Problème de virus ou ver unknown Trojan

Résolu
Bonsoir, j'ai malheureusement un virus ou ver dans mon système Windows internet intitulé Trojan j'ai un anti-virus Norton mais rien à faire pouvez-vous svp m'aider pour m'en débarasser s.v.p lien gratuit si possible merci
Configuration: Windows Vista
Internet Explorer 7.0

55 réponses

Résumé de la discussion

Un Trojan infecte le système Windows Vista est signalé malgré Norton, et la démarche consiste à utiliser des outils spécialisés pour isoler et supprimer les éléments malveillants. Les recommandations préconisent HijackThis pour repérer les éléments suspects, OTMoveIt pour les déplacer et supprimer, puis CCleaner en mode sans échec pour nettoyer les résidus et les entrées de registre. Il est ensuite conseillé de redémarrer en mode sans échec, de supprimer des éléments identifiés comme C:\Windows\msvidc32.dll et C:\Windows\ASScrPro.exe, puis de redémarrer et de répéter le balayage pour confirmer la désinfection. D’autres interventions insistent sur la variété des configurations et l’importance de vérifier les rapports de désinfection à chaque étape, afin d’éviter la réutilisation de procédures non adaptées à la machine concernée.

Bobot (l’IA à votre service)
  1. Bonsoir

    un virus ou ver intitulé Trojan , c'est très vague.... :)

    Bref,
    Commence par poster un rapport HijackThis stp,
    >Télécharge HiJackThis : https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/
    - Lance Hijackthis, sélectionne < Scan > puis < save log >
    - Enregistre le rapport sur ton bureau.
    Et envoie stp, par collier/coller, ton log Hijackthis sur le forum,
    ;)

    A+
    0
    1. Bonsoir je n'y connait hélas pas grand chose j'ai essayé de suivre votre dire sur hijackthis, voyez si cela correspond à la demande merci beaucoup

      Voici le message d'information

      X your computer was infected by unknow trojan
      It's dangerous for your system
      (critical files can be lost!)
      Click ok to downloand the antispyware program to clean your system

      Je rentre dans google et je demande le site caramail la page google s'ouvre et j'ai en premier lieu le site caramail en segond j'ai un message avec un grand X en rouge et sa dit

      X Error !
      your browser was hijacked? Some results was changed by p. advertising!
      You need to clean your system immediately to provent it. Dowload the new antispyware software.

      En toisième position j'ai un site bizzare non demandé avec une photo de femme sexy ?

      Youtube P Watch Now
      http://youtube/watch?v=Hgdzq 12 aA2

      Voici la liste HijackThis

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 20:45:40, on 27.02.2008
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16609)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Nero\Nero 7\InCD\InCD.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
      C:\Windows\vsnp2std.exe
      C:\Program Files\ASUS\ATK Media\DMedia.exe
      C:\Windows\System32\ASUSTPE.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Windows\ASScrPro.exe
      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
      C:\Windows\System32\mobsync.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\ASUS\ASUS Live Update\ALU.exe
      C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
      C:\Program Files\Internet Explorer\ieuser.exe
      C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\Windows\system32\SearchFilterHost.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ch/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: MS Video Control 1.0 - {54629298-47B2-4F79-BC62-7B3648D70020} - C:\Windows\msvidc32.dll
      O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
      O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: Afficher Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
      O4 - HKLM\..\Run: [snp2std] C:\Windows\vsnp2std.exe
      O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
      O4 - HKLM\..\Run: [ASUSTPE] C:\Windows\system32\ASUSTPE.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
      O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
      O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone.exe
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/flashax.cab
      O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
      O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
      O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
      O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
      O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
      0
    2. Re-bonsoir ya-t'il une personne qui a la réponse à mon problème merci pour votre collaboration
      0
    3. Merci pour ta réponse voici le recap.et pour ta collaboration A+
      0
    4. @Utilisateur anonymeSalut j'ai envoyé le rapport sur le forum merci pou ta coll.

