais peut être le remplacer avec une version gratuite de AVG, as tu des conseils à me donner sur ce sujet là?

              Sinon voila les rapports,

              A²squared:
              Version - a-squared Free 2.1

              Réglages Scan:

              Objets: Mémoire, Traces, Cookies, C:\
              Scan archives: Marche
              Heuristiques: Marche
              Scan ADS: Marche

              Début du scan: 07-02-02 20:01:11

              C:\Documents and Settings\SEB\Cookies\seb@247realmedia[2].txt Détecter: Trace.TrackingCookie
              C:\Documents and Settings\SEB\Cookies\seb@atdmt[2].txt Détecter: Trace.TrackingCookie
              C:\Documents and Settings\SEB\Cookies\seb@bs.serving-sys[1].txt Détecter: Trace.TrackingCookie
              C:\Documents and Settings\SEB\Cookies\seb@fastclick[2].txt Détecter: Trace.TrackingCookie
              C:\Documents and Settings\SEB\Cookies\seb@mediaplex[1].txt Détecter: Trace.TrackingCookie
              C:\Documents and Settings\SEB\Cookies\seb@serving-sys[1].txt Détecter: Trace.TrackingCookie
              C:\Documents and Settings\SEB\Cookies\seb@smartadserver[2].txt Détecter: Trace.TrackingCookie
              C:\Documents and Settings\SEB\Cookies\seb@stat.dealtime[2].txt Détecter: Trace.TrackingCookie
              C:\Documents and Settings\SEB\Cookies\seb@tradedoubler[2].txt Détecter: Trace.TrackingCookie
              C:\Documents and Settings\SEB\Cookies\seb@tribalfusion[2].txt Détecter: Trace.TrackingCookie
              C:\Documents and Settings\SEB\Cookies\seb@weborama[1].txt Détecter: Trace.TrackingCookie
              C:\Documents and Settings\SEB\Cookies\seb@zedo[1].txt Détecter: Trace.TrackingCookie
              C:\Documents and Settings\SEB\Mes documents\LOGICIEL\Sécurité\SmitfraudFix.zip/Process.exe Détecter: Riskware.RiskTool.Win32.Processor.20
              C:\Documents and Settings\SEB\Mes documents\LOGICIEL\Sécurité\SmitfraudFix.zip/Reboot.exe Détecter: Riskware.RiskTool.Win32.Reboot.f
              C:\WINDOWS\system32\Process.exe Détecter: Riskware.RiskTool.Win32.Processor.20

              Scanné

              Fichiers: 153556
              Traces: 96345
              Cookies: 80
              Processus: 57

              Trouver

              Fichiers: 3
              Traces: 0
              Cookies: 12
              Processus: 0
              Clés de Registre: 0

              Fin du Scan: 07-02-02 20:52:09
              Temps du Scan: 00:50:58

              Celui de Ewido:

              ---------------------------------------------------------
              AVG Anti-Spyware - Rapport d'analyse
              ---------------------------------------------------------

              + Créé à: 13:29 07-02-03

              + Résultat de l'analyse:

              C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP7\A0002559.exe -> Not-A-Virus.Downloader.Win32.WinFixer.m : Aucune action entreprise.
              C:\Documents and Settings\SEB\Mes documents\LOGICIEL\Sécurité\WinAntiSpyware2007FreeInstall.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Aucune action entreprise.
              C:\Documents and Settings\SEB\Cookies\seb@247realmedia[1].txt -> TrackingCookie.247realmedia : Aucune action entreprise.

              Fin du rapport

              Et enfin celui de Kaspersky:
              -------------------------------------------------------------------------------
              KASPERSKY ONLINE SCANNER REPORT
              07-02-03 16:48
              Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
              Kaspersky Online Scanner version: 5.0.83.0
              Kaspersky Anti-Virus database last update: 3/02/2007
              Kaspersky Anti-Virus database records: 249715
              -------------------------------------------------------------------------------

              Scan Settings:
              Scan using the following antivirus database: standard
              Scan Archives: true
              Scan Mail Bases: true

              Scan Target - My Computer:
              C:\
              D:\

              Scan Statistics:
              Total number of scanned objects: 94340
              Number of viruses found: 0
              Number of infected objects: 0 / 0
              Number of suspicious objects: 0
              Duration of the scan process: 01:01:45

