Probleme Amaena et restrictions

Bonjour , j'ai vraiment un gros probleme , depuis quelques temps je ne suis plus capable de changer ma page d'accueil et lorsque je clique sur le bouton droit de la sourit sur internet explorer et que je veut aller sur propriété il me dise un message disant qu'il ne peut pas a cause de restrictions . Pourtant lorsque je vais sur internet et je clique outils , option internet lui il marche . En plus jai un message qui apparait dans le bas avec un icone jaune avec un point d'exclamation dedans disant en anglais que window a trouvé un spyware et quil faut que je telecharge sur un site amaena un logiciel antispyware . En plus de tout sa j'arrete pas davoir des pop up de window disant aussi quil a trouver unh spyware et sa tout le 5 min
aidez moi quelqun je vais mourrir
lol
svp
Configuration: Windows XP
Internet Explorer 7.0

13 réponses

  1. Tout d'abord Bonjour et bienvenue sur le forum d'entraide COMMENT CA MARCHE

    Tout d'abord Bonjour et bienvenue sur le forum d'entraide COMMENT CA MARCHE

    Télécharge HijackThis ici:
    http://www.merijn.org/files/hijackthis.zip
    ou ici :
    https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/29061.html

    Dézippe le dans un dossier prévu à cet effet.
    Par exemple C:\hijackthis < Enregistre le bien dans c : !
    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://perso.orange.fr/rginformatique/section%20virus/Hijenr.gif

    Lance le puis:
    clique sur "do a system scan and save logfile" (cf démo)
    faire un copier coller du log entier sur le forum

    Démo : (Merci a Balltrap34 pour cette réalisation)

    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

    ensuite

    Fais un clic droit sur ce lien :
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.zip
    Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
    Fais un clic droit sur navilog1.zip et choisis "tout extraire"
    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Laisse-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
    Copie-colle l'intégralité dans une réponse. Referme le blocnote.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

    0
    1. voila mon hikack

      logfile of HijackThis v1.99.1
      Scan saved at 13:45:11, on 05/08/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16473)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.exe
      C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
      C:\WINDOWS\system32\printer.exe
      C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
      C:\WINDOWS\system32\crypserv.exe
      C:\Program Files\Symantec AntiVirus\DefWatch.exe
      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      C:\PROGRA~1\SYMANT~1\VPTray.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
      C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
      C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
      C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Symantec AntiVirus\Rtvscan.exe
      C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\DOCUME~1\REN~1\LOCALS~1\Temp\Répertoire temporaire 1 pour hijackthis[1].zip\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.lapresse.ca
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\printer.exe
      O2 - BHO: IEHlprObj Class - {ABCDECF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\system32\vtr212.dll
      O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [Syyixhcj] C:\Program Files\Pyotks\Dmkjy.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
      O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
      O4 - HKLM\..\Run: [SemanticInsight] C:\Program Files\RXToolBar\Semantic Insight\SemanticInsight.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
      O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
      O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe
      O4 - Startup: system.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: autorun.exe
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
      O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
      O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
      O8 - Extra context menu item: &Search - http://kt.bar.need2find.com/KT/menusearch.html?p=KT
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: Télécharger avec Star Downloader - C:\Program Files\Star Downloader\sdie.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O11 - Options group: [INTERNATIONAL] International*
      O15 - Trusted Zone: http://lms2.decclic.qc.ca
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://walmart.pnimedia.com/upload/activex/v2_0_0_9/PCAXSetupv2.0.0.9.cab?
      O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O20 - AppInit_DLLs: C:\WINDOWS\system32\hrum212.txt
      O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
      O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
      O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
      O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
      O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\system32\ImapiRox.exe
      O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
      O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
      O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
      O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
      O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
      0
      1. Fais un clic droit sur ce lien :
        http://perso.orange.fr/il.mafioso/Navifix/Navilog1.zip
        Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
        Fais un clic droit sur navilog1.zip et choisis "tout extraire"
        Ensuite double clique sur navilog1.exe pour lancer l'installation.
        Une fois l'installation terminée, le fix s'exécutera automatiquement.
        (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

        Laisse-toi guider. Au menu principal, choisis 1 et valides.
        (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

        Patiente jusqu'au message :
        *** Analyse Termine le ..... ***
        Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
        Copie-colle l'intégralité dans une réponse. Referme le blocnote.
        Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

        0
        1. voila lautre scan

          Search Navipromo version 2.0.5 commencé le 05/08/2007 à 13:50:55,29

          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
          !!! Poster ce rapport sur le forum pour le faire analyser !!!
          !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