      Voici ce rapport

      SmitFraudFix v2.298

      Scan done at 18:52:30.32, 28.02.2008
      Run from C:\Users\sergenathalie\SmitfraudFix
      OS: Microsoft Windows [version 6.0.6000] - Windows_NT
      The filesystem type is NTFS
      Fix run in normal mode

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\Windows\system32\csrss.exe
      C:\Windows\system32\wininit.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\services.exe
      C:\Windows\system32\lsass.exe
      C:\Windows\system32\lsm.exe
      C:\Windows\system32\winlogon.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\Ati2evxx.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\SLsvc.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\ATK Hotkey\ASLDRSrv.exe
      C:\Windows\System32\spoolsv.exe
      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\Ati2evxx.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Nero\Nero 7\InCD\InCD.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
      C:\Program Files\ATK Hotkey\Hcontrol.exe
      C:\Program Files\ATKOSD2\ATKOSD2.exe
      C:\Program Files\Wireless Console 2\wcourier.exe
      C:\Program Files\P4G\BatteryLife.exe
      C:\Windows\vsnp2std.exe
      C:\Program Files\ASUS\Splendid\ACMON.exe
      C:\Program Files\ASUS\ATK Media\DMedia.exe
      C:\Windows\System32\ACEngSvr.exe
      C:\Windows\System32\ASUSTPE.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Windows\ASScrPro.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\ATK Hotkey\ATKOSD.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\SearchIndexer.exe
      C:\Windows\system32\WUDFHost.exe
      C:\Windows\system32\wbem\wmiprvse.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Windows Media Player\wmpnetwk.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\ASUS\ASUS Live Update\ALU.exe
      C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
      C:\Program Files\Internet Explorer\ieuser.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\servicing\TrustedInstaller.exe
      C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\system32\SearchProtocolHost.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Windows\system32\cmd.exe
      C:\Windows\system32\conime.exe
      C:\Windows\system32\wbem\wmiprvse.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\sergenathalie

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\sergenathalie\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\SERGEN~1\FAVORI~1

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, following keys are not inevitably infected!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri
      +--------------------------------------------------+
      [!] Suspicious: msvidc32.dll
      BHO: MS Video Control 1.0 - {54629298-47B2-4F79-BC62-7B3648D70020}
      CLSID: {54629298-47B2-4F79-BC62-7B3648D70020}
      AppID: {54629298-47B2-4F79-BC62-7B3648D70020}
      AppID: msvidc32.dll
      Classes: msvidc32.Video
      TypeLib: {74D46BBA-5638-473A-83B6-97E7804A7411}
      Interface: {48D78BE5-CFB9-4B66-9AC4-96D4CF21DE06}

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, following keys are not inevitably infected!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, following keys are not inevitably infected!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, following keys are not inevitably infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""
      "LoadAppInit_DLLs"=dword:00000000

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, following keys are not inevitably infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

      »»»»»»»»»»»»»»»»»»»»»»»» Rustock

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: Atheros AR5006EG Wireless Network Adapter
      DNS Server Search Order: 192.168.2.1

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{57021EBC-FE13-42EE-8B46-3CE2ED5FB340}: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{57021EBC-FE13-42EE-8B46-3CE2ED5FB340}: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{57021EBC-FE13-42EE-8B46-3CE2ED5FB340}: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

      »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

      »»»»»»»»»»»»»»»»»»»»»»»» End
      0
  2. Rebonsoir,

    Tu peux me tutoyer stp ? C'est plus sympa sur le web...merci :)))

    Alors comme cela ça chauffe sur ton PC ?
    Bon pour te rafraichir je te paye une bière : http://images2.hiboox.com/images/4007/g2fnto04.gif

    mdr :))

    >Ouvre ce lien (merci a S!RI pour ce fix) http://siri.urz.free.fr/Fix/SmitfraudFix.php et télécharge SmitfraudFix.exe.
    - Regarde le tuto
    - Exécute le programme et choisi l’option 1
    Le programme va générer un rapport, copie/colle le sur le forum stp.

