Viirus heat et winspykiller

Résolu
Bonjour,

Depuis hier je suis infecté par virus heat et winspykiller et j'arrive pas à m'en débarrasser !
Les messages SYSTEM ALERT continu et mon PC est hyper lent ...
Avez-vous une solution ?

Merci pour votre aide .
Configuration: Windows XP
Internet Explorer 7.0

31 réponses

Résumé de la discussion

Infection par les virus Heat et WinSpyKiller provoquant des alertes système constantes et une lenteur marquée du PC sous Windows XP et Internet Explorer 7, avec messages SYSTEM ALERT. Plusieurs utilisateurs suggèrent d'analyser les fichiers suspects avec VirusTotal et d'extraire des rapports, puis d'utiliser HijackThis pour repérer les entrées malveillantes dans le journal des résultats. En cas de détection, certains recommandent des outils de suppression comme SmitFraudfix ou des nettoyages via des analyses antivirus en mode hors ligne, puis de redémarrer proprement. D'autres interviennent avec des rapports HijackThis supplémentaires et notent que la présence d'alertes peut refléter des démarrages automatiques persistants, nécessitant une vérification des éléments de démarrage et des services.

Bobot (l’IA à votre service)
  1. slt,

    Télécharge sur le bureau hijackthis

    Fait un clic droit sur l'icone hijackthis.

    /!\Renome hijackthis en skim.exe ( a le place de hijacktihs.exe) c'est important!!/!\

    *Après avoir fais ca double-clic dessus.

    *Clic sur Do a system scan and save the log

    *A la fin de l'analyse un rapport va etre générer colle le ici.

    Une démo d'hijackthis
    0
    1. Voici mon rapport :

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 12:43:35, on 19/04/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16640)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv51.exe
      C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wdfmgr.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\NetProject\scit.exe
      C:\Program Files\NetProject\sbmntr.exe
      C:\Program Files\NetProject\scm.exe
      C:\WINDOWS\System32\igfxtray.exe
      C:\Program Files\NetProject\sbsm.exe
      C:\WINDOWS\System32\hkcmd.exe
      C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Progra~1\Launch Manager\LaunchAp.exe
      C:\Progra~1\Launch Manager\PowerKey.exe
      C:\Progra~1\Launch Manager\HotkeyApp.exe
      C:\Progra~1\Launch Manager\CtrlVol.exe
      C:\Progra~1\Launch Manager\Wbutton.exe
      C:\Program Files\Acer\Notebook Manager\almxptray.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\ltmoh\Ltmoh.exe
      C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
      C:\WINDOWS\mrofinu1423.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\UberIcon\UberIcon Manager.exe
      C:\Documents and Settings\Homer\Application Data\SpeedRunner\SpeedRunner.exe
      C:\Documents and Settings\Homer\Application Data\Microsoft\Windows\jmkoqv.exe
      C:\Program Files\Twain\Twain.exe
      C:\Documents and Settings\Homer\Application Data\WinTouch\WinTouch.exe
      C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      c:\program files\panda software\panda antivirus 2007\WebProxy.exe
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\NetProject\sbsm.exe
      C:\DOCUME~1\Homer\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk32.exe
      C:\DOCUME~1\Homer\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fssm32.exe
      C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\WINDOWS\System32\wbem\wmiprvse.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/toolbar/ie8/sidebar.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/toolbar/ie8/sidebar.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.acer.com/worldwide/selection.html
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\^^^^^.exe
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: 892267 helper - {25E0128D-AAFC-49FF-AB11-1F12C2FCC391} - (no file)
      O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll
      O2 - BHO: (no name) - {7C109800-A5D5-438F-9640-18D17E168B88} - C:\Program Files\NetProject\sbmdl.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: Internet Service - {51D81DD5-55B7-497F-95DB-D356429BB54E} - C:\Program Files\NetProject\wamdl.dll
      O4 - HKLM\..\Run: [LaunchApp] LaunApp
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
      O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [LaunchAp] C:\Progra~1\Launch Manager\LaunchAp.exe
      O4 - HKLM\..\Run: [PowerKey] "C:\Progra~1\Launch Manager\PowerKey.exe"
      O4 - HKLM\..\Run: [LManager] C:\Progra~1\Launch Manager\HotkeyApp.exe
      O4 - HKLM\..\Run: [CtrlVol] C:\Progra~1\Launch Manager\CtrlVol.exe
      O4 - HKLM\..\Run: [Wbutton] "C:\Progra~1\Launch Manager\Wbutton.exe"
      O4 - HKLM\..\Run: [AcerNotebookManager] C:\Program Files\Acer\Notebook Manager\almxptray.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
      O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE" /s
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1423.exe 61A847B5BBF7281336993B466188719AB689201522886B092CBD44BD8689220221DD325762E901F3D1DC7E4638E8323A15806F97BDE4417E6FD967002BA754E2C681210C67D36D
      O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\^^^^^.exe
      O4 - HKLM\..\RunOnce: [Panda_cleaner_168056] C:\Program Files\Panda Software\Panda Antivirus 2007\pavdr.exe 168056
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe"
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [SpeedRunner] C:\Documents and Settings\Homer\Application Data\SpeedRunner\SpeedRunner.exe
      O4 - HKCU\..\Run: [SfKg6wIP] C:\Documents and Settings\Homer\Application Data\Microsoft\Windows\jmkoqv.exe
      O4 - HKCU\..\Run: [Twain] C:\Program Files\Twain\Twain.exe
      O4 - HKCU\..\Run: [WinTouch] C:\Documents and Settings\Homer\Application Data\WinTouch\WinTouch.exe
      O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe
      O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\NetProject\sbmntr.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
      O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
      O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.gateietool.com/redirect.php (file missing)
      O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.gateietool.com/redirect.php (file missing)
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
      O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
      O22 - SharedTaskScheduler: exegeses - {db763ed8-100a-481b-8913-50a2f41dcdc3} - C:\WINDOWS\system32\bubbj.dll
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv51.exe
      O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
      0
      1. ok plusieurs cochonneries

