Mal/heuri-e... Mal/ofbus-A... Troj/Busky-gen

Bonjour,

Mal/heuri-e... Mal/ofbus-A... Troj/Busky-gen (voila ce que Spy-sweeper me trouve lorsque je fais un scan complet)

Spy-Sweeper me dit qu'il arrivé a maitrisé le (Troj Busky-gen) et a le maitre en quarantaine mais pas les deux (Mal), cependant le trojan revient apres un redémarrage de mon PC. et J'ai un message disant qu'il ne parvient pas a mettre les Mal/heuri-e, Mal/ofbus-A en quarantaine.
Ca fait des jours la et J'arrive a rien et mon Pc est hyper lent :(( aidez-moi svp ! merci d'avance.
Configuration: Windows XP
Firefox 2.0.0.8


J'ai fait un scan de HijackThis puisque il semblerait que cet outil soit génial et indispensable ici dont je post le résultat... :

Logfile of HijackThis v1.99.1
Scan saved at 01:01:20, on 2007-10-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINNT\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\JEAN-M~1\SAUVEG~1\SAUV~1.BEL\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\PATRIC~1\LOCALS~1\Temp\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?pc=mssh&form=msshhp&ocid=onepro&homepage=http%3a%2f%2fwww.microsoft.com%2fisapi%2fredir.dll%3fprd%3d{SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 211.250.145.3:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {0DFD8F30-0C46-E79A-B048-93D5BF3D94A4} - SAPSTR.dll (file missing)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINNT\system32\
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [MSConfig] "C:\WINNT\PCHealth\HelpCtr\Binaries\MSConfig.exe" /auto
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ca\msntabres.dll.mui/229?58abea2839d149c6a945c98ff1fddd4a
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ca\msntabres.dll.mui/230?58abea2839d149c6a945c98ff1fddd4a
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\shdocvw.dll
O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O17 - HKLM\System\CCS\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{A0A2EC58-1B20-4221-B4B1-BE24C7A93743}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{FA641A12-2A06-4258-A899-391029DDE196}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.153 85.255.112.12
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINNT\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINNT\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINNT\system32\WPDShServiceObj.dll
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

60 réponses

Résumé de la discussion

Plusieurs symptômes signalent une infection complexe : un malware Trojan Mal/Heuri-E et Mal/ofbus-A résistant aux quarantines de Spy Sweeper et ralentissant fortement le système sous Windows XP. Des interventions préconisées incluent une relance de HijackThis en mode scan uniquement et la correction des entrées critiques, notamment O17 et les paramètres DNS, pour restaurer les paramètres réseau. D'autres solutions évoquent des outils comme SmitFraudFix et des vérifications approfondies du comportement des services et des processus afin d'identifier les composantes actives et de nettoyer les autoruns. En cas de persistance, le fil souligne que, malgré les nettoyages, une réinstallation complète ou une remise à zéro du système peut devenir nécessaire, avec une attention particulière à la sécurité et aux sauvegardes.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonjour,

    Ta version d'hijackthis est obsolète.

    Supprime la via le panneau de configuration, ajout/suppression de programmes.

    Clique sur ce lien
    http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
    pour télécharger le fichier d'installation d'HijackThis.

    Enregistre HJTInstall.exe sur ton bureau.

    Double-clique sur HJTInstall.exe pour lancer le programme

    Par défaut, il s'installera là :
    C:\Program Files\Trend Micro\HijackThis

    Accepte la license en cliquant sur le bouton "I Accept"

    Choisis Do a scan only

    Coche la case devant les lignes suivantes

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 211.250.145.3:8080
    R3 - URLSearchHook: (no name) - {0DFD8F30-0C46-E79A-B048-93D5BF3D94A4} - SAPSTR.dll (file missing)
    F2 - REG:system.ini: Shell=Explorer.exe C:\WINNT\system32\
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

    Ferme toutes les fenêtres (hormis HijackThis), y compris ton navigateur.

    Clique sur fix checked.

    Ferme Hijackthis.

    Tutoriaux : http://pageperso.aol.fr/balltrap34/demohijack.htm (ne fixe rien pour le moment !!)
    http://cybersecurite.xooit.com/t138-HijackThis-2-0-2.htm

    Ensuite

    Imprime ces instructions car il va y avoir un redémarrage de l'ordinateur.

    * Télécharge FixWareout de ce site sur le bureau:
    http://downloads.subratam.org/Fixwareout.exe
    hxxp://swandog46.geekstogo.com/Fixwareout.exe

    * Lance le fix: clique sur Next, puis Install, puis assure toi que "Run fixit" est activé puis clique sur Finish.
    Le fix va commencer, suis les messages à l'écran. Il te sera demandé de redémarrer ton ordinateur, fais le. Ton système mettra un peu plus de temps au démarrage, c'est normal.

    *Poste (Copie/colle) le contenu du rapport qui va s'afficher à l'écran (report.txt) avec un nouveau rapport HijackThis! dans ta prochaine réponse.
    0
    1. Bonjour,

      Merci beaucoup de ton aide, voici mon rapport Fixwareout :

      Username "Patrick Payeur" - 2007-10-26 19:32:30

      [Fixwareout edited 9/01/2007]

      ~~~~~ Prerun check

      Cache de résolution DNS vidé.
      System was rebooted successfully.

      ~~~~~ Postrun check
      HKLM\SOFTWARE\~\Winlogon\ "system"=""
      ....
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion

      "huhsc" Value deleted
      HKCR\CLSID\{C6A8D02C-4BF2-46FF-AC18-C7A6513A02FA

      }\_h\4 Deleted.
      ....
      ~~~~~ Misc files.
      ....
      ~~~~~ Checking for older varients.
      ....

      C:\Program Files\RegistryCleaner < Found
      Additional tools are recommended.