    A+

    ;)

    Ne tiens pas compte de la ligne ci-dessous ; c'est un repère pour moi : (avec un un nom qui commence par ASS....tu te doutes...)
    C:\Windows\ASScrPro.exe
    0
    1. Bonsoir,

      ya-til une personne qui puisse m'aider à tuer ce ver ou virus TROJAN j'ai téléchargé sur SmitFraudFix voici le rapport qui pour moi est du chinois ?? que faire ?
      Merci pour votre collab.

      SmitFraudFix v2.298

      Scan done at 18:52:30.32, 28.02.2008
      Run from C:\Users\sergenathalie\SmitfraudFix
      OS: Microsoft Windows [version 6.0.6000] - Windows_NT
      The filesystem type is NTFS
      Fix run in normal mode

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\Windows\system32\csrss.exe
      C:\Windows\system32\wininit.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\services.exe
      C:\Windows\system32\lsass.exe
      C:\Windows\system32\lsm.exe
      C:\Windows\system32\winlogon.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\Ati2evxx.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\SLsvc.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\ATK Hotkey\ASLDRSrv.exe
      C:\Windows\System32\spoolsv.exe
      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\Ati2evxx.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Nero\Nero 7\InCD\InCD.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
      C:\Program Files\ATK Hotkey\Hcontrol.exe
      C:\Program Files\ATKOSD2\ATKOSD2.exe
      C:\Program Files\Wireless Console 2\wcourier.exe
      C:\Program Files\P4G\BatteryLife.exe
      C:\Windows\vsnp2std.exe
      C:\Program Files\ASUS\Splendid\ACMON.exe
      C:\Program Files\ASUS\ATK Media\DMedia.exe
      C:\Windows\System32\ACEngSvr.exe
      C:\Windows\System32\ASUSTPE.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Windows\ASScrPro.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\ATK Hotkey\ATKOSD.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\SearchIndexer.exe
      C:\Windows\system32\WUDFHost.exe
      C:\Windows\system32\wbem\wmiprvse.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Windows Media Player\wmpnetwk.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\ASUS\ASUS Live Update\ALU.exe
      C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
      C:\Program Files\Internet Explorer\ieuser.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\servicing\TrustedInstaller.exe
      C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\system32\SearchProtocolHost.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Windows\system32\cmd.exe
      C:\Windows\system32\conime.exe
      C:\Windows\system32\wbem\wmiprvse.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\sergenathalie

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\sergenathalie\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\SERGEN~1\FAVORI~1

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, following keys are not inevitably infected!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri
      +--------------------------------------------------+
      [!] Suspicious: msvidc32.dll
      BHO: MS Video Control 1.0 - {54629298-47B2-4F79-BC62-7B3648D70020}
      CLSID: {54629298-47B2-4F79-BC62-7B3648D70020}
      AppID: {54629298-47B2-4F79-BC62-7B3648D70020}
      AppID: msvidc32.dll
      Classes: msvidc32.Video
      TypeLib: {74D46BBA-5638-473A-83B6-97E7804A7411}
      Interface: {48D78BE5-CFB9-4B66-9AC4-96D4CF21DE06}

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, following keys are not inevitably infected!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, following keys are not inevitably infected!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, following keys are not inevitably infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""
      "LoadAppInit_DLLs"=dword:00000000

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, following keys are not inevitably infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

      »»»»»»»»»»»»»»»»»»»»»»»» Rustock

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: Atheros AR5006EG Wireless Network Adapter
      DNS Server Search Order: 192.168.2.1

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{57021EBC-FE13-42EE-8B46-3CE2ED5FB340}: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{57021EBC-FE13-42EE-8B46-3CE2ED5FB340}: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{57021EBC-FE13-42EE-8B46-3CE2ED5FB340}: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

      »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

      »»»»»»»»»»»»»»»»»»»»»»»» End
      0
      1. BS

        ya-til une personne qui traite mon problème merci pour votre réponse

        SmitFraudFix v2.298

        Scan done at 18:52:30.32, 28.02.2008
        Run from C:\Users\sergenathalie\SmitfraudFix
        OS: Microsoft Windows [version 6.0.6000] - Windows_NT
        The filesystem type is NTFS
        Fix run in normal mode