        Télécharge, puis installe MSNFix : http://sosvirus.changelog.fr/MSNFix.zip , tuto de Malekal
        - Décompresse donc le dossier zip MSNFix et lance le fichier "MSNFix.bat". Une fenêtre bleue doit apparaitre.
        - Mets l'interface en français en appuyant sur la touche F puis sur Entrée.
        - Lance la recherche de virus en appuyant sur la touche R puis sur Entrée.
        Si un virus est détecté, il te sera alors demandé de nettoyer l'ordinateur.
        Un message d'erreur concernant la suppression impossible d'un fichier sera résolu par un redémarrage.
        Après le nettoyage, la barre "Démarrer" s'efface puis réapparait, cela fait partie de la procédure de nettoyage.
        - Poste le rapport qui s'ouvre en fin de nettoyage sur le forum stp.

        Si ta barre "Démarrer" ne s'affiche toujours pas, il suffit de faire :
        Ctrl + Alt + Suppr (sous Windows XP), ou Ctrl + Maj + Echap (sous Windows Vista) pour ouvrir le Gestionnaire de tâches Windows.
        - Fais ensuite "Fichier", puis "Nouvelle tâche" et entre explorer.exe dans la fenêtre qui apparait et finis par "OK".

        - redémarre ton ordinateur pour achever le nettoyage !
        0
        1. Voici le second rapport :
          MSNFix 1.707

          C:\Documents and Settings\Homer\Bureau\MSNFix\MSNFix
          Fix exécuté le 19/04/2008 - 12:56:19,00 By Homer
          mode normal

          ************************ Recherche les fichiers présents

          ... C:\WINDOWS\system32\^^^^^.exe
          ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\wintouch.cfg
          ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\WTUninstaller.exe
          ... C:\Program Files\CPV\CPV8.dll
          ... C:\WINDOWS\b153.exe
          ... C:\WINDOWS\b156.exe
          ... C:\DOCUME~1\Homer\APPLIC~1\SpeedRunner\config.cfg
          ... C:\DOCUME~1\Homer\APPLIC~1\SpeedRunner\SRUninstall.exe
          ... C:\Program Files\Twain\Twain.exe
          ... C:\Program Files\Twain\Twain.exe
          ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\wintouch.cfg
          ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\WinTouch.exe
          ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\WTUninstaller.exe
          ... C:\Program Files\CPV\CPV7.dll
          ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\wintouch.cfg
          ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\WinTouch.exe
          ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\WTUninstaller.exe
          ... C:\WINDOWS\b???.exe
          ... C:\WINDOWS\mrofinu*.exe
          ... C:\WINDOWS\system32\real.txt
          ... C:\WINDOWS\system32\spooIsv.exe

