Rapport HIJACKTHIS

bonjour à tous,
j'ai eu quelques virus mais je les ai supprimer et maintenant mon ordi et un peux lent je pense peut être que j'ai supprimer un composant de vista mais je ne sais pas trop je viens de faire un rapport avec HIJACKTHIS et je voudrais savoir si quelqu'un pourrait me dire si mon ordinateur est infectée .
je vous remerci d'avance

voici le rapport :
****************

Logfile of HijackThis v1.99.1
Scan saved at 16:54:10, on 26/08/2007
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Packard Bell\FIJI\ABoard.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Windows\PixArt\Pac207\Monitor.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
C:\Windows\ehome\ehtray.exe
C:\Users\Aurélie\AppData\Local\Microsoft\lawchfsxvc.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Windows\System32\mobsync.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [ACTIVBOARD] C:\Program Files\Packard Bell\FIJI\aboard.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [lawchfsxvc] c:\users\aurélie\appdata\local\microsoft\lawchfsxvc.exe lawchfsxvc
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u2-windows-i586-jc.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: R54G Wireless Service - Unknown owner - C:\Program Files\Wireless 802.11g Monitor\WLService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

************************
Configuration: Windows XP
Firefox 2.0.0.6

98 réponses

Résumé de la discussion

Un utilisateur se demande si son ordinateur est encore infecté après avoir supprimé des virus et partagé un rapport HijackThis détaillé, et sollicite une analyse des éléments suspects relevés dans le fichier. Plusieurs symptômes et éléments du rapport pointent des modules potentiellement indésirables, notamment des extensions et services lancés au démarrage, des BHO et des entrées de registre, nécessitant une évaluation prudente. Des échanges suggèrent d'utiliser Avast et de vérifier les éléments restants, en évitant des suppressions précipitées et en convertissant les indicateurs suspects du log en actions adaptées. En cas d'absence d'amélioration, la suite propose une analyse système complète et la vérification des programmes installés, sur les tâches planifiées et les services suspects pour repérer des restes non détectés.

Bobot (l’IA à votre service)
  1. salut anthony,

    Fermes toutes tes applications et ton navigateur.
    Relance HiJackthis et coches les lignes suivante et Fix Checked.

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe

    Avec quoi as tu supprimé ces virus?
    _____________________________

    Essayez ce scan en ligne (sous IE uniquement, accepter le module activeX) :
    Bitdefender http://www.bitdefender.fr/scan_fr/scan8/ie.html
    S'il trouve quelque chose colle le log dans ton prochain message.
    _____________________________

    Si j'étais toi je me débarrasserais de Avast, ce n'est malheureusement plus un bon AV gratuit, sur le marché actuellement Antivir de Avira est bien meilleur même que les gros Norton, McAfee, Panda, il est en anglais mais très simple d'utilisation (comparable à BitDefender et sur certains points meilleur).
    https://www.avira.com/

    Le tutoriel pour Antivir ici :
    http://forum.malekal.com/ftopic4192.php

    Et ici un comparatif intéressant Avast-Antivir:
    http://forum.malekal.com/ftopic3528.php
    Et 2 autres comparatifs complet:
    http://www.pcinpact.com/actu/news/31149-Antivirus-resultats-dun-test-de-performances.htm
    https://www.av-comparatives.org/

    A+

    Denis
    0
    1. ok je vais faire ce que tu me dis
      pour les virus je les ai tous supprimer avec avast.
      le scan avec Bitdefender dur assez longtemps je crouis , non ??
      il est mieu que je change tout de suite d'anti virus ou j'attends d'avoir fais tous les scan??
      et je voudrais savoir si au moment où j'enlève avast ,donc je ne suis plus protèger, et le temps que je mets pour mettre Antivir je ne risque aucune infection?? parce que j'ai une alice box donc je suis connecté dès que mon ordinateur est allumé, je dois la débranché??
      0
      1. boujour DeNisCoOl,
        je ne suis pas arrivé à lancer le scan Bitdefender je ne sais pas pourquoi .
        que me conseilles tu ??
        merci
        0
        1. Salut

          E - Scan online avec BitDefender
          Fais ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2 (en haut) va se mettre à clignoter, clic dessus et choisis "accepter l'active X" pour faire fonctionner le scan anti-virus.
          Une fois qu'il a terminé colle le rapport ici stp
          https://www.bitdefender.com/toolbox/
          Copie/Colle le rapport

          0
          1. salut,

            Marci Marie ;-)
            J'oublies toujours de préciser IE.