        »»»»»»»»»»»»»»»»»»»»»»»» Process

        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\Ati2evxx.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\ATK Hotkey\ASLDRSrv.exe
        C:\Windows\System32\spoolsv.exe
        C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\Ati2evxx.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\Nero\Nero 7\InCD\InCD.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
        C:\Program Files\ATK Hotkey\Hcontrol.exe
        C:\Program Files\ATKOSD2\ATKOSD2.exe
        C:\Program Files\Wireless Console 2\wcourier.exe
        C:\Program Files\P4G\BatteryLife.exe
        C:\Windows\vsnp2std.exe
        C:\Program Files\ASUS\Splendid\ACMON.exe
        C:\Program Files\ASUS\ATK Media\DMedia.exe
        C:\Windows\System32\ACEngSvr.exe
        C:\Windows\System32\ASUSTPE.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Windows\ASScrPro.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
        C:\Windows\ehome\ehmsas.exe
        C:\Program Files\ATK Hotkey\ATKOSD.exe
        C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\SearchIndexer.exe
        C:\Windows\system32\WUDFHost.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Windows Media Player\wmpnetwk.exe
        C:\Windows\system32\taskeng.exe
        C:\Program Files\ASUS\ASUS Live Update\ALU.exe
        C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
        C:\Program Files\Internet Explorer\ieuser.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
        C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Windows\servicing\TrustedInstaller.exe
        C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Windows\system32\SearchProtocolHost.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Windows\system32\cmd.exe
        C:\Windows\system32\conime.exe
        C:\Windows\system32\wbem\wmiprvse.exe

        »»»»»»»»»»»»»»»»»»»»»»»» hosts

        »»»»»»»»»»»»»»»»»»»»»»»» C:\

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\sergenathalie

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\sergenathalie\Application Data

        »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\SERGEN~1\FAVORI~1

        »»»»»»»»»»»»»»»»»»»»»»»» Desktop

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

        »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

        »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
        !!!Attention, following keys are not inevitably infected!!!

        IEDFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri
        +--------------------------------------------------+
        [!] Suspicious: msvidc32.dll
        BHO: MS Video Control 1.0 - {54629298-47B2-4F79-BC62-7B3648D70020}
        CLSID: {54629298-47B2-4F79-BC62-7B3648D70020}
        AppID: {54629298-47B2-4F79-BC62-7B3648D70020}
        AppID: msvidc32.dll
        Classes: msvidc32.Video
        TypeLib: {74D46BBA-5638-473A-83B6-97E7804A7411}
        Interface: {48D78BE5-CFB9-4B66-9AC4-96D4CF21DE06}

        »»»»»»»»»»»»»»»»»»»»»»»» VACFix
        !!!Attention, following keys are not inevitably infected!!!

        VACFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
        !!!Attention, following keys are not inevitably infected!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
        !!!Attention, following keys are not inevitably infected!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
        "AppInit_DLLs"=""
        "LoadAppInit_DLLs"=dword:00000000

        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
        !!!Attention, following keys are not inevitably infected!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

        »»»»»»»»»»»»»»»»»»»»»»»» Rustock

        »»»»»»»»»»»»»»»»»»»»»»»» DNS

        Description: Atheros AR5006EG Wireless Network Adapter
        DNS Server Search Order: 192.168.2.1

        HKLM\SYSTEM\CCS\Services\Tcpip\..\{57021EBC-FE13-42EE-8B46-3CE2ED5FB340}: DhcpNameServer=192.168.2.1
        HKLM\SYSTEM\CS1\Services\Tcpip\..\{57021EBC-FE13-42EE-8B46-3CE2ED5FB340}: DhcpNameServer=192.168.2.1
        HKLM\SYSTEM\CS3\Services\Tcpip\..\{57021EBC-FE13-42EE-8B46-3CE2ED5FB340}: DhcpNameServer=192.168.2.1
        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
        HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

        »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

        »»»»»»»»»»»»»»»»»»»»»»»» End
        0
        1. Oui,
          bonsoir,
          me revilà,
          > Lance Hijackthis :
          - Puis sélectionne < Scan >
          - Coche les cases des lignes suivantes :