          ************************ Recherche les dossiers présents

          ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\
          ... C:\Program Files\CPV\
          ... C:\Program Files\Temporary\
          ... C:\DOCUME~1\Homer\APPLIC~1\SpeedRunner\
          ... C:\Program Files\Twain\
          ... C:\Program Files\Inet_Get_2\
          ... \TEMP\
          ... C:\Program Files\InetGet2\
          ... C:\Program Files\Temporary\
          ... C:\Program Files\CPV\
          ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\

          ************************ Suppression des fichiers

          .. OK ... C:\WINDOWS\system32\^^.exe
          /!\ ... C:\WINDOWS\system32\^^^^^.exe
          /!\ ... C:\WINDOWS\system32\^^^^^.exe
          /!\ ... C:\WINDOWS\system32\^^^^^.exe
          .. OK ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\wintouch.cfg
          .. OK ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\WTUninstaller.exe
          .. OK ... C:\Program Files\CPV\CPV8.dll
          .. OK ... C:\WINDOWS\b153.exe
          .. OK ... C:\WINDOWS\b156.exe
          .. OK ... C:\DOCUME~1\Homer\APPLIC~1\SpeedRunner\config.cfg
          .. OK ... C:\DOCUME~1\Homer\APPLIC~1\SpeedRunner\SRUninstall.exe
          .. OK ... C:\Program Files\Twain\Twain.exe
          .. OK ... C:\Program Files\Twain\Twain.exe
          .. OK ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\wintouch.cfg
          /!\ ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\WinTouch.exe
          .. OK ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\WTUninstaller.exe
          .. OK ... C:\Program Files\CPV\CPV7.dll
          .. OK ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\wintouch.cfg
          /!\ ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\WinTouch.exe
          .. OK ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\WTUninstaller.exe
          /!\ ... C:\WINDOWS\b???.exe
          .. OK ... C:\WINDOWS\mrofinu*.exe
          .. OK ... C:\WINDOWS\system32\real.txt
          .. OK ... C:\WINDOWS\system32\spooIsv.exe

          ************************ Suppression des dossiers

          /!\ ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\
          /!\ ... C:\Program Files\CPV\
          .. OK ... C:\Program Files\Temporary\
          /!\ ... C:\DOCUME~1\Homer\APPLIC~1\SpeedRunner\
          /!\ ... C:\Program Files\Twain\
          .. OK ... C:\Program Files\Inet_Get_2\
          /!\ ... \TEMP\
          .. OK ... C:\Program Files\InetGet2\
          .. OK ... C:\Program Files\Temporary\
          /!\ ... C:\Program Files\CPV\
          /!\ ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\

          ************************ Nettoyage du registre

          Les fichiers encore présents seront supprimés au prochain redémarrage

          ************************ Suppression des fichiers

          .. OK ... C:\DOCUME~1\Homer\APPLIC~1\SpeedRunner\SRUninstall.exe
          .. OK ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\WinTouch.exe
          .. OK ... C:\DOCUME~1\Homer\APPLIC~1\WinTouch\WinTouch.exe
          .. OK ... C:\WINDOWS\b???.exe
          .. OK ... C:\WINDOWS\system32\^^.exe

          ************************ Fichiers suspects

          Aucun Fichier trouvé

          Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 19042008_13021104.zip

          ************************ HKLM\...\Winlogon\Userinit

          Userinit = C:\WINDOWS\system32\userinit.exe,

          ------------------------------------------------------------------------
          Auteur : !aur3n7 Contact: https://www.ionos.fr/
          ------------------------------------------------------------------------

          --------------------------------------------- END ---------------------------------------------
          0
          1. ok refait un hijackthis et on passe a la suite
            0
            1. OK
              Je fait : "Do a system scan only"
              0
              1. *Clic sur Do a system scan and save the log
                0
                1. OK ! Voila le rapport :