      ~~~~~ Current runs (hklm hkcu "run" Keys Only)
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\C

      urrentVersion\Run]
      "MSConfig"="\"C:\\WINNT\\PCHealth\\HelpCtr\\Bina

      ries\\MSConfig.exe\" /auto"
      "SpySweeper"="C:\\Program Files\\Webroot\\Spy

      Sweeper\\SpySweeperUI.exe /startintray"

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Cu

      rrentVersion\Run]
      ....
      Hosts file was reset, If you use a custom hosts

      file please replace it...
      ~~~

      -----------------------------------------------------
      et voici mon nouveau rapport HijackThis :
      ----------------------------------------------------
      Merci encore pour ton aide c grandement apprécié =)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:43:16, on 2007-10-26
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINNT\System32\smss.exe
      C:\WINNT\system32\winlogon.exe
      C:\WINNT\system32\services.exe
      C:\WINNT\system32\lsass.exe
      C:\WINNT\system32\svchost.exe
      C:\WINNT\System32\svchost.exe
      C:\WINNT\system32\spoolsv.exe
      C:\WINNT\Explorer.EXE
      C:\WINNT\System32\svchost.exe
      C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
      C:\WINNT\system32\wscntfy.exe
      C:\WINNT\system32\wuauclt.exe
      C:\WINNT\system32\notepad.exe
      C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?pc=mssh&form=msshhp&ocid=onepro&homepage=http%3a%2f%2fwww.microsoft.com%2fisapi%2fredir.dll%3fprd%3d{SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [MSConfig] "C:\WINNT\PCHealth\HelpCtr\Binaries\MSConfig.exe" /auto
      O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'Default user')
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ca\msntabres.dll.mui/229?58abea2839d149c6a945c98ff1fddd4a
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ca\msntabres.dll.mui/230?58abea2839d149c6a945c98ff1fddd4a
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\shdocvw.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\shdocvw.dll
      O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
      O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
      O17 - HKLM\System\CCS\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: NameServer = 208.67.220.220,208.67.222.222
      O17 - HKLM\System\CCS\Services\Tcpip\..\{A0A2EC58-1B20-4221-B4B1-BE24C7A93743}: NameServer = 208.67.220.220,208.67.222.222
      O17 - HKLM\System\CCS\Services\Tcpip\..\{FA641A12-2A06-4258-A899-391029DDE196}: NameServer = 208.67.220.220,208.67.222.222
      O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.153 85.255.112.12
      O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
      O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
      O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
      0
      1. Contributeur sécurité
        Bonjour,

        Va dans Démarrer > Panneau de configuration > Connexions > clique droit sur la connexion > Propriétés > onglet Gestion de réseau
        Mettre en surbrillance Protocole Internet (tcp/ip) puis cliquer sur le bouton Propriétés.
        Dans les options (serveur DNS préféré et serveur DNS auxiliaire) on trouvera une de ces adresses présentes dans le rapport hijackthis en ligne 017 =>(85.255.114.73 85.255.112.227 etc...)

        Pour les éliminer, cocher : "Obtenir les adresses des serveurs DNS automatiquement" puis cliquer 2 fois sur"Ok" et redémarrer le PC.

        Installe un antivirus. Le gratuit le plus performant actuellement est antivir.

        Tuto et lien de téléchargement ici :

        https://www.malekal.com/avira-free-security-antivirus-gratuit/

        Tu sembles ne pas avoir de parefeu contrôlant les connexions sortantes, ce qui est un risque de sécurité.

        Si c'est le cas tu as le choix entre ces deux possibilités :

        Zone Alarm Tuto et lien de téléchargement ici :
        https://www.malekal.com/tutoriel-zonealarm-firewall/

        Kerio Tuto et lien de téléchargement ici :
        http://www.malekal.com/kerio_firewall.php

        Il y en a d'autres que tu peux trouver en ouvrant ce lien :
        http://www.malekal.com/menu_tutorials_logiciels.php

        Il faut que tu désactives le parefeu de Windows (panneau de configuration, parefeu de Windows) après le téléchargement et avant l'installation (déconnecte toi du Net à ce moment là).

        fais unn scan complet avec antivir.

        Poste le" rapport avec u nouveau rapport Hijackthis.

        Compment va l'ordi ?
        0
        1. Bonjour,

          Le lien que tu m'as donné avec antivir ne fonctionnait pas, lorsque j'ai voulu aller le chercher. jai donc fait tout ce que tu m'as demandé mais jai seulement refait un scan avec mon spy sweeper, w/ antivirus.

          Il détecte encore tous les virus, jai installé zone alarm avec l'internet coupé aussi. et mon pc ne va pas mieu qu'avant :(
          je n'ai pas de rapport a vec antivir puisque je l'avais pas mais si tu crois que c'Est nécéssaire et mieu que spysweeper je vais en faire un et t'envoyer le rapport par la suite....

          je t'envoie mon nouveau rapport hijackthis :

          Merci encore pour ton aide.