          O2 - BHO: MS Video Control 1.0 - {54629298-47B2-4F79-BC62-7B3648D70020} - C:\Windows\msvidc32.dll

          Ensuite,
          - Ferme toutes les autres fenêtres et applications (même internet)
          - Clic sur < fixe checked >

          > Télécharge OTMoveIT (de Old_Timer) : http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe sur ton bureau...
          - Double-clique sur OTMoveIt.exe pour le lancer.
          - Assure toi que la case "Unregister Dll's and Ocx's" est bien cochée !!!
          - Copie le texte qui se trouve ci-dessous et colle-le dans le cadre de gauche de OTMoveIt nommé <Paste standard List of Files/Folders to be moved>.

          C:\Windows\msvidc32.dll
          C:\Windows\ASScrPro.exe

          - Clique sur < MoveIt! > pour lancer la suppression.
          - Lorsqu'un résultat apparaît dans le cadre Results clique sur Exit
          N.B :Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. Accepte en cliquant sur YES.
          Un rapport est créé dans %SYSTEMDRIVE%\_OTMoveIt\MovedFiles\date du jour, copie-colle-le dans ta réponse suivante stp.

          >Télécharge et installe Ccleaner : https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html , si besoin est tu trouveras des Tutoriaux ici, ici et là, fais les mises à jour puis ferme le programme.

          > Démarre en mode sans échec : (image). Si problème : tuto ici
          >Lance Ccleaner,,
          - Choisi l’onglet "Options" puis clique sur "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures" (tout doit être supprimé).
          - Dans l'onglet "Nettoyeur" clique sur "Analyse".
          - Une fois l'analyse terminée, clique sur "Lancer le Nettoyage".
          - Dans l'onglet "registre" => Recherches des erreurs => Réparer les erreurs sélectionnées => enregistre une sauvegarde => corriger toutes erreurs sélectionnées => ok => fermer.
          N.B : Si Ccleaner te propose d'enregistrer une sauvegarde, reponds oui et enregistre sous 'Bureau'
          Recommence jusqu’à ce qu’il ne trouve plus rien (cela varie en général entre 1 et 4 fois).

          > Relance ton PC en mode normal puis Hijackthis :
          Puis sélectionne < do a system scan and save a logfile >,

          Et envoie, par collier/coller, ton log Hijackthis stp,

          A+
          0
          1. Salut je te remercie pour toutes ces recherches jespère que j'ai bien suivit tes instructions voici le nouveau rapport
            Si par hasard tu tardes à me conntacter no problèm je m'absente quelques heures dès 18h30 A+ merci encore

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 16:40:43, on 29.02.2008
            Platform: Windows Vista (WinNT 6.00.1904)
            MSIE: Internet Explorer v7.00 (7.00.6000.16609)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\Dwm.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Program Files\Nero\Nero 7\InCD\InCD.exe
            C:\Windows\RtHDVCpl.exe
            C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
            C:\Windows\vsnp2std.exe
            C:\Program Files\ASUS\ATK Media\DMedia.exe
            C:\Windows\System32\ASUSTPE.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Windows\ASScrPro.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Windows\ehome\ehtray.exe
            C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
            C:\Windows\ehome\ehmsas.exe
            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\taskeng.exe
            C:\Program Files\ASUS\ASUS Live Update\ALU.exe
            C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
            C:\Program Files\Internet Explorer\ieuser.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
            C:\Windows\system32\NOTEPAD.EXE