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 13:18:21, on 19/04/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv51.exe
                  C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
                  C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\notepad.exe
                  C:\Program Files\NetProject\scit.exe
                  C:\Program Files\NetProject\scm.exe
                  C:\Program Files\NetProject\sbmntr.exe
                  C:\Program Files\NetProject\sbsm.exe
                  C:\WINDOWS\System32\igfxtray.exe
                  C:\WINDOWS\System32\hkcmd.exe
                  C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Progra~1\Launch Manager\LaunchAp.exe
                  C:\Progra~1\Launch Manager\PowerKey.exe
                  C:\Progra~1\Launch Manager\HotkeyApp.exe
                  C:\Progra~1\Launch Manager\CtrlVol.exe
                  C:\Progra~1\Launch Manager\Wbutton.exe
                  C:\Program Files\Acer\Notebook Manager\almxptray.exe
                  C:\WINDOWS\AGRSMMSG.exe
                  C:\Program Files\ltmoh\Ltmoh.exe
                  C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\UberIcon\UberIcon Manager.exe
                  C:\Documents and Settings\Homer\Application Data\SpeedRunner\SpeedRunner.exe
                  C:\Documents and Settings\Homer\Application Data\Microsoft\Windows\jmkoqv.exe
                  C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                  c:\program files\panda software\panda antivirus 2007\WebProxy.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\Program Files\Panda Software\Panda Antivirus 2007\psimreal.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/toolbar/ie8/sidebar.html
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/toolbar/ie8/sidebar.html
                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
                  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.acer.com/worldwide/selection.html
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                  O2 - BHO: 892267 helper - {25E0128D-AAFC-49FF-AB11-1F12C2FCC391} - (no file)
                  O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll
                  O2 - BHO: (no name) - {7C109800-A5D5-438F-9640-18D17E168B88} - C:\Program Files\NetProject\sbmdl.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: Internet Service - {51D81DD5-55B7-497F-95DB-D356429BB54E} - C:\Program Files\NetProject\wamdl.dll
                  O4 - HKLM\..\Run: [LaunchApp] LaunApp
                  O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                  O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [LaunchAp] C:\Progra~1\Launch Manager\LaunchAp.exe
                  O4 - HKLM\..\Run: [PowerKey] "C:\Progra~1\Launch Manager\PowerKey.exe"
                  O4 - HKLM\..\Run: [LManager] C:\Progra~1\Launch Manager\HotkeyApp.exe
                  O4 - HKLM\..\Run: [CtrlVol] C:\Progra~1\Launch Manager\CtrlVol.exe
                  O4 - HKLM\..\Run: [Wbutton] "C:\Progra~1\Launch Manager\Wbutton.exe"
                  O4 - HKLM\..\Run: [AcerNotebookManager] C:\Program Files\Acer\Notebook Manager\almxptray.exe
                  O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                  O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
                  O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE" /s
                  O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe"
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [SpeedRunner] C:\Documents and Settings\Homer\Application Data\SpeedRunner\SpeedRunner.exe
                  O4 - HKCU\..\Run: [SfKg6wIP] C:\Documents and Settings\Homer\Application Data\Microsoft\Windows\jmkoqv.exe
                  O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe
                  O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\NetProject\sbmntr.exe
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                  O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                  O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                  O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                  O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                  O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.gateietool.com/redirect.php (file missing)
                  O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.gateietool.com/redirect.php (file missing)
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                  O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                  O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
                  O22 - SharedTaskScheduler: exegeses - {db763ed8-100a-481b-8913-50a2f41dcdc3} - C:\WINDOWS\system32\bubbj.dll
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv51.exe
                  O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
                  0
                  1. ok maintenant :

                    télécharge smitfraudfix: smitfraudfix

                    # Double clique sur l'icone de smitfraud pui choisis l'option 1 et poste le rapport.

                    Tient moi au courant a+.
                    0
                    1. Voici le rapport de smitfraudix :
                      SmitFraudFix v2.315

                      Rapport fait à 13:24:12,01, 19/04/2008
                      Executé à partir de C:\Documents and Settings\Homer\Bureau\SmitfraudFix
                      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                      Le type du système de fichiers est FAT32
                      Fix executé en mode normal

                      »»»»»»»»»»»»»»»»»»»»»»»» Process

                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv51.exe
                      C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
                      C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\notepad.exe
                      C:\Program Files\NetProject\scit.exe
                      C:\Program Files\NetProject\scm.exe
                      C:\Program Files\NetProject\sbmntr.exe
                      C:\Program Files\NetProject\sbsm.exe
                      C:\WINDOWS\System32\igfxtray.exe
                      C:\WINDOWS\System32\hkcmd.exe
                      C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\Progra~1\Launch Manager\LaunchAp.exe
                      C:\Progra~1\Launch Manager\PowerKey.exe
                      C:\Progra~1\Launch Manager\HotkeyApp.exe
                      C:\Progra~1\Launch Manager\CtrlVol.exe
                      C:\Progra~1\Launch Manager\Wbutton.exe
                      C:\Program Files\Acer\Notebook Manager\almxptray.exe
                      C:\WINDOWS\AGRSMMSG.exe
                      C:\Program Files\ltmoh\Ltmoh.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\UberIcon\UberIcon Manager.exe
                      C:\Documents and Settings\Homer\Application Data\SpeedRunner\SpeedRunner.exe
                      C:\Documents and Settings\Homer\Application Data\Microsoft\Windows\jmkoqv.exe
                      C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\Program Files\Panda Software\Panda Antivirus 2007\psimreal.exe
                      C:\Program Files\Panda Software\Panda Antivirus 2007\avciman.exe
                      C:\WINDOWS\system32\cmd.exe