          Fix lancé depuis C:\Program Files\navilog1
          Mise a jour le 01.07.2007 a 12h00 by IL-MAFIOSO

          Executé en mode normal

          *** Recherche Programmes installes ***

          *** Recherche dossiers dans C:\WINDOWS ***

          *** Recherche dossiers dans C:\Program Files ***

          *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

          *** Recherche dossiers dans C:\Documents and Settings\Ren‚\Application Data ***

          *** Recherche avec BlackLight Engine/F-secure ***
          BlackLight Engine est un produit de F-secure, pour + d'infos :
          https://www.f-secure.com/en

          F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
          ======================================

          Copyright 2005-2006 F-Secure Corporation. All rights reserved.
          This is a beta version. It will expire on 1st of October, 2007.
          Version information: 2.2.1064.

          [+] Started on 08/05/07 at 13:51:01.
          [+] Initializing ...
          [+] Starting scan, press Ctrl-C to abort.
          [+] Scanning for hidden items ...........................................................................
          [+] Scan complete.
          [+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
          [+] Exited on 08/05/07 at 13:59:16 (return code = 0).

          *** Recherche fichiers ***

          *** Recherche cles registre ***

          Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]

          Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]

          Recherche Clé Magic Control

          *** Module de Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Recherche fichiers connus:

          2)Recherche Heuristique :
          *
          **
          ***
          ****
          *****
          ******
          *******
          ********

          3)Recherche Certificats :

          *** Analyse Terminé le 05/08/2007 à 13:59:52,14 ***
          0
          1. je voulais aussi vous dire que jai essayé de faire ccleaner et easy cleaner en mode sans echec , jai aussi fait spybot lui il trouve mon probleme de restriction et page daccueil jai pu mettre cyberpresse.ca mais lorsque je redemarre mon ordi le meme probleme revient .
            merci davance
            0
            1. Ouvre ce lien (merci a S!RI pour ce programme). http://siri.urz.free.fr/Fix/SmitfraudFix.php
              et télécharge SmitfraudFix.exe.

              Regarde le tuto
              Exécute le en choisissant l’option 1, il va générer un rapport
              Copie/colle le sur le poste stp.
              0
              1. voila le scan avec SmitFraudFix
                ------------------------------------------------------------------
                je voulais vous dire que pendant le scan il y avait pleins de messdage me disant que la modification du registre a ete désactivée par l'administrateur etk
                -------------------------------------------------------------------
                SmitFraudFix v2.208

                Rapport fait à 14:23:42,78, 05/08/2007
                Executé à partir de C:\Documents and Settings\Ren‚\Bureau\SmitfraudFix
                OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                Le type du système de fichiers est NTFS
                Fix executé en mode normal

                »»»»»»»»»»»»»»»»»»»»»»»» Process

                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\Explorer.exe
                C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                C:\WINDOWS\system32\printer.exe
                C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                C:\WINDOWS\system32\crypserv.exe
                C:\Program Files\Symantec AntiVirus\DefWatch.exe
                C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                C:\PROGRA~1\SYMANT~1\VPTray.exe
                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
                C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
                C:\Program Files\QuickTime\qttask.exe
                C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
                C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
                C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Symantec AntiVirus\Rtvscan.exe
                C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\WINDOWS\system32\cmd.exe

                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                Fichier hosts corrompu !

                192.168.200.3 download.microsoft.com
                192.168.200.3 downloads.microsoft.com
                192.168.200.3 go.microsoft.com
                192.168.200.3 microsoft.com
                192.168.200.3 msdn.microsoft.com
                192.168.200.3 office.microsoft.com
                192.168.200.3 support.microsoft.com
                192.168.200.3 windowsupdate.microsoft.com
                192.168.200.3 www.microsoft.com
                192.168.200.3 pandasoftware.com
                192.168.200.3 www.pandasoftware.com

                »»»»»»»»»»»»»»»»»»»»»»»» C:\

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Ren‚

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Ren‚\Application Data

                C:\Documents and Settings\Ren‚\Application Data\Install.dat PRESENT !

