Windows security alert

Résolu
bonjour j'aimerais savoir si quelqu'un peux m'aider s.v.p avec ce probleme , je crois que mon ordi est infecter merci a l'avance
Configuration: Windows XP
Internet Explorer 7.0

22 réponses

Résumé de la discussion

Plusieurs indices indiquent qu'un ordinateur sous Windows XP avec Internet Explorer 7 est potentiellement infecté et nécessite une procédure de nettoyage adaptée et vérifiée rapidement. La solution recommandée consiste à démarrer en mode sans échec, relancer SmitfraudFix et choisir l'option 2 en répondant oui à tout, puis sauvegarder le rapport et redémarrer en mode normal. Le rapport sauvegardé est ensuite copié pour évaluation, et la suite peut nécessiter des mesures complémentaires comme des antivirus, pare-feu et antispyware recommandés additionnellement ultérieurement. D'autres échanges proposent des options complémentaires et des références d'antivirus gratuits comme AVG Anti-Spyware, ou des services en ligne pour une protection accrue à long terme.

Bobot (l’IA à votre service)
  1. merci pour ton service si rapide je suis vraiment debutant dans domaine mais c un ordi qui ma ete donner et quand je le rouvre j'ai un page rouge qui dis "your privacy is in danger " pis quelque instant plus tard ca rouvre un autre boite qui dis "windows security alert " warning! potentiel spyware operation et si je ferme cette boit d'autre rouvre sans arret peux tu me dire etape par etape ce que je doit faire merciiiii encore
    1. WWaa il a lair vraiment infecter ton PC. lol.
      Pour ce qui est de PC cillin tu n'as que 1 mois gratuit. Apré il faut acheter la licence qui est de 59 € TTC/ ans
      1. peux tu dire ce que je dois faire pour commencer ? je lu qu'il ya des gens qui son des pro en regardant les rappord de ton pc et de dis comment faire pour nettoyer tous ca tu c comment toi ?
        1. Contributeur
          J'ai demandé que ton message soit transféré dans le forum sécurité mais en attendant que ça se fasse, télécharge les logiciels suivant et installe-les:
          Ad-aware
          Patch français pour Ad-aware
          CCleaner
          Hijackthis

          -----------------------------------
          Installe Ad-Aware, puis le petit logiciel de francisation qui va avec si nécessaire: démarre ensuite un scan complet de ton système (le logiciel voudra se mettre à jour, il faut l'autoriser): c'est un processus qui peut prendre du temps, une fois que le scan est commencé, aussi bien couper votre connexion pour limiter les risques. Effacez ce que le programme trouve comme risques critiques.

          -------------------------------------
          Ensuite, installe HijackThis
          Dézippe le dans un dossier prévu à cet effet, dans un dossier vide sur le bureau par exemple < Enregistre le bien dans disque dur système (C: normalement) et non pas dans un deuxième disque dur ou une autre partition
          comme ceci : (Merci a Balltrap34 pour cette réalisation)
          exécute le programme puis:
          clique sur "do a system scan and save logfile" (cf démo)
          faire un copier coller du log entier sur le forum

          Démonstration : (Merci a Balltrap34 pour cette réalisation)

          -----------------------------------------
          Télécharges Blacklight et sauvegarde le sur ton bureau.
          https://www.f-secure.com/en
          Double cliques sur " blbeta.exe " et acceptes la licence; clic sur "Scan" puis "Next"

          Un rapport, va se créer sur ton bureau "fslb-....."

          Copies et colles le contenu de ce rapport ici.

          Ne touche à rien d'autre!