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ch/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            O1 - Hosts: ::1 localhost
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
            O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O3 - Toolbar: Afficher Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
            O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
            O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
            O4 - HKLM\..\Run: [snp2std] C:\Windows\vsnp2std.exe
            O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
            O4 - HKLM\..\Run: [ASUSTPE] C:\Windows\system32\ASUSTPE.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
            O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
            O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone.exe
            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
            O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
            O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
            O13 - Gopher Prefix:
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/flashax.cab
            O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
            O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
            O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
            O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
            O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
            0
          2. Merci beaucoup pour toute cette souffrance informatique ça fonctionne plus de virus super Maître DIID
            0
        2. Bonjour, mon problème de TOJAN est résolu je tenais à remercier toutes les super....stars de l'inform. merci merci beaucoup à tous et surtout à Maître DIID
          0
          1. __      __           _           __        _            
            \ \    / /          | |         / _|      (_)           
             \ \  / /__ _  ___  | |_  ___  | |_  __ _  _  _ __  ___ 
              \ \/ // _` |/ __| | __|/ _ \ |  _|/ _` || || '__|/ _ \
               \  /| (_| |\__ \ | |_|  __/ | | | (_| || || |  |  __/
                \/  \__,_||___/  \__|\___| |_|  \__,_||_||_|   \___|
                                                                    
                                                                    
                               _  _                     _          _ 
                              (_)| |                   | |        | |
             _ __ ___    __ _  _ | |_  _ __  ___     __| |  ___   | |
            | '_ ` _ \  / _` || || __|| '__|/ _ \   / _` | / _ \  | |
            | | | | | || (_| || || |_ | |  |  __/  | (_| ||  __/  | |
            |_| |_| |_| \__,_||_| \__||_|   \___|   \__,_| \___|  |_|
                                                                     
                                                                     
                           _                                       _       
                          (_)                                     | |      
             _   _  _ __   _ __   __ ___  _ __  ___    ___   __ _ | |  ___ 
            | | | || '_ \ | |\ \ / // _ \| '__|/ __|  / __| / _` || | / _ \
            | |_| || | | || | \ V /|  __/| |   \__ \  \__ \| (_| || ||  __/
             \__,_||_| |_||_|  \_/  \___||_|   |___/  |___/ \__,_||_| \___|
                                                                           
                                                                           
                                                    _                       _  _  _ 
                                                   | |                     | || || |
             _   _  ___  _   _  _ __  _ __    __ _ | |_  ___  _   _  _ __  | || || |
            | | | |/ __|| | | || '__|| '_ \  / _` || __|/ _ \| | | || '__| | || || |
            | |_| |\__ \| |_| || |   | |_) || (_| || |_|  __/| |_| || |    |_||_||_|
             \__,_||___/ \__,_||_|   | .__/  \__,_| \__|\___| \__,_||_|    (_)(_)(_)
                                     | |                                            
                                     |_|                                            
            0
        3. Salut natserg,

          Pourquoi as tu posté ton message ici ?????
          http://www.commentcamarche.net/forum/affich 5218881 probleme de virus ou ver unknown trojan#16

          Si tu sèmes des réponses un peu partout dans la discussion on ne va jamais y arriver....

          Donc peux tu reposter un rapport HiJackT en fin de discussion stp.
          Pour réponde ne clique pas sur <répondre à DllD> mais vas tout en bas dans <Répondre> (comme je viens de la faire)..

          Merci,

          a+
          0
          1. Salut je suis un peu perdu est-ce le bon suis-je au bonne endroit mille excuse A+ merci

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 16:40:43, on 29.02.2008
            Platform: Windows Vista (WinNT 6.00.1904)
            MSIE: Internet Explorer v7.00 (7.00.6000.16609)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\Dwm.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Program Files\Nero\Nero 7\InCD\InCD.exe
            C:\Windows\RtHDVCpl.exe
            C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
            C:\Windows\vsnp2std.exe
            C:\Program Files\ASUS\ATK Media\DMedia.exe
            C:\Windows\System32\ASUSTPE.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Windows\ASScrPro.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Windows\ehome\ehtray.exe
            C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
            C:\Windows\ehome\ehmsas.exe
            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\taskeng.exe
            C:\Program Files\ASUS\ASUS Live Update\ALU.exe
            C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
            C:\Program Files\Internet Explorer\ieuser.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
            C:\Windows\system32\NOTEPAD.EXE

