Virus trojan /probleme avec internet explorer

Bonjour, mon ordinateur a été infecté par un virs (trojan) il y a 3 jours ! en lisant plusieur forum j pensais avoir reglé mon problème mais dès que je me conecte a internet des pages s'ouvrent toutes les 20 secondes et certaines me disant que mon ordi est infecter et me propose des logiciels pour regler le problème !!!!!!!!!

j'ai avast familiale comme anti virus - sous vista

si quelqu'un pouvait me venir en aide SVP !!!!!!!!!!!!!
Configuration: Windows vista
Internet Explorer 7.0

26 réponses

Résumé de la discussion

Un ordinateur sous Windows Vista est infecté par un cheval de Troie, affichant des redirections et des pages intrusives à chaque connexion Internet malgré Avast Family installé. Plusieurs réponses proposent des outils et méthodes de désinfection, notamment HijackThis, SmitfraudFix, Navilog/Navifix, CCleaner et des scripts Clean, accompagnés d’analyses de rapports pour guider l’intervention. Des conseils évoquent la gestion des comptes utilisateurs, l’exécution correcte des outils sur le bureau et la vérification minutieuse des résultats avant toute suppression de fichiers. En dernière analyse, la discussion illustre la diversité des approches et l’importance d’une analyse de journaux pour éviter de supprimer des composants légitimes dans une configuration Windows Vista.

Bobot (l’IA à votre service)
  1. Bonjour,

    Si ton anti-virus actuel ne te donne pas satifaction, utilise-en un autre : antivir par exemple
    0
    1. mon anti virus me va mais probleme il n'a pas pu eliminer completement l'infection
      0
      1. je viens de voir le lien mais je ne sais pas si les erreurs son ses memes que les miennes
        0
        1. salut,

          Pour commencer:

          Désactive le contrôle des comptes utilisateurs :

          - Va dans démarrer puis panneau de configuration
          - Double Clique sur l'icône "Comptes d'utilisateurs"
          - Clique ensuite sur désactiver et valide.

          Télécharge sur le bureau hijackthis.

          ftp://ftp.commentcamarche.com/download/HJTInstall.exe
          Fait un clic droit sur l'icone hijackthis.

          /!\Renome hijackthis en skim.exe ( a le place de hijacktihs.exe) c'est important!!/!\

          *Après avoir fais ca double-clic dessus.

          *Clic sur Do a system scan and save the log

          *A la fin de l'analyse un rapport va etre générer colle le ici.

          Une démo d'hijackthis :
          http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

          puis,

          Télécharge Navilog:

          http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

          -Choisis Enregistrer et enregistre-le sur ton bureau.

          - Ensuite double clique sur navilog1.exe pour lancer l'installation.
          Une fois l'installation terminée, le fix s'exécutera automatiquement.
          (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

          -Laisse-toi guider. Au menu principal, choisis 1 et valides.
          (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
          Patiente jusqu'au message " Analyse Termine le ....."

          -Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
          Copie/colle l'intégralité du rapport dans ta réponse. Referme le blocnote.
          Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

          -Si ton antivirus detecte un virus ou un cheval de troie durant l'analyse ignore le.

          ****** en tout deux rapport a poster******
          0
          1. Logfile of HijackThis v1.99.1
            Scan saved at 14:22:11, on 14/03/2008
            Platform: Unknown Windows (WinNT 6.00.1904)
            MSIE: Internet Explorer v7.00 (7.00.6000.16609)

            Running processes:
            C:\Windows\system32\Dwm.exe
            C:\Windows\system32\taskeng.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Windows\RtHDVCpl.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
            C:\Program Files\Picasa2\PicasaMediaDetector.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Packard Bell\FIJI\ABoard.exe
            C:\Program Files\Alwil Software\Avast4\ashDisp.exe
            C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
            C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
            C:\Program Files\Packard Bell\FIJI\AOSD.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
            C:\Program Files\DAEMON Tools Lite\daemon.exe
            C:\Windows\System32\rundll32.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
            C:\Program Files\Internet Explorer\ieuser.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Windows\Explorer.exe
            C:\Users\MEKRA\Desktop\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://format.packardbell.com/cgi-bin/redirect/?country=FR&range=AD&phase=8&key=IESTART
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
            O1 - Hosts: ::1 localhost
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
            O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
            O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
            O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
            O4 - HKLM\..\Run: [ACTIVBOARD] C:\Program Files\Packard Bell\FIJI\aboard.exe
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
            O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
            O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
            O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
            O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\MEKRA\AppData\Local\Temp\pmnol.dll,c
            O4 - HKCU\..\Run: [BMdf016c35] Rundll32.exe "C:\Users\MEKRA\AppData\Local\Temp\qrkvunoj.dll",s
            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
            O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
            O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
            O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
            O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
            O11 - Options group: [INTERNATIONAL] International*
            O13 - Gopher Prefix:
            O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
            O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
            O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} (HPDDClientExec Class) - http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab
            O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
            O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
            O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
            O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
            O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
            O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
            O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
            O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
            O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
            0
            1. Search Navipromo version 3.5.0 commencé le 14/03/2008 à 14:26:44,91