            A+

            Denis
            0
            1. lol

              Prends le mon lien si tu eux
              par contre il est sous Vista l'internaute
              A+
              0
              1. bonjour ^^Marie^^, je n'arrive ni a faire le scan BitDefender ni celui de genproc
                il me dit que c'est impossible .
                je suis sous vista peux être que sa a une influance ??
                0
                1. que dois-je faire si aucun scan ne marche ???
                  0
                  1. DeNisCoOl, va arriver
                    Faut patienter
                    J'Peux pas être partout
                    0
                    1. ok merci beaucoup d'êter là.
                      j'attend DeNisCoOl
                      0
                  2. Bitdefender ne fonctionne pas sous Vista
                    Refais un log hitjathis
                    stp
                    0
                    1. bonjour voici le log

                      Logfile of HijackThis v1.99.1
                      Scan saved at 16:54:10, on 26/08/2007
                      Platform: Unknown Windows (WinNT 6.00.1904)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16512)

                      Running processes:
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\RtHDVCpl.exe
                      C:\Program Files\Packard Bell\FIJI\ABoard.exe
                      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                      C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                      C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                      C:\Windows\PixArt\Pac207\Monitor.exe
                      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                      C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                      C:\Windows\ehome\ehtray.exe
                      C:\Users\Aurélie\AppData\Local\Microsoft\lawchfsxvc.exe
                      C:\Windows\ehome\ehmsas.exe
                      C:\Program Files\MSN Messenger\msnmsgr.exe
                      C:\Windows\System32\mobsync.exe
                      C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
                      C:\Windows\system32\SearchFilterHost.exe
                      C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                      O1 - Hosts: ::1 localhost
                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                      O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                      O4 - HKLM\..\Run: [ACTIVBOARD] C:\Program Files\Packard Bell\FIJI\aboard.exe
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                      O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
                      O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                      O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                      O4 - HKCU\..\Run: [lawchfsxvc] c:\users\aurélie\appdata\local\microsoft\lawchfsxvc.exe lawchfsxvc
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                      O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
                      O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
                      O11 - Options group: [INTERNATIONAL] International*
                      O13 - Gopher Prefix:
                      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u2-windows-i586-jc.cab
                      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                      O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                      O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                      O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                      O23 - Service: R54G Wireless Service - Unknown owner - C:\Program Files\Wireless 802.11g Monitor\WLService.exe
                      O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                      O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                      O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                      O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                      O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
                      O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
                      0
                      1. j'ai eu quelques virus mais je les ai supprimer
                        Tu as fait quoi exactement ???

                        Essaie ça

                        Télécharge SmitfraudFix
                        Ouvre ce lien (merci a S!RI pour ce programme)
                        http://siri.urz.free.fr/Fix/SmitfraudFix.php
                        et télécharge SmitfraudFix.exe.

                        Regarde le tuto

                        Exécute le en choisissant l’option 1,
                        il va générer un rapport
                        Copie/colle le sur le poste stp.
                        0
                        1. voici le scan

                          SmitFraudFix v2.217

                          Scan done at 10:03:29,99, 28/08/2007
                          Run from C:\Windows\SmitfraudFix
                          OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                          The filesystem type is NTFS
                          Fix run in normal mode

                          »»»»»»»»»»»»»»»»»»»»»»»» Process

                          C:\Windows\system32\csrss.exe
                          C:\Windows\system32\wininit.exe
                          C:\Windows\system32\csrss.exe
                          C:\Windows\system32\services.exe
                          C:\Windows\system32\lsass.exe
                          C:\Windows\system32\lsm.exe
                          C:\Windows\system32\winlogon.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\SLsvc.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\System32\ZoneLabs\vsmon.exe
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\Explorer.EXE
                          C:\Windows\System32\spoolsv.exe
                          C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\system32\svchost.exe
                          C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                          C:\Windows\system32\svchost.exe
                          C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\system32\SearchIndexer.exe
                          C:\Windows\system32\WUDFHost.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\RtHDVCpl.exe
                          C:\Program Files\Packard Bell\FIJI\ABoard.exe
                          C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                          C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                          C:\Windows\PixArt\Pac207\Monitor.exe
                          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                          C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
                          C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                          C:\Windows\ehome\ehtray.exe
                          C:\Users\Aurélie\AppData\Local\Microsoft\lawchfsxvc.exe
                          C:\Windows\ehome\ehmsas.exe
                          C:\Program Files\MSN Messenger\msnmsgr.exe
                          C:\Program Files\MSN Messenger\usnsvc.exe
                          C:\Program Files\AntiVir PersonalEdition Classic\avscan.exe
                          C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
                          C:\Windows\system32\cmd.exe
                          C:\Windows\system32\conime.exe
                          C:\Windows\system32\wbem\wmiprvse.exe

                          »»»»»»»»»»»»»»»»»»»»»»»» hosts

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                          C:\Windows\system32\sysmain.dll FOUND !