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ch/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            O1 - Hosts: ::1 localhost
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
            O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O3 - Toolbar: Afficher Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
            O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
            O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
            O4 - HKLM\..\Run: [snp2std] C:\Windows\vsnp2std.exe
            O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
            O4 - HKLM\..\Run: [ASUSTPE] C:\Windows\system32\ASUSTPE.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
            O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
            O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone.exe
            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
            O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
            O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
            O13 - Gopher Prefix:
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/flashax.cab
            O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
            O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
            O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
            O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
            O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
            0
            1. Hier j'ai déjà effetué toutes ces op. le problème est que je n'arrive pas à trouvé ou j'ai téléchargé OTMovelt2 il n'est pas sur mon bureau ni dans mes documents nouveau et le rapport %SYSTEMDRIVE%\_OTMoveIt\MovedFiles\date du jour est introuvable ?? ceux-ci dit je peux naviguer sur le net et je n'es plus de virus ou de ver tout fonctionne ? dois-je répéter toute l'opération que tu m'imdiques ci-dessus une deuxième fois ? merci pour ta coll. A+
              0
              1. Re bonsoir...

                C'est louche....

                Peux tu reposter un rapport HiJackT stp ?

                Parce que pour moi tu es toujours infecté...

                Merci,

                A°
                0
            2. Pas de problème voila le report :

              Merci

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 16:40:43, on 29.02.2008
              Platform: Windows Vista (WinNT 6.00.1904)
              MSIE: Internet Explorer v7.00 (7.00.6000.16609)
              Boot mode: Normal

              Running processes:
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\Program Files\Nero\Nero 7\InCD\InCD.exe
              C:\Windows\RtHDVCpl.exe
              C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
              C:\Windows\vsnp2std.exe
              C:\Program Files\ASUS\ATK Media\DMedia.exe
              C:\Windows\System32\ASUSTPE.exe
              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              C:\Windows\ASScrPro.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Windows\ehome\ehtray.exe
              C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              C:\Program Files\Windows Media Player\wmpnscfg.exe
              C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
              C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
              C:\Windows\ehome\ehmsas.exe
              C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\ASUS\ASUS Live Update\ALU.exe
              C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
              C:\Program Files\Internet Explorer\ieuser.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
              C:\Windows\system32\NOTEPAD.EXE

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ch/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              O1 - Hosts: ::1 localhost
              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
              O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O3 - Toolbar: Afficher Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
              O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
              O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
              O4 - HKLM\..\Run: [snp2std] C:\Windows\vsnp2std.exe
              O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
              O4 - HKLM\..\Run: [ASUSTPE] C:\Windows\system32\ASUSTPE.exe
              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
              O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
              O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone.exe
              O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
              O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
              O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
              O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
              O13 - Gopher Prefix:
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/flashax.cab
              O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
              O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
              O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
              O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
              O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
              O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
              O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
              O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
              O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
              O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
              0
              1. Bon ...

                je t'explique : si tu regarde ton rapport HiJackT :
                Running processes:
                C:\Windows\system32\Dwm.exe
                C:\Windows\Explorer.EXE
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\Program Files\Nero\Nero 7\InCD\InCD.exe
                C:\Windows\RtHDVCpl.exe
                C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                C:\Windows\vsnp2std.exe
                C:\Program Files\ASUS\ATK Media\DMedia.exe
                C:\Windows\System32\ASUSTPE.exe
                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                C:\Windows\ASScrPro.exe
                C:\Program Files\Windows Sidebar\sidebar.exe
                C:\Windows\ehome\ehtray.exe


                Et qu'après tu vas là :

                http://www.greatis.com/appdata/d/a/asscrpro.exe.htm

                Tu t'aperçois qu'il s'agit d'un cheval de troie....

                Bref,

                > Télécharge OTMoveIT (de Old_Timer) : http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe sur ton bureau...
                - Double-clique sur OTMoveIt.exe pour le lancer.
                - Assure toi que la case "Unregister Dll's and Ocx's" est bien cochée !!!
                - Copie le texte qui se trouve ci-dessous et colle-le dans le cadre de gauche de OTMoveIt nommé <Paste standard List of Files/Folders to be moved>.

                C:\Windows\ASScrPro.exe

                - Clique sur < MoveIt! > pour lancer la suppression.
                - Lorsqu'un résultat apparaît dans le cadre Results clique sur Exit
                N.B :Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. Accepte en cliquant sur YES.
                Un rapport est créé dans %SYSTEMDRIVE%\_OTMoveIt\MovedFiles\date du jour, copie-colle-le dans ta réponse suivante stp.