                »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\REN~1\Favoris

                »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                SrchSTS.exe by S!Ri
                Search SharedTaskScheduler's .dll

                »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                "AppInit_DLLs"="C:\\WINDOWS\\system32\\hrum212.txt"

                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                »»»»»»»»»»»»»»»»»»»»»»»» DNS

                Description: Carte réseau Fast Ethernet PCI Realtek RTL8139 Family - Miniport d'ordonnancement de paquets
                DNS Server Search Order: 24.200.241.37
                DNS Server Search Order: 24.201.245.77

                HKLM\SYSTEM\CCS\Services\Tcpip\..\{EEC5BAC0-336F-4A03-A867-F61C4D808906}: DhcpNameServer=24.200.241.37 24.201.245.77
                HKLM\SYSTEM\CS1\Services\Tcpip\..\{EEC5BAC0-336F-4A03-A867-F61C4D808906}: DhcpNameServer=24.200.241.37 24.201.245.77
                HKLM\SYSTEM\CS3\Services\Tcpip\..\{EEC5BAC0-336F-4A03-A867-F61C4D808906}: DhcpNameServer=24.200.241.37 24.201.245.77
                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=24.200.241.37 24.201.245.77
                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222
                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=24.200.241.37 24.201.245.77
                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222
                HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=24.200.241.37 24.201.245.77
                HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222

                »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                »»»»»»»»»»»»»»»»»»»»»»»» Fin
                0
                1. Démarre en mode sans échec :
                  Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
                  Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                  Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                  (Si F8 ne marche pas utilise la touche F5).
                  ----------------------------------------------------------------------------
                  Relance le programme Smitfraud,
                  Cette fois choisit l’option 2, répond oui a tous ;
                  Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

                  0
                  1. Euh sa lair niezeux mais la je susi pas capable de faire copier pis de redémarrer mon ordi pis recoler il a perdu mon scan
                    etk durant que je faisait le scan il faisait encore pleins de fois la modification du registre a été désactivée par l'administrateur
                    que doit faire pour le le cpoier coller marche
                    0
                    1. reExécute le en choisissant l’option 1, il va générer un rapport
                      Copie/colle le sur le poste stp.
                      0
                      1. voila
                        je crois que c'est sa que tu veut

                        SmitFraudFix v2.208

                        Rapport fait à 17:42:37,90, 05/08/2007
                        Executé à partir de C:\Documents and Settings\Ren‚\Bureau\SmitfraudFix
                        OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                        Le type du système de fichiers est NTFS
                        Fix executé en mode sans echec

                        »»»»»»»»»»»»»»»»»»»»»»»» Process

                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\Explorer.exe
                        C:\WINDOWS\system32\printer.exe
                        C:\WINDOWS\system32\cmd.exe

                        »»»»»»»»»»»»»»»»»»»»»»»» hosts

                        Fichier hosts corrompu !

                        192.168.200.3 download.microsoft.com
                        192.168.200.3 downloads.microsoft.com
                        192.168.200.3 go.microsoft.com
                        192.168.200.3 microsoft.com
                        192.168.200.3 msdn.microsoft.com
                        192.168.200.3 office.microsoft.com
                        192.168.200.3 support.microsoft.com
                        192.168.200.3 windowsupdate.microsoft.com
                        192.168.200.3 www.microsoft.com
                        192.168.200.3 pandasoftware.com
                        192.168.200.3 www.pandasoftware.com

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Ren‚

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Ren‚\Application Data

                        »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\REN~1\Favoris

                        »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                        »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                        »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                        »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                        "AppInit_DLLs"="C:\\WINDOWS\\system32\\hrum212.txt"

                        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                        »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                        »»»»»»»»»»»»»»»»»»»»»»»» DNS

                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{EEC5BAC0-336F-4A03-A867-F61C4D808906}: DhcpNameServer=24.200.241.37 24.201.245.77
                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{EEC5BAC0-336F-4A03-A867-F61C4D808906}: DhcpNameServer=24.200.241.37 24.201.245.77
                        HKLM\SYSTEM\CS3\Services\Tcpip\..\{EEC5BAC0-336F-4A03-A867-F61C4D808906}: DhcpNameServer=24.200.241.37 24.201.245.77
                        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=24.200.241.37 24.201.245.77
                        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222
                        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=24.200.241.37 24.201.245.77
                        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222
                        HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=24.200.241.37 24.201.245.77
                        HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                        »»»»»»»»»»»»»»»»»»»»»»»» Fin
                        0
                        1. euh je voulais savoir pk lorsque je fait le scan il y a un message quui revient me disant que la modification du régistre a été désactivée par l'administrateur
                          merci
                          0
                          1. Démarre en mode sans échec :
                            Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
                            Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.

                            choisi la session Administrateur

                            Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                            (Si F8 ne marche pas utilise la touche F5).
                            ----------------------------------------------------------------------------
                            Relance le programme Smitfraud,
                            Cette fois choisit l’option 2, répond oui a tous ;
                            Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum
                            0