              !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
              !!! Postez ce rapport sur le forum pour le faire analyser !!!
              !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

              Outil exécuté depuis C:\Program Files\navilog1
              Mise à jour le 04.03.2008 à 17h00 par IL-MAFIOSO

              Microsoft Windows Vista 6.0.6000
              Internet Explorer : 7.0.6000.16609
              Système de fichiers : NTFS

              Executé en mode normal

              *** Recherche Programmes installés ***

              *** Recherche dossiers dans C:\Windows ***

              *** Recherche dossiers dans C:\Program Files ***

              *** Recherche dossiers dans C:\ProgramData ***

              *** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***

              *** Recherche dossiers dans c:\users\mekra\appdata\roaming\microsoft\windows\start menu\programs ***

              *** Recherche dossiers dans C:\Users\MEKRA\AppData\Local\virtualstore\Program Files ***

              *** Recherche dossiers dans C:\Users\MEKRA\AppData\Roaming ***

              *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
              pour + d'infos : http://www.gmer.net

              Aucun Fichier trouvé

              *** Recherche avec GenericNaviSearch ***
              !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
              !!! A vérifier impérativement avant toute suppression manuelle !!!

              * Recherche dans C:\Windows\system32 *

              * Recherche dans C:\Users\MEKRA\AppData\Local\Microsoft *

              * Recherche dans C:\Users\MEKRA\AppData\Local *

              *** Recherche fichiers ***

              *** Recherche clés spécifiques dans le Registre ***

              *** Module de Recherche complémentaire ***
              (Recherche fichiers spécifiques)

              1)Recherche nouveaux fichiers Instant Access :

              2)Recherche Heuristique :

              * Dans C:\Windows\system32 :

              * Dans C:\Users\MEKRA\AppData\Local\Microsoft :

              * Dans C:\Users\MEKRA\AppData\Local :

              3)Recherche Certificats :

              Certificat Egroup absent !
              Certificat Electronic-Group absent !
              Certificat OOO-Favorit absent !

              4)Recherche fichiers connus :

              *** Analyse terminée le 14/03/2008 à 14:34:03,38 ***
              0
              1. Logfile of HijackThis v1.99.1
                Scan saved at 14:56:22, on 14/03/2008
                Platform: Unknown Windows (WinNT 6.00.1904)
                MSIE: Internet Explorer v7.00 (7.00.6000.16609)

                Running processes:
                C:\Windows\system32\Dwm.exe
                C:\Windows\system32\taskeng.exe
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\Windows\RtHDVCpl.exe
                C:\Windows\System32\rundll32.exe
                C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                C:\Program Files\Picasa2\PicasaMediaDetector.exe
                C:\Windows\System32\rundll32.exe
                C:\Program Files\Packard Bell\FIJI\ABoard.exe
                C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                C:\Program Files\Packard Bell\FIJI\AOSD.exe
                C:\Program Files\Windows Sidebar\sidebar.exe
                C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                C:\Program Files\DAEMON Tools Lite\daemon.exe
                C:\Windows\System32\rundll32.exe
                C:\Windows\System32\rundll32.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                C:\Program Files\Internet Explorer\ieuser.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Windows\Explorer.exe
                C:\Users\MEKRA\Desktop\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://format.packardbell.com/...
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                O1 - Hosts: ::1 localhost
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
                O4 - HKLM\..\Run: [ACTIVBOARD] C:\Program Files\Packard Bell\FIJI\aboard.exe
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
                O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
                O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\MEKRA\AppData\Local\Temp\pmnol.dll,c
                O4 - HKCU\..\Run: [BMdf016c35] Rundll32.exe "C:\Users\MEKRA\AppData\Local\Temp\qrkvunoj.dll",s
                O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
                O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
                O11 - Options group: [INTERNATIONAL] International*
                O13 - Gopher Prefix:
                O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
                O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} (HPDDClientExec Class) - http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab
                O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
                0
                1. Non télécharge la version qu'il y a sur le lien !
                  0
                  1. SmitFraudFix v2.302