          --------------------------------------------------------------------------

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 15:52:00, on 2007-10-27
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINNT\System32\smss.exe
          C:\WINNT\system32\winlogon.exe
          C:\WINNT\system32\services.exe
          C:\WINNT\system32\lsass.exe
          C:\WINNT\system32\svchost.exe
          C:\WINNT\System32\svchost.exe
          C:\WINNT\system32\spoolsv.exe
          C:\WINNT\System32\svchost.exe
          C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
          C:\WINNT\Explorer.EXE
          C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
          C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
          C:\WINNT\system32\ZoneLabs\vsmon.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?pc=mssh&form=msshhp&ocid=onepro&homepage=http%3a%2f%2fwww.microsoft.com%2fisapi%2fredir.dll%3fprd%3d{SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O4 - HKLM\..\Run: [MSConfig] "C:\WINNT\PCHealth\HelpCtr\Binaries\MSConfig.exe" /auto
          O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
          O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'Default user')
          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
          O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ca\msntabres.dll.mui/229?58abea2839d149c6a945c98ff1fddd4a
          O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ca\msntabres.dll.mui/230?58abea2839d149c6a945c98ff1fddd4a
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\shdocvw.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\shdocvw.dll
          O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
          O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
          O17 - HKLM\System\CCS\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: NameServer = 208.67.220.220,208.67.222.222
          O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.153 85.255.112.12
          O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
          O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
          O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
          O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
          O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
          0
          1. Re bonjour,

            J'ai un nouveau probleme... voici ce que j'ai lorsque j'essaie d'installer Aviera antivir :

            Extracting eula.txt
            Extracting readme.txt
            Extracting basic\addr_file.html
            Extracting filelist.ini
            Extracting product.ini
            Extracting basic\vista64\avgntflt.inf
            Extracting basic\avipbb.inf
            Extracting basic\ssmdrv.inf
            Extracting basic\avadmin.exe
            Extracting basic\avcenter.exe
            CRC failed in basic\avcenter.exe
            Unexpected end of archive

            =/
            0
            1. Contributeur sécurité
              Re

              imprime ces instructions et déconnecte toi du net pour les mettre en oeuvre.

              1) Relance HijackThis.

              Choisis Do a scan only

              Coche la case devant les lignes suivantes

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm

              Ferme toutes les fenêtres (hormis HijackThis), y compris ton navigateur.

              Clique sur fix checked.

              Ferme Hijackthis.

              2) Relance Fixwareout

              * Lance le fix: clique sur Next, puis Install, puis assure toi que "Run fixit" est activé puis clique sur Finish.
              Le fix va commencer, suis les messages à l'écran. Il te sera demandé de redémarrer ton ordinateur, fais le. Ton système mettra un peu plus de temps au démarrage, c'est normal.

              *Poste (Copie/colle) le contenu du rapport qui va s'afficher à l'écran (report.txt) .

              3)Va dans Démarrer > Panneau de configuration > Connexions > clique droit sur la connexion > Propriétés > onglet Gestion de réseau
              Mettre en surbrillance Protocole Internet (tcp/ip) puis cliquer sur le bouton Propriétés.
              Dans les options (serveur DNS préféré et serveur DNS auxiliaire) on trouvera une de ces adresses présentes dans le rapport hijackthis en ligne 017 =>(85.255.114.73 85.255.112.227 etc...)

              Pour les éliminer, cocher : "Obtenir les adresses des serveurs DNS automatiquement" puis cliquer 2 fois sur"Ok" et redémarrer le PC.

              4) reconnecte toi et poste les rapports avec un nouveau log Hijackthis.

              Dans la foulée, essaye de réinstaller antivir.

              0
              1. merci encore pour tout!!

                jai réussi a downloader antivir un peu plus tard voici mon rapport antivir, je n'ai pas encore fait ce que tu m'as demandé précédament. mais je t'envoie quand meme le rapport que j'ai eu la je vais faire la derniere etape que tu m'as demandé :)

                rapport antivir :

                ----------------------------------------------------
                AntiVir PersonalEdition Classic
                Report file date: 2007年10月27日 16:18

                Scanning for 904194 virus strains and unwanted programs.

                Licensed to: Avira AntiVir PersonalEdition Classic
                Serial number: 0000149996-ADJIE-0001
                Platform: Windows XP
                Windows version: (Service Pack 2) [5.1.2600]
                Username: SYSTEM
                Computer name: SOUS-SOL

                Version information:
                BUILD.DAT : 270 15603 Bytes 2007-09-19 13:32:00
                AVSCAN.EXE : 7.0.6.1 290856 Bytes 2007-08-23 18:16:29
                AVSCAN.DLL : 7.0.6.0 49192 Bytes 2007-08-16 17:23:51
                LUKE.DLL : 7.0.5.3 147496 Bytes 2007-08-14 20:32:47
                LUKERES.DLL : 7.0.6.1 10280 Bytes 2007-08-21 17:35:20
                ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 2007-07-18 20:06:03
                ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 2007-09-13 20:06:03
                ANTIVIR2.VDF : 7.0.0.140 940544 Bytes 2007-10-26 20:06:03
                ANTIVIR3.VDF : 7.0.0.142 3072 Bytes 2007-10-26 20:06:03
                AVEWIN32.DLL : 7.6.0.30 3056128 Bytes 2007-10-27 20:06:03
                AVWINLL.DLL : 1.0.0.7 14376 Bytes 2007-02-26 15:36:26
                AVPREF.DLL : 7.0.2.2 25640 Bytes 2007-07-18 12:39:17
                AVREP.DLL : 7.0.0.1 155688 Bytes 2007-04-16 18:16:24
                AVPACK32.DLL : 7.3.0.15 360488 Bytes 2007-08-03 13:46:00
                AVREG.DLL : 7.0.1.6 30760 Bytes 2007-07-18 12:17:06
                AVARKT.DLL : 1.0.0.20 278568 Bytes 2007-08-28 17:26:33
                AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 2007-07-18 12:10:18
                NETNT.DLL : 7.0.0.0 7720 Bytes 2007-03-08 16:09:42
                RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 2007-08-07 17:38:13
                RCTEXT.DLL : 7.0.62.0 86056 Bytes 2007-08-21 17:50:37
                SQLITE3.DLL : 3.3.17.1 339968 Bytes 2007-07-23 14:37:21