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Aur‚lie

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Aur‚lie\Application Data

                          »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\AURLIE~1\FAVORI~1

                          »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                          »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                          »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                          !!!Attention, following keys are not inevitably infected!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                          !!!Attention, following keys are not inevitably infected!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                          "AppInit_DLLs"=""
                          "LoadAppInit_DLLs"=dword:00000001

                          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                          !!!Attention, following keys are not inevitably infected!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                          »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                          »»»»»»»»»»»»»»»»»»»»»»»» DNS

                          Description: RT73 USB Wireless LAN Card #3
                          DNS Server Search Order: 192.168.1.1

                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{578DD687-1B0B-4E39-A5FA-B170EDAEEB72}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{578DD687-1B0B-4E39-A5FA-B170EDAEEB72}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS3\Services\Tcpip\..\{578DD687-1B0B-4E39-A5FA-B170EDAEEB72}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                          »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                          »»»»»»»»»»»»»»»»»»»»»»»» End
                          0
                          1. Démarre en mode sans échec :
                            Pour cela, tu tapotes la touche F8 ((Si F8 ne marche pas utilise la touche F5)).
                            dès le début de l’allumage du pc sans t’arrêter.
                            Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                            Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                            ----------------------------------------------------------------------------
                            Relance le programme Smitfraud,
                            Cette fois choisit l’option 2,
                            répond oui à tous ;
                            Sauvegarde le rapport,
                            Redémarre en mode normal,
                            Copie/colle le rapport sauvegardé sur le forum

                            Refais un log Hitjackthis
                            0
                            1. Pour répondre a ta question : donc des virus sont entrés dans mon pc avast ma conseillé de les supprimer donc j'ai fais cela mais je n'ai pas noté les virus désolé
                              0
                              1. voici le log de Smitfraud

                                SmitFraudFix v2.217

                                Rapport fait à 11:13:11,10, 28/08/2007
                                Executé à partir de C:\Users\Aur‚lie\Desktop\SmitfraudFix
                                OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                                Le type du système de fichiers est NTFS
                                Fix executé en mode sans echec

                                »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                SrchSTS.exe by S!Ri
                                Search SharedTaskScheduler's .dll

                                »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                127.0.0.1 localhost
                                ::1 localhost

                                »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                                GenericRenosFix by S!Ri

                                »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                                Problème suppression C:\Windows\system32\sysmain.dll

                                »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                HKLM\SYSTEM\CCS\Services\Tcpip\..\{578DD687-1B0B-4E39-A5FA-B170EDAEEB72}: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS1\Services\Tcpip\..\{578DD687-1B0B-4E39-A5FA-B170EDAEEB72}: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS3\Services\Tcpip\..\{578DD687-1B0B-4E39-A5FA-B170EDAEEB72}: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                                »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                                »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                                Nettoyage terminé.

                                »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                SrchSTS.exe by S!Ri
                                Search SharedTaskScheduler's .dll

                                »»»»»»»»»»»»»»»»»»»»»»»» Reboot

                                Problème suppression C:\Windows\system32\sysmain.dll

                                »»»»»»»»»»»»»»»»»»»»»»»» Fin

                                ******************************************************
                                voici le log de HijackThis

                                Logfile of HijackThis v1.99.1
                                Scan saved at 16:54:10, on 26/08/2007
                                Platform: Unknown Windows (WinNT 6.00.1904)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16512)

                                Running processes:
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\Explorer.EXE
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\RtHDVCpl.exe
                                C:\Program Files\Packard Bell\FIJI\ABoard.exe
                                C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                                C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                                C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                                C:\Windows\PixArt\Pac207\Monitor.exe
                                C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                                C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                                C:\Windows\ehome\ehtray.exe
                                C:\Users\Aurélie\AppData\Local\Microsoft\lawchfsxvc.exe
                                C:\Windows\ehome\ehmsas.exe
                                C:\Program Files\MSN Messenger\msnmsgr.exe
                                C:\Windows\System32\mobsync.exe
                                C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
                                C:\Windows\system32\SearchFilterHost.exe
                                C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                O1 - Hosts: ::1 localhost
                                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                O4 - HKLM\..\Run: [ACTIVBOARD] C:\Program Files\Packard Bell\FIJI\aboard.exe
                                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                                O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
                                O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                                O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                O4 - HKCU\..\Run: [lawchfsxvc] c:\users\aurélie\appdata\local\microsoft\lawchfsxvc.exe lawchfsxvc
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                                O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
                                O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
                                O11 - Options group: [INTERNATIONAL] International*
                                O13 - Gopher Prefix:
                                O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u2-windows-i586-jc.cab
                                O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                                O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                                O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                                O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                                O23 - Service: R54G Wireless Service - Unknown owner - C:\Program Files\Wireless 802.11g Monitor\WLService.exe
                                O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                                O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                                O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                                O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
                                O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
                                0
                                • 1
                                • 2
                                • 3
                                • 4
                                • 5