          Bonne chance!
          Je passe le relai aux experts pour la suite (les autres logiciels pourront alors être utiles)
          1. merci claude c super d'avoir une reponse aussi rapide , j'ai deja commencer les procedures ont va voir si ca va marcher encore un gros merci
          2. Contributeur
            @laigre2002Ce fut un plaisir! Et merci à Regis59 pour la suite.
        2. Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 12:11:12 PM, on 06/08/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16473)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
          C:\WINDOWS\system32\svchost.exe
          C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
          C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
          C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
          C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*https://fr.yahoo.com/?p=us
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: MSVPS System - {100B21CD-3B97-44FB-B1C0-EA6249E482E8} - C:\WINDOWS\ddesupport.dll
          O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - (no file)
          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
          O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: IMVU.lnk = C:\Program Files\IMVU\IMVUClient.exe
          O8 - Extra context menu item: &Webshots Photo Search - res://C:\Program Files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesca.dll
          O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesca.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\pierre\Start Menu\Programs\IMVU\Run IMVU.lnk
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
          O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
          O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - https://driveragent.com/files/driveragent.cab
          O21 - SSODL: msole - {4704E7D1-D75E-484A-8507-024B3CE55DEB} - C:\WINDOWS\msole.dll
          O21 - SSODL: msdde - {BAE6B29C-8DEF-47F6-B864-AF94A67A7DD0} - C:\WINDOWS\msdde.dll
          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
          O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
          O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
          O23 - Service: Protection Trend Micro contre les programmes espions (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
          O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
          O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
          O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
          O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
          1. 08/06/07 12:29:23 [Info]: BlackLight Engine 1.0.64 initialized
            08/06/07 12:29:23 [Info]: OS: 5.1 build 2600 (Service Pack 2)
            08/06/07 12:29:23 [Note]: 7019 4
            08/06/07 12:29:23 [Note]: 7005 0
            08/06/07 12:29:23 [Note]: 7006 0
            08/06/07 12:29:23 [Note]: 7011 1692
            08/06/07 12:29:25 [Note]: 7026 0
            08/06/07 12:29:25 [Note]: 7026 0
            08/06/07 12:29:30 [Note]: FSRAW library version 1.7.1022
            08/06/07 12:35:24 [Note]: 7007 0

            voici l'autre rapport
            1. j'attend apres la suite , c super qu'il y a encore des gens gentils qui aide les autres merci de m'aider j'ai hate de voir les resultats
              1. Contributeur sécurité
                Re,

                C'est parti:

                Télécharge SmitfraudFix de S!Ri:
                http://siri.urz.free.fr/Fix/SmitfraudFix.exe
                Tu le mets sur le Bureau.
                Tu ouvres SmitfraudFix, tu double cliques sur SmitfraudFix.cmd et tu choisis l’option 1
                Poste le rapport.

                A+
                1. SmitFraudFix v2.208

                  Scan done at 17:35:19.67, 06/08/2007
                  Run from C:\Documents and Settings\pierre\Desktop\SmitfraudFix
                  OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
                  The filesystem type is NTFS
                  Fix run in normal mode

                  »»»»»»»»»»»»»»»»»»»»»»»» Process

                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
                  C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
                  C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
                  C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                  C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                  C:\WINDOWS\system32\cmd.exe

                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                  C:\WINDOWS\ddesupport.dll FOUND !
                  C:\WINDOWS\main_uninstaller.exe FOUND !
                  C:\WINDOWS\mgrs.exe FOUND !
                  C:\WINDOWS\msole.dll FOUND !
                  C:\WINDOWS\msdde.dll FOUND !
                  C:\WINDOWS\privacy_danger FOUND !

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\pierre

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\pierre\Application Data

                  »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\pierre\FAVORI~1

                  »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                  C:\DOCUME~1\pierre\Desktop\Error Cleaner.url FOUND !
                  C:\DOCUME~1\pierre\Desktop\Privacy Protector.url FOUND !
                  C:\DOCUME~1\pierre\Desktop\Spyware?Malware Protection.url FOUND !

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                  »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                  »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                  "Source"="file:///C:\\WINDOWS\\privacy_danger\\index.htm"
                  "SubscribedURL"=""
                  "FriendlyName"="Privacy Protection"

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
                  "Source"="About:Home"
                  "SubscribedURL"="About:Home"
                  "FriendlyName"="My Current Home Page"

                  »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                  !!!Attention, following keys are not inevitably infected!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                  !!!Attention, following keys are not inevitably infected!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                  !!!Attention, following keys are not inevitably infected!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                  »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                  Description: SiS 900-Based PCI Fast Ethernet Adapter - Packet Scheduler Miniport
                  DNS Server Search Order: 64.71.255.198

                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{CC8C7DFD-CCC5-4506-B629-E2BBCAD2451D}: DhcpNameServer=64.71.255.198
                  HKLM\SYSTEM\CS1\Services\Tcpip\..\{CC8C7DFD-CCC5-4506-B629-E2BBCAD2451D}: DhcpNameServer=64.71.255.198
                  HKLM\SYSTEM\CS2\Services\Tcpip\..\{CC8C7DFD-CCC5-4506-B629-E2BBCAD2451D}: DhcpNameServer=64.71.255.198
                  HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=64.71.255.198
                  HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=64.71.255.198
                  HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=64.71.255.198