                Configuration settings for the scan:
                Jobname..........................: Complete system scan
                Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                Logging..........................: low
                Primary action...................: interactive
                Secondary action.................: ignore
                Scan master boot sector..........: off
                Scan boot sector.................: on
                Boot sectors.....................: C:,
                Scan memory......................: on
                Process scan.....................: on
                Scan registry....................: on
                Search for rootkits..............: off
                Scan all files...................: Intelligent file selection
                Scan archives....................: on
                Recursion depth..................: 20
                Smart extensions.................: on
                Macro heuristic..................: on
                File heuristic...................: medium

                Start of the scan: 2007年10月27日 16:18

                The scan of running processes will be started
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                Scan process 'zlclient.exe' - '0' Module(s) have been scanned
                Scan process 'explorer.exe' - '1' Module(s) have been scanned
                Scan process 'SpySweeper.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'sched.exe' - '1' Module(s) have been scanned
                Scan process 'avguard.exe' - '1' Module(s) have been scanned
                Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                Scan process 'vsmon.exe' - '0' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'lsass.exe' - '1' Module(s) have been scanned
                Scan process 'services.exe' - '1' Module(s) have been scanned
                Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'smss.exe' - '1' Module(s) have been scanned
                20 processes with 20 modules were scanned

                Start scanning boot sectors:
                Boot sector 'C:\'
                [NOTE] No virus was found!

                Starting to scan the registry.
                The registry was scanned ( '20' files ).

                Starting the file scan:

                Begin scan in 'C:\'
                C:\hiberfil.sys
                [WARNING] The file could not be opened!
                C:\pagefile.sys
                [WARNING] The file could not be opened!
                C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Quarantine\{00000E8A-0000-0000-CCA6-47071AA99E9C}\DATA.CAB
                [0] Archive type: CAB (Microsoft)
                --> RESOURCE1
                [DETECTION] Contains detection pattern of the dropper DR/Gator.3202
                [INFO] The file was deleted!
                C:\Documents and Settings\All Users\Application Data\SecTaskMan\svchost.exe.q_1C321C6_q
                [DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/VB.bco.128 Backdoor server programs
                [INFO] The file was deleted!
                C:\Documents and Settings\All Users\Application Data\SecTaskMan\vmfvaxe.dll.q_63A1401_q
                [DETECTION] Is the Trojan horse TR/Vundo.Gen
                [INFO] The file was deleted!
                C:\Documents and Settings\All Users\Documents\Sauvegarde03-03-03\EXE\babylon31.exe
                [0] Archive type: ZIP SFX (self extracting)
                --> cd_install_167.exe
                [DETECTION] Contains detection pattern of the dropper DR/Cydoor.A.18
                [INFO] The file was deleted!
                C:\Documents and Settings\Jean-Marie Payeur\Sauvegarde03-03-03\EXE\babylon31.exe
                [0] Archive type: ZIP SFX (self extracting)
                --> cd_install_167.exe
                [DETECTION] Contains detection pattern of the dropper DR/Cydoor.A.18
                [INFO] The file was deleted!
                C:\Documents and Settings\Julie Payeur\Local Settings\Temporary Internet Files\Content.IE5\TBJFT50E\upAYB_unk[6].int
                [DETECTION] Is the Trojan horse TR/Dldr.Swizzor.DV
                [INFO] The file was deleted!
                C:\Documents and Settings\Patrick Payeur\Local Settings\Application Data\jgfihob.dll
                [DETECTION] Is the Trojan horse TR/Vundo.Gen
                [INFO] The file was deleted!
                C:\WINNT\svchost.exe
                [DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/VB.bco.128 Backdoor server programs
                [INFO] The file was deleted!
                C:\WINNT\system32\drivers\sptd.sys
                [WARNING] The file could not be opened!

                End of the scan: 2007年10月27日 23:07
                Used time: 6:48:47 min

                The scan has been done completely.

                11725 Scanning directories
                377060 Files were scanned
                8 viruses and/or unwanted programs were found
                0 Files were classified as suspicious:
                8 files were deleted
                0 files were repaired
                0 files were moved to quarantine
                0 files were renamed
                3 Files cannot be scanned
                377052 Files not concerned
                8470 Archives were scanned
                3 Warnings
                4 Notes
                0
                1. Contributeur sécurité
                  Bonjour,

                  je suppose que tu continueras à ton réveil lol.

                  En tout cas c'est une bonne nouvelle et antivir a bien travaillé;
                  0
                  1. Bonjour,
                    oui ma copine voulait plus que je sois sur mon pc hier soir ^^

                    Pour l'étape de ma gestion de réseau il semblerait que depuis la derniere fois j'étais encore en "obtenir les adresses des serveurs automatiquement"

                    jvoulais seulement t'en faire part :)

                    merci encore pour tout!

                    ... alors voici mon report de fixwareout, suivi d'un nouveau rapport HijackThis :

                    Username "Patrick Payeur" - 2007-10-28 8:26:27 [Fixwareout edited 9/01/2007]

                    ~~~~~ Prerun check

                    Cache de résolution DNS vidé.
                    System was rebooted successfully.

                    ~~~~~ Postrun check
                    HKLM\SOFTWARE\~\Winlogon\ "system"=""
                    ....
                    ....
                    ~~~~~ Misc files.
                    ....
                    ~~~~~ Checking for older varients.
                    ....

                    C:\Program Files\RegistryCleaner < Found
                    Additional tools are recommended.