                    Scan done at 14:59:03,41, 14/03/2008
                    Run from C:\Users\MEKRA\SmitfraudFix
                    OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                    The filesystem type is NTFS
                    Fix run in normal mode

                    »»»»»»»»»»»»»»»»»»»»»»»» Process

                    C:\Windows\system32\csrss.exe
                    C:\Windows\system32\wininit.exe
                    C:\Windows\system32\csrss.exe
                    C:\Windows\system32\services.exe
                    C:\Windows\system32\lsass.exe
                    C:\Windows\system32\lsm.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\winlogon.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\SLsvc.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\Windows\System32\spoolsv.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\PnkBstrA.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\SearchIndexer.exe
                    C:\Windows\system32\WUDFHost.exe
                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    C:\Windows\system32\Dwm.exe
                    C:\Windows\system32\taskeng.exe
                    C:\Program Files\Windows Defender\MSASCui.exe
                    C:\Windows\RtHDVCpl.exe
                    C:\Windows\System32\rundll32.exe
                    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                    C:\Program Files\Picasa2\PicasaMediaDetector.exe
                    C:\Windows\System32\rundll32.exe
                    C:\Program Files\Packard Bell\FIJI\ABoard.exe
                    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                    C:\Program Files\Packard Bell\FIJI\AOSD.exe
                    C:\Program Files\Windows Sidebar\sidebar.exe
                    C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                    C:\Program Files\DAEMON Tools Lite\daemon.exe
                    C:\Windows\System32\rundll32.exe
                    C:\Windows\System32\rundll32.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                    C:\Windows\system32\taskeng.exe
                    C:\Program Files\Internet Explorer\ieuser.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Windows\system32\conime.exe
                    C:\Windows\Explorer.exe
                    C:\Windows\system32\SearchProtocolHost.exe
                    C:\Windows\system32\SearchFilterHost.exe
                    C:\Windows\system32\cmd.exe
                    C:\Windows\system32\wbem\wmiprvse.exe

                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\MEKRA

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\MEKRA\Application Data

                    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\MEKRA\FAVORI~1

                    »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                    !!!Attention, following keys are not inevitably infected!!!

                    IEDFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                    !!!Attention, following keys are not inevitably infected!!!

                    VACFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                    !!!Attention, following keys are not inevitably infected!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                    !!!Attention, following keys are not inevitably infected!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                    "AppInit_DLLs"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                    !!!Attention, following keys are not inevitably infected!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                    »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                    Description: NVIDIA nForce Networking Controller
                    DNS Server Search Order: 192.168.1.1

                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{2AAB5DBD-8873-4C31-82B8-8069EA07F660}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{2AAB5DBD-8873-4C31-82B8-8069EA07F660}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{2AAB5DBD-8873-4C31-82B8-8069EA07F660}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                    »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                    »»»»»»»»»»»»»»»»»»»»»»»» End
                    0
                    1. Au fait c'était quoi ton trojan t'as le nom sa nous avancerait !
                      0
                      1. tu vas télécharger clean .

                        http://www.malekal.com/download/clean.zip
                        * Décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier dénommé "clean ".

                        * Ouvre le dossier « clean » qui se trouve sur ton bureau.
                        * Double-clic sur « clean.cmd ».
                        Une fenêtre noire va apparaître, choisis l’option 1.

                        Clean va travailler.
                        * Redémarre normalement
                        * Poste qui se trouve ici C:\rapport_clean.txt.

                        C - Ccleaner :
                        (nettoyeur de registre, cookies+temps+tempos+prefetch+historique+etc.)
                        Télécharge ici :
                        https://www.ccleaner.com/ccleaner/download
                        Tutorial ici:
                        https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
                        ET
                        http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm
                        0
                        1. j ai tout fait mais au moment ou je valide 1 un message apparait : run time error 75 : path/file access error
                          0
                          1. et du coup rien ne se passe
                            0
                            1. ?????

                              Explique avec quel programme sa marche pas.
                              0
                              • 1
                              • 2