                Et poste le rapport cette fois stp...

                Car c'est pas fini...

                :))))
                0
                1. Hello,
                  J'ai une autre question , peux-tu svp me dire si je télécharge avast ,peut-il être compatible avec l'anti-virus Norton, ou je ne peux avoir les deux en même temps. merci pour ta coll A+
                  0
                  1. NON !!!

                    Qu'un seul antivirus en même temps....

                    Veux tu bien faire ce que je te demande ? ou j'abandonne ?

                    A+

                    :)
                    0
                2. Oui mille excuses je pensais que c'étais fini

                  Voilà je t'explique Double-clique sur OTMoveIt.exe pour le lancer. --OK JE L'ES FAIT--
                  - Assure toi que la case "Unregister Dll's and Ocx's" est bien cochée !!! -OK-
                  - Copie le texte qui se trouve ci-dessous et colle-le dans le cadre de gauche de OTMoveIt nommé <Paste standard List of Files/Folders to be moved>. --OK--

                  C:\Windows\ASScrPro.exe --OK--

                  - Clique sur < MoveIt! > pour lancer la suppression.--OK--
                  - Lorsqu'un résultat apparaît dans le cadre Results clique sur Exit--JE N'ES PAS EU LE TEMPS DE LE FAIRE LE LOGICIEL MA DEMANDE DE REDEMARRER LE PC SANS ME DEMANDER YES??
                  ET LE PC REDEMARRE ET ME DEMANDE DE RENTER DENOUVEAU LE PASSWORD QUE DOIS-JE FAIRE ?

                  REPETER L'OPERATION ?

                  MERCI a+
                  0
                  1. GNééé ???!!!

                    Bon c'est bisard...

                    Pas grave...

                    essaye de supprimer le fichier comme ça (avec un minimum d'applications ouvertes) sinon fais le en mode sans échec stp.

                    Tiens moi au courant !

                    A+

                    :)
                    0
                3. Contributeur
                  Dlld
                  La fievre du samedi s/foire?
                  kisses`
                  0
                  1. Hey' !

                    Y a pas un soucis dans son rapport ?
                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 16:40:43, on 29.02.2008 


                    ....
                    Le même rapport est posté plusieurs fois =/

                    Post
                    12,16,18,22
                    0
                    1. Salut, cyrildu17,

                      Mais passe voir par là :

                      http://www.greatis.com/appdata/d/a/asscrpro.exe.htm

                      Asscrpro.exe is Trojan/Backdoor

                      Alors...peux être que je me plante...mais là....
                      0
                    2. @Utilisateur anonymeOui je suis d'accord ,

                      Mais demande lui un rapport Hijackthis ' frais ' cette fois-ci =/
                      0
                    3. @Utilisateur anonymeEt mais tu arrive comme ça pour cela ????

                      T'es bourré ou quoi ?

                      A+
                      0
                  2. Merci que dois-je faire ??? souci ou pas souci ?

                    Je n'arrive pas à trouver le rapport créé dans %SYSTEMDRIVE%\_OTMoveIt\MovedFiles\date du jour

                    Oû se cache t'il ?

                    merci pour votre coll A+
                    0
                    1. Re,

                      bref
                      Pour le rapport (désolé...je suis perturbé ! mdr) bref,

                      Vas Menu démarrer => rechercher => tape 'OTMoveIt' => choppe le rapport texte qui y corresponds...

                      A+
                      0
                      1. DIID

                        Merci merci je suis une ptite blonde que dois-je faire qui croire ou allez Svp... l'instruction ci-dessus est pour moi ? dois-je aller dans greatis.com

                        A+
                        0
                        1. Bon laisse tomber le rapport...

                          Démarre en mode sans échec stp et supprime ce fichier :

                          C:\Windows\ASScrPro.exe

                          Après on pourras parler de la couleur de tes cheveux..

                          MDR

                          :)))
                          0
                          • 1
                          • 2
                          • 3