                  »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                  »»»»»»»»»»»»»»»»»»»»»»»» End

                  et voila le rapport
                  1. Contributeur sécurité
                    Re,

                    Démarre en mode sans échec :
                    Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                    Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                    Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                    (Si F8 ne marche pas utilise la touche F5).
                    ----------------------------------------------------------------------------
                    Relance le programme Smitfraud,
                    Cette fois choisit l’option 2, répond oui a tous ;
                    Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

                    A+
                    1. SmitFraudFix v2.208

                      Scan done at 17:54:53.46, 06/08/2007
                      Run from C:\Documents and Settings\pierre\Desktop\SmitfraudFix
                      OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
                      The filesystem type is NTFS
                      Fix run in safe mode

                      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                      !!!Attention, following keys are not inevitably infected!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                      »»»»»»»»»»»»»»»»»»»»»»»» hosts

                      127.0.0.1 localhost

                      »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                      GenericRenosFix by S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                      C:\WINDOWS\ddesupport.dll Deleted
                      C:\WINDOWS\main_uninstaller.exe Deleted
                      C:\WINDOWS\mgrs.exe Deleted
                      C:\WINDOWS\msole.dll Deleted
                      C:\WINDOWS\msdde.dll Deleted
                      C:\WINDOWS\privacy_danger\ Deleted
                      C:\DOCUME~1\pierre\Desktop\Error Cleaner.url Deleted
                      C:\DOCUME~1\pierre\Desktop\Privacy Protector.url Deleted
                      C:\DOCUME~1\pierre\Desktop\Spyware?Malware Protection.url Deleted

                      »»»»»»»»»»»»»»»»»»»»»»»» DNS

                      HKLM\SYSTEM\CCS\Services\Tcpip\..\{CC8C7DFD-CCC5-4506-B629-E2BBCAD2451D}: DhcpNameServer=64.71.255.198
                      HKLM\SYSTEM\CS1\Services\Tcpip\..\{CC8C7DFD-CCC5-4506-B629-E2BBCAD2451D}: DhcpNameServer=64.71.255.198
                      HKLM\SYSTEM\CS2\Services\Tcpip\..\{CC8C7DFD-CCC5-4506-B629-E2BBCAD2451D}: DhcpNameServer=64.71.255.198
                      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=64.71.255.198
                      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=64.71.255.198
                      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=64.71.255.198

                      »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

                      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                      !!!Attention, following keys are not inevitably infected!!!

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                      "System"=""

                      »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                      Registry Cleaning done.

                      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                      !!!Attention, following keys are not inevitably infected!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      »»»»»»»»»»»»»»»»»»»»»»»» End
                      1. voici l'autre repport semble bien aller mais laisser moi savoir si je doit faire autre chose
                        1. Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 6:24:50 PM, on 06/08/2007
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v7.00 (7.00.6000.16473)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\WINDOWS\Explorer.EXE
                          c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
                          C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                          C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
                          C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
                          C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
                          C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
                          C:\Program Files\Internet Explorer\IEXPLORE.EXE
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                          O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - (no file)
                          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
                          O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
                          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
                          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                          O4 - Startup: IMVU.lnk = C:\Program Files\IMVU\IMVUClient.exe
                          O8 - Extra context menu item: &Webshots Photo Search - res://C:\Program Files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
                          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                          O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesca.dll
                          O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesca.dll
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                          O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\pierre\Start Menu\Programs\IMVU\Run IMVU.lnk
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                          O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                          O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - https://driveragent.com/files/driveragent.cab
                          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                          O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
                          O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
                          O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
                          O23 - Service: Protection Trend Micro contre les programmes espions (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
                          O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
                          O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
                          O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
                          1. Contributeur sécurité
                            Re,

                            ¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

                            O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - (no file)

                            Ferme HJT.

                            Dis moi ou en sont tes soucis?

                            A+
                            1. regis59 un gros merci je n'ai plus souci toute fontionne # 1, pour l'instant je croie que tout mes problemes sur cette ordi son corriger grace a toi un gros merci encore
                          2. juste une derniere question pour toi , dis moi ce que je doit avoir ou garder sur mon ordi pour une protection maximal et quel programme merci a l'avance
                            • 1
                            • 2