                    ~~~~~ Current runs (hklm hkcu "run" Keys Only)
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "MSConfig"="C:\\WINNT\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"
                    "ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
                    "avgnt"="\"C:\\Program Files\\Avira\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min"
                    "SpySweeper"="C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeperUI.exe /startintray"

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    ....
                    Hosts file was reset, If you use a custom hosts file please replace it...
                    ~~~~~ End report ~~~~~

                    -------------------------------------------------------------------------------------
                    Rapport HijackThis
                    -------------------------------------------------------------------------------------

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 08:40:56, on 2007-10-28
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                    Boot mode: Normal

                    Running processes:
                    C:\WINNT\System32\smss.exe
                    C:\WINNT\system32\winlogon.exe
                    C:\WINNT\system32\services.exe
                    C:\WINNT\system32\lsass.exe
                    C:\WINNT\system32\svchost.exe
                    C:\WINNT\System32\svchost.exe
                    C:\WINNT\system32\ZoneLabs\vsmon.exe
                    C:\WINNT\system32\spoolsv.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    C:\WINNT\Explorer.EXE
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    C:\WINNT\System32\svchost.exe
                    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\WINNT\system32\NOTEPAD.EXE
                    C:\WINNT\system32\wuauclt.exe
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?pc=mssh&form=msshhp&ocid=onepro&homepage=http%3a%2f%2fwww.microsoft.com%2fisapi%2fredir.dll%3fprd%3d{SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                    O4 - HKLM\..\Run: [MSConfig] "C:\WINNT\PCHealth\HelpCtr\Binaries\MSConfig.exe" /auto
                    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                    O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'Default user')
                    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ca\msntabres.dll.mui/229?58abea2839d149c6a945c98ff1fddd4a
                    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ca\msntabres.dll.mui/230?58abea2839d149c6a945c98ff1fddd4a
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\shdocvw.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\shdocvw.dll
                    O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
                    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
                    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: NameServer = 208.67.220.220,208.67.222.222
                    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.153 85.255.112.12
                    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
                    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
                    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
                    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
                    O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                    0
                    1. Contributeur sécurité
                      Re,

                      Ouvre ce lien (merci a S!RI pour ce programme). http://siri.urz.free.fr/Fix/SmitfraudFix.php
                      et télécharge SmitfraudFix.exe.

                      Regarde le tuto
                      Exécute le en choisissant l’option 1, il va générer un rapport
                      Copie/colle le sur le poste stp.
                      0
                      1. Bonjour,

                        merci de répondre aussi vite !
                        voici mon rapport de smitfraudfix :

                        SmitFraudFix v2.242

                        Rapport fait à 12:36:44,54, 2007-10-28
                        Executé à partir de C:\Documents and Settings\Patrick Payeur\Bureau\SmitfraudFix
                        OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                        Le type du système de fichiers est NTFS
                        Fix executé en mode normal

                        »»»»»»»»»»»»»»»»»»»»»»»» Process

                        C:\WINNT\System32\smss.exe
                        C:\WINNT\system32\winlogon.exe
                        C:\WINNT\system32\services.exe
                        C:\WINNT\system32\lsass.exe
                        C:\WINNT\system32\svchost.exe
                        C:\WINNT\System32\svchost.exe
                        C:\WINNT\system32\ZoneLabs\vsmon.exe
                        C:\WINNT\system32\spoolsv.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        C:\WINNT\Explorer.EXE
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        C:\WINNT\System32\svchost.exe
                        C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                        C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\WINNT\system32\cmd.exe

                        »»»»»»»»»»»»»»»»»»»»»»»» hosts

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\Web

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system32

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system32\LogFiles

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Patrick Payeur

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Patrick Payeur\Application Data

                        »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\PATRIC~1\Favoris

                        »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                        C:\Program Files\RegistryCleaner\ PRESENT !

                        »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                        »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                        »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                        "AppInit_DLLs"=""

                        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                        "system"=""

                        »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                        »»»»»»»»»»»»»»»»»»»»»»»» DNS

                        Description: Intel(R) PRO/100 VE Network Connection - Miniport d'ordonnancement de paquets
                        DNS Server Search Order: 192.168.0.1

                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{35DFB68E-305F-40ED-A240-D04ACDD59BB5}: DhcpNameServer=208.67.220.220,208.67.222.222
                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: DhcpNameServer=208.67.220.220,208.67.222.222
                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: NameServer=208.67.220.220,208.67.222.222
                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{A0A2EC58-1B20-4221-B4B1-BE24C7A93743}: DhcpNameServer=192.168.0.1
                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{FA641A12-2A06-4258-A899-391029DDE196}: DhcpNameServer=208.67.220.220,208.67.222.222
                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{35DFB68E-305F-40ED-A240-D04ACDD59BB5}: DhcpNameServer=85.255.116.153,85.255.112.12
                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: DhcpNameServer=85.255.116.153,85.255.112.12
                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: NameServer=85.255.116.153,85.255.112.12
                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{A0A2EC58-1B20-4221-B4B1-BE24C7A93743}: DhcpNameServer=192.168.0.1
                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{A0A2EC58-1B20-4221-B4B1-BE24C7A93743}: NameServer=85.255.116.153,85.255.112.12
                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{FA641A12-2A06-4258-A899-391029DDE196}: DhcpNameServer=85.255.116.153,85.255.112.12
                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{FA641A12-2A06-4258-A899-391029DDE196}: NameServer=85.255.116.153,85.255.112.12
                        HKLM\SYSTEM\CS2\Services\Tcpip\..\{35DFB68E-305F-40ED-A240-D04ACDD59BB5}: DhcpNameServer=208.67.220.220,208.67.222.222
                        HKLM\SYSTEM\CS2\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: DhcpNameServer=208.67.220.220,208.67.222.222
                        HKLM\SYSTEM\CS2\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: NameServer=208.67.220.220,208.67.222.222
                        HKLM\SYSTEM\CS2\Services\Tcpip\..\{A0A2EC58-1B20-4221-B4B1-BE24C7A93743}: DhcpNameServer=192.168.0.1
                        HKLM\SYSTEM\CS2\Services\Tcpip\..\{FA641A12-2A06-4258-A899-391029DDE196}: DhcpNameServer=208.67.220.220,208.67.222.222
                        HKLM\SYSTEM\CS3\Services\Tcpip\..\{35DFB68E-305F-40ED-A240-D04ACDD59BB5}: DhcpNameServer=208.67.220.220,208.67.222.222
                        HKLM\SYSTEM\CS3\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: DhcpNameServer=208.67.220.220,208.67.222.222
                        HKLM\SYSTEM\CS3\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: NameServer=208.67.220.220,208.67.222.222
                        HKLM\SYSTEM\CS3\Services\Tcpip\..\{A0A2EC58-1B20-4221-B4B1-BE24C7A93743}: DhcpNameServer=192.168.0.1
                        HKLM\SYSTEM\CS3\Services\Tcpip\..\{FA641A12-2A06-4258-A899-391029DDE196}: DhcpNameServer=208.67.220.220,208.67.222.222
                        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
                        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222
                        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
                        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=85.255.116.153 85.255.112.12
                        HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
                        HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222
                        HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
                        HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                        »»»»»»»»»»»»»»»»»»»»»»»» Fin
                        0
                        1. Contributeur sécurité
                          Re,