              Infected Object Name / Virus Name / Last Action
              C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\791576950ebfab18ffae65fe78f04804_317f7cfe-190a-4e83-b1c9-595527d33e6e Object is locked skipped
              C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
              C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
              C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
              C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
              C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
              C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
              C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
              C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
              C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
              C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
              C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
              C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
              C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\call256.dbb Object is locked skipped
              C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\callmember256.dbb Object is locked skipped
              C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\chat512.dbb Object is locked skipped
              C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\chatmsg1024.dbb Object is locked skipped
              C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\chatmsg2048.dbb Object is locked skipped
              C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\chatmsg256.dbb Object is locked skipped
              C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\chatmsg512.dbb Object is locked skipped
              C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\contactgroup256.dbb Object is locked skipped
              C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\index2.dat Object is locked skipped
              C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\profile16384.dbb Object is locked skipped
              C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\transfer256.dbb Object is locked skipped
              C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\transfer512.dbb Object is locked skipped
              C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\user1024.dbb Object is locked skipped
              C:\Documents and Settings\SEB\Cookies\index.dat Object is locked skipped
              C:\Documents and Settings\SEB\Local Settings\Application Data\ApplicationHistory\cli.exe.c88dbd71.ini.inuse Object is locked skipped
              C:\Documents and Settings\SEB\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
              C:\Documents and Settings\SEB\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
              C:\Documents and Settings\SEB\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
              C:\Documents and Settings\SEB\Local Settings\Historique\History.IE5\MSHist012007020320070204\index.dat Object is locked skipped
              C:\Documents and Settings\SEB\Local Settings\Temp\bbassistant.log Object is locked skipped
              C:\Documents and Settings\SEB\Local Settings\Temp\hpodvd09.log Object is locked skipped
              C:\Documents and Settings\SEB\Local Settings\Temp\Perflib_Perfdata_1b8.dat Object is locked skipped
              C:\Documents and Settings\SEB\Local Settings\Temp\Perflib_Perfdata_3e8.dat Object is locked skipped
              C:\Documents and Settings\SEB\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
              C:\Documents and Settings\SEB\NTUSER.DAT Object is locked skipped
              C:\Documents and Settings\SEB\ntuser.dat.LOG Object is locked skipped
              C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
              C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
              C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
              C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
              C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
              C:\Program Files\Alwil Software\Avast4\DATA\report\Protection résidente.txt Object is locked skipped
              C:\Program Files\Autodesk Network License Manager\License\License.txt Object is locked skipped
              C:\Program Files\Club-Internet\Le Compagnon Club\log\mpbtn.log Object is locked skipped
              C:\Program Files\Club-Internet\Le Compagnon Club\SmartBridge\AlertFilter.log Object is locked skipped
              C:\Program Files\Club-Internet\Le Compagnon Club\SmartBridge\log\httpclient.log Object is locked skipped
              C:\Program Files\Club-Internet\Le Compagnon Club\SmartBridge\SmartBridge.log Object is locked skipped
              C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
              C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP19\change.log Object is locked skipped
              C:\WINDOWS\CSC\00000001 Object is locked skipped
              C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
              C:\WINDOWS\SchedLgU.Txt Object is locked skipped
              C:\WINDOWS\SoftwareDistribution\EventCache\{10B16156-A973-4AF7-9C64-75C6791C3811}.bin Object is locked skipped
              C:\WINDOWS\SoftwareDistribution\EventCache\{31A943B0-8DC6-4881-8B11-30BA530C50A3}.bin Object is locked skipped
              C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
              C:\WINDOWS\Sti_Trace.log Object is locked skipped
              C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
              C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
              C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
              C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
              C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
              C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
              C:\WINDOWS\system32\config\default.LOG Object is locked skipped
              C:\WINDOWS\system32\config\SAM Object is locked skipped
              C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
              C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
              C:\WINDOWS\system32\config\SECURITY Object is locked skipped
              C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
              C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
              C:\WINDOWS\system32\config\software.LOG Object is locked skipped
              C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
              C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
              C:\WINDOWS\system32\config\system.LOG Object is locked skipped
              C:\WINDOWS\system32\h323log.txt Object is locked skipped
              C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
              C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
              C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
              C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
              C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
              C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
              C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
              C:\WINDOWS\Temp\Perflib_Perfdata_750.dat Object is locked skipped
              C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
              C:\WINDOWS\wiadebug.log Object is locked skipped
              C:\WINDOWS\wiaservc.log Object is locked skipped
              C:\WINDOWS\WindowsUpdate.log Object is locked skipped

              Scan process completed.

              Tout à l'air de bien se passer, j'espere que tu vas me dire la meme chose. qu'il n'y a pas une petite bête cacher quelque part?
              Qu'es ce que tu en pense si je me protège avec la version gratuite d'AVG, et Kerio?

              Merci encore a toi Boulepat, avec tou cet attirail d'anti spyware, j'espere pouvoir m'en sortir la prochaine fois tout seul, et de faire un peu de vacance. merci, merci
              0