                          Démarre en mode sans échec :
                          Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
                          Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                          Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                          (Si F8 ne marche pas utilise la touche F5).
                          ----------------------------------------------------------------------------
                          Relance le programme Smitfraud,
                          Cette fois choisit l’option 2, répond oui a tous ;
                          Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

                          Remets aussi un log Hijackthis.
                          0
                          1. re ! voici mon rapport smithfraud suivi de mon hijackthis :)

                            SmitFraudFix v2.242

                            Rapport fait à 15:13:29,14, 2007-10-28
                            Executé à partir de C:\Documents and Settings\Patrick Payeur\Bureau\virusdelete\SmitfraudFix
                            OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                            Le type du système de fichiers est NTFS
                            Fix executé en mode sans echec

                            »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                            SrchSTS.exe by S!Ri
                            Search SharedTaskScheduler's .dll

                            »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                            »»»»»»»»»»»»»»»»»»»»»»»» hosts

                            127.0.0.1 localhost

                            »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                            S!Ri's WS2Fix: LSP not Found.
                            »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                            GenericRenosFix by S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                            C:\Program Files\RegistryCleaner\ supprimé

                            »»»»»»»»»»»»»»»»»»»»»»»» DNS

                            HKLM\SYSTEM\CCS\Services\Tcpip\..\{35DFB68E-305F-40ED-A240-D04ACDD59BB5}: DhcpNameServer=208.67.220.220,208.67.222.222
                            HKLM\SYSTEM\CCS\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: DhcpNameServer=208.67.220.220,208.67.222.222
                            HKLM\SYSTEM\CCS\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: NameServer=208.67.220.220,208.67.222.222
                            HKLM\SYSTEM\CCS\Services\Tcpip\..\{A0A2EC58-1B20-4221-B4B1-BE24C7A93743}: DhcpNameServer=192.168.0.1
                            HKLM\SYSTEM\CCS\Services\Tcpip\..\{FA641A12-2A06-4258-A899-391029DDE196}: DhcpNameServer=208.67.220.220,208.67.222.222
                            HKLM\SYSTEM\CS1\Services\Tcpip\..\{35DFB68E-305F-40ED-A240-D04ACDD59BB5}: DhcpNameServer=85.255.116.153,85.255.112.12
                            HKLM\SYSTEM\CS1\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: DhcpNameServer=85.255.116.153,85.255.112.12
                            HKLM\SYSTEM\CS1\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: NameServer=85.255.116.153,85.255.112.12
                            HKLM\SYSTEM\CS1\Services\Tcpip\..\{A0A2EC58-1B20-4221-B4B1-BE24C7A93743}: DhcpNameServer=192.168.0.1
                            HKLM\SYSTEM\CS1\Services\Tcpip\..\{A0A2EC58-1B20-4221-B4B1-BE24C7A93743}: NameServer=85.255.116.153,85.255.112.12
                            HKLM\SYSTEM\CS1\Services\Tcpip\..\{FA641A12-2A06-4258-A899-391029DDE196}: DhcpNameServer=85.255.116.153,85.255.112.12
                            HKLM\SYSTEM\CS1\Services\Tcpip\..\{FA641A12-2A06-4258-A899-391029DDE196}: NameServer=85.255.116.153,85.255.112.12
                            HKLM\SYSTEM\CS2\Services\Tcpip\..\{35DFB68E-305F-40ED-A240-D04ACDD59BB5}: DhcpNameServer=208.67.220.220,208.67.222.222
                            HKLM\SYSTEM\CS2\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: DhcpNameServer=208.67.220.220,208.67.222.222
                            HKLM\SYSTEM\CS2\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: NameServer=208.67.220.220,208.67.222.222
                            HKLM\SYSTEM\CS2\Services\Tcpip\..\{A0A2EC58-1B20-4221-B4B1-BE24C7A93743}: DhcpNameServer=192.168.0.1
                            HKLM\SYSTEM\CS2\Services\Tcpip\..\{FA641A12-2A06-4258-A899-391029DDE196}: DhcpNameServer=208.67.220.220,208.67.222.222
                            HKLM\SYSTEM\CS3\Services\Tcpip\..\{35DFB68E-305F-40ED-A240-D04ACDD59BB5}: DhcpNameServer=208.67.220.220,208.67.222.222
                            HKLM\SYSTEM\CS3\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: DhcpNameServer=208.67.220.220,208.67.222.222
                            HKLM\SYSTEM\CS3\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: NameServer=208.67.220.220,208.67.222.222
                            HKLM\SYSTEM\CS3\Services\Tcpip\..\{A0A2EC58-1B20-4221-B4B1-BE24C7A93743}: DhcpNameServer=192.168.0.1
                            HKLM\SYSTEM\CS3\Services\Tcpip\..\{FA641A12-2A06-4258-A899-391029DDE196}: DhcpNameServer=208.67.220.220,208.67.222.222
                            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
                            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222
                            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
                            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=85.255.116.153 85.255.112.12
                            HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
                            HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222
                            HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
                            HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222

                            »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                            "system"=""

                            »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                            Nettoyage terminé.

                            »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                            SrchSTS.exe by S!Ri
                            Search SharedTaskScheduler's .dll

                            »»»»»»»»»»»»»»»»»»»»»»»» Fin

                            ____________________________________________________________

                            hijackthis

                            ____________________________________________________________

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 18:17:36, on 2007-10-28
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                            Boot mode: Normal

                            Running processes:
                            C:\WINNT\System32\smss.exe
                            C:\WINNT\system32\winlogon.exe
                            C:\WINNT\system32\services.exe
                            C:\WINNT\system32\lsass.exe
                            C:\WINNT\system32\svchost.exe
                            C:\WINNT\System32\svchost.exe
                            C:\WINNT\system32\ZoneLabs\vsmon.exe
                            C:\WINNT\system32\spoolsv.exe
                            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                            C:\WINNT\System32\svchost.exe
                            C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                            C:\WINNT\Explorer.EXE
                            C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                            C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
                            C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?pc=mssh&form=msshhp&ocid=onepro&homepage=http%3a%2f%2fwww.microsoft.com%2fisapi%2fredir.dll%3fprd%3d{SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
                            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                            O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                            O4 - HKLM\..\Run: [MSConfig] "C:\WINNT\PCHealth\HelpCtr\Binaries\MSConfig.exe" /auto
                            O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                            O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
                            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'Default user')
                            O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                            O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                            O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ca\msntabres.dll.mui/229?58abea2839d149c6a945c98ff1fddd4a
                            O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ca\msntabres.dll.mui/230?58abea2839d149c6a945c98ff1fddd4a
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\shdocvw.dll
                            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\shdocvw.dll
                            O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
                            O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
                            O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
                            O17 - HKLM\System\CCS\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: NameServer = 208.67.220.220,208.67.222.222
                            O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.153 85.255.112.12
                            O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
                            O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
                            O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
                            O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                            O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
                            O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                            0
                            1. Contributeur sécurité
                              Re,

                              toujours des traces de l'infection wareout.

                              Tu relances fixwareout, puis tu postes le rapport avec un nouveau log Hijackthis.
                              0
                              1. rebonjour , voici mes 2 rapport fixwarout suivi de hijackthis

                                encore merci de ton aide

                                Username "Patrick Payeur" - 2007-10-28 20:51:18 [Fixwareout edited 9/01/2007]

                                ~~~~~ Prerun check

                                Cache de résolution DNS vidé.

                                System was rebooted successfully.

                                ~~~~~ Postrun check
                                HKLM\SOFTWARE\~\Winlogon\ "system"=""
                                ....
                                ....
                                ~~~~~ Misc files.
                                ....
                                ~~~~~ Checking for older varients.
                                ....

                                ~~~~~ Current runs (hklm hkcu "run" Keys Only)
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "MSConfig"="\"C:\\WINNT\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe\" /auto"
                                "ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
                                "avgnt"="\"C:\\Program Files\\Avira\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min"
                                "SpySweeper"="C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeperUI.exe /startintray"

                                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                ....
                                Hosts file was reset, If you use a custom hosts file please replace it...
                                ~~~~~ End report ~~~~~

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 00:52:27, on 2007-10-29
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                Boot mode: Normal

                                Running processes:
                                C:\WINNT\System32\smss.exe
                                C:\WINNT\system32\winlogon.exe
                                C:\WINNT\system32\services.exe
                                C:\WINNT\system32\lsass.exe
                                C:\WINNT\system32\svchost.exe
                                C:\WINNT\System32\svchost.exe
                                C:\WINNT\system32\spoolsv.exe
                                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                C:\WINNT\System32\svchost.exe
                                C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                                C:\WINNT\Explorer.EXE
                                C:\WINNT\system32\notepad.exe
                                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
                                C:\Program Files\Mozilla Firefox\firefox.exe
                                C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
                                C:\WINNT\system32\NOTEPAD.EXE
                                C:\WINNT\system32\wscntfy.exe
                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?pc=mssh&form=msshhp&ocid=onepro&homepage=http%3a%2f%2fwww.microsoft.com%2fisapi%2fredir.dll%3fprd%3d{SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
                                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                O4 - HKLM\..\Run: [MSConfig] "C:\WINNT\PCHealth\HelpCtr\Binaries\MSConfig.exe" /auto
                                O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
                                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'SYSTEM')
                                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'Default user')
                                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ca\msntabres.dll.mui/229?58abea2839d149c6a945c98ff1fddd4a
                                O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ca\msntabres.dll.mui/230?58abea2839d149c6a945c98ff1fddd4a
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\shdocvw.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\shdocvw.dll
                                O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
                                O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
                                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
                                O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                                O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
                                O17 - HKLM\System\CCS\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: NameServer = 208.67.220.220,208.67.222.222
                                O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.153 85.255.112.12
                                O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
                                O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
                                O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
                                O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
                                O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                                0
                                1. Contributeur sécurité
                                  Bonjour,

                                  Relance HijackThis.

                                  Choisis Do a scan only

                                  Coche la case devant les lignes suivantes

                                  O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.153 85.255.112.12

                                  Ferme toutes les fenêtres (hormis HijackThis), y compris ton navigateur.

                                  Clique sur fix checked.

                                  Ferme Hijackthis.

                                  Redémarre l'ordi et poste un nouveau log Hijackthis.
                                  0
                                  1. mon nouveau rapport hijackthis :

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 10:40:02, on 2007-10-29
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINNT\System32\smss.exe
                                    C:\WINNT\system32\winlogon.exe
                                    C:\WINNT\system32\services.exe
                                    C:\WINNT\system32\lsass.exe
                                    C:\WINNT\system32\svchost.exe
                                    C:\WINNT\System32\svchost.exe
                                    C:\WINNT\system32\ZoneLabs\vsmon.exe
                                    C:\WINNT\system32\spoolsv.exe
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                    C:\WINNT\System32\svchost.exe
                                    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                                    C:\WINNT\system32\wuauclt.exe
                                    C:\WINNT\Explorer.EXE
                                    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                    C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
                                    C:\Program Files\Mozilla Firefox\firefox.exe
                                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?pc=mssh&form=msshhp&ocid=onepro&homepage=http%3a%2f%2fwww.microsoft.com%2fisapi%2fredir.dll%3fprd%3d{SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
                                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                                    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                    O4 - HKLM\..\Run: [MSConfig] "C:\WINNT\PCHealth\HelpCtr\Binaries\MSConfig.exe" /auto
                                    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                    O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
                                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINNT\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'Default user')
                                    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ca\msntabres.dll.mui/229?58abea2839d149c6a945c98ff1fddd4a
                                    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ca\msntabres.dll.mui/230?58abea2839d149c6a945c98ff1fddd4a
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\shdocvw.dll
                                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\shdocvw.dll
                                    O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
                                    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
                                    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                                    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                                    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
                                    O17 - HKLM\System\CCS\Services\Tcpip\..\{7D1B5118-3443-43EF-A3D2-148DD05A02C7}: NameServer = 208.67.220.220,208.67.222.222
                                    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
                                    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
                                    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
                                    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
                                    O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                                    0
                                    1. Contributeur sécurité
                                      Re,

                                      tu as bien redémarré l'ordi avant de refaire tourner Hijackthis et de psoter le log ?

                                      Comment se porte l'ordi ?
                                      0
                                      1. Salut et désolé de me jeter dans votre conversation, j'ai le même problème Mal/Heurie-E et Mal/Packer impossible de mettre en quarantaine avec webroot spysweeper.

                                        voici le rapport hi jack this, n'étant pas une foudre en informatique j'ai préféré ne pas suivre les infos données plus haut, je suppose que chaque machine à ses spécificités, d'avance merci pour aide précieuse!!

                                        Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 21:24:22, on 29/10/2007
                                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                                        MSIE: Internet Explorer v7.00 (7.00.6000.16544)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\WINDOWS\System32\smss.exe
                                        C:\WINDOWS\system32\winlogon.exe
                                        C:\WINDOWS\system32\services.exe
                                        C:\WINDOWS\system32\lsass.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\WINDOWS\Explorer.EXE
                                        C:\WINDOWS\system32\spoolsv.exe
                                        C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                                        C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                                        C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
                                        C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
                                        C:\WINDOWS\RTHDCPL.EXE
                                        C:\Program Files\iTunes\iTunesHelper.exe
                                        C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
                                        C:\WINDOWS\system32\ctfmon.exe
                                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                        C:\Program Files\a-squared Anti-Malware\a2service.exe
                                        C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                                        C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
                                        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        C:\WINDOWS\eHome\ehRecvr.exe
                                        C:\WINDOWS\eHome\ehSched.exe
                                        c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                        C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                                        C:\WINDOWS\system32\nvsvc32.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                                        C:\Program Files\iPod\bin\iPodService.exe
                                        C:\WINDOWS\system32\dllhost.exe
                                        C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
                                        C:\Program Files\Internet Explorer\iexplore.exe
                                        C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                        C:\Program Files\Internet Explorer\iexplore.exe
                                        C:\Program Files\WinRAR\WinRAR.exe
                                        C:\DOCUME~1\SERGEM~1\LOCALS~1\Temp\Rar$EX00.953\HijackThis.exe

                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.microsoft.com/r/rlidOfficeUpdate?clid=1036
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                        R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                        O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
                                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                        O4 - HKLM\..\Run: [LaunchApp] Alaunch
                                        O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                                        O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
                                        O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
                                        O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                                        O4 - HKLM\..\Run: [eDataSecurity Loader] "C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" 0
                                        O4 - HKLM\..\Run: [eRecoveryService] "C:\Acer\Empowering Technology\eRecovery\eRAgent.exe"
                                        O4 - HKLM\..\Run: [EEventManager] "C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe"
                                        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                        O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
                                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                        O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
                                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                        O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                        O4 - Global Startup: ColorVisionStartup.lnk = C:\Program Files\ColorVision\Utility\ColorVisionStartup.exe
                                        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                        O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - https://www.eset.com/
                                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
                                        O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
                                        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                                        O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mypix.com/importer/ImageUploader4.cab
                                        O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.inoculer.com/antivirus/Msie/bitdefender.cab
                                        O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://charon777.free.fr/plugins/hardwaredetection.cab
                                        O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - https://www.phox.fr/fr-FR/
                                        O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
                                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                        O17 - HKLM\System\CCS\Services\Tcpip\..\{0569E79A-D093-47EE-AFF5-B74FEF6D4EE6}: NameServer = 84.103.237.146 86.64.145.146
                                        O17 - HKLM\System\CS1\Services\Tcpip\..\{0569E79A-D093-47EE-AFF5-B74FEF6D4EE6}: NameServer = 84.103.237.146 86.64.145.146
                                        O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
                                        O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                                        O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
                                        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                        O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                        O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                                        0
                                        1. Contributeur sécurité
                                          Bonjour,

                                          Il serait préférable que tu fasses ton message personnel, cela rendra les postes plus compréhensibles et la réponse à ton problème sera plus efficace
                                          Procèdes comme ceci :
                                          http://pageperso.aol.fr/balltrap34/demofairesontmessage.htm

                                          A bientôt
                                          0
                                          • 1
                                          • 2
                                          • 3