                      »»»»»»»»»»»»»»»»»»»»»»»» hosts

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                      C:\WINDOWS\system32\bubbj.dll PRESENT !
                      C:\WINDOWS\system32\892267\ PRESENT !

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Homer

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Homer\Application Data

                      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\HOMER\FAVORIS

                      C:\DOCUME~1\HOMER\FAVORIS\Online Security Test.url PRESENT !

                      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                      C:\Program Files\NetProject\ PRESENT !

                      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                      "Source"="About:Home"
                      "SubscribedURL"="About:Home"
                      "FriendlyName"="Ma page d'accueil"

                      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      IEDFix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      VACFix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                      "{db763ed8-100a-481b-8913-50a2f41dcdc3}"="exegeses"

                      [HKEY_CLASSES_ROOT\CLSID\{db763ed8-100a-481b-8913-50a2f41dcdc3}\InProcServer32]
                      @="C:\WINDOWS\system32\bubbj.dll"

                      [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{db763ed8-100a-481b-8913-50a2f41dcdc3}\InProcServer32]
                      @="C:\WINDOWS\system32\bubbj.dll"

                      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                      "AppInit_DLLs"=""

                      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                      "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                      "System"=""

                      »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                      »»»»»»»»»»»»»»»»»»»»»»»» DNS

                      Description: Realtek RTL8139/810x Family Fast Ethernet NIC - Miniport d'ordonnancement de paquets
                      DNS Server Search Order: 82.216.111.125
                      DNS Server Search Order: 82.216.111.121
                      DNS Server Search Order: 82.216.111.122

                      HKLM\SYSTEM\CCS\Services\Tcpip\..\{97D7574E-CDB6-4D56-8A51-47870A9486D1}: DhcpNameServer=82.216.111.125 82.216.111.121 82.216.111.122
                      HKLM\SYSTEM\CS1\Services\Tcpip\..\{97D7574E-CDB6-4D56-8A51-47870A9486D1}: DhcpNameServer=82.216.111.125 82.216.111.121 82.216.111.122
                      HKLM\SYSTEM\CS2\Services\Tcpip\..\{97D7574E-CDB6-4D56-8A51-47870A9486D1}: DhcpNameServer=82.216.111.125 82.216.111.121 82.216.111.122
                      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=82.216.111.125 82.216.111.121 82.216.111.122
                      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=82.216.111.125 82.216.111.121 82.216.111.122
                      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=82.216.111.125 82.216.111.121 82.216.111.122

                      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                      »»»»»»»»»»»»»»»»»»»»»»»» Fin
                      0
                      1. On continue,

                        Redémarre ton ordinateur en mode sans échec
                        Ouvre le dossier SmitfraudFix
                        Double clic sur Smitfraud.cmd choisis l'option 2 et Entrée
                        Réponds O aux deux questions suivantes:
                        -Voulez-vous nettoyer le registre ?
                        -Corriger le fichier infecté ?
                        Un rapport.txt sera généré et tu le postes pour contrôle.
                        0
                        1. Pas mal ! Les messages ne s'affiche plus ! Bref je sais pas si l'on a fini mais voici le rapport :
                          SmitFraudFix v2.315

                          Rapport fait à 13:53:07,14, 19/04/2008
                          Executé à partir de C:\Documents and Settings\Homer\Bureau\SmitfraudFix
                          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                          Le type du système de fichiers est FAT32
                          Fix executé en mode sans echec

                          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                          "{db763ed8-100a-481b-8913-50a2f41dcdc3}"="exegeses"

                          [HKEY_CLASSES_ROOT\CLSID\{db763ed8-100a-481b-8913-50a2f41dcdc3}\InProcServer32]
                          @="C:\WINDOWS\system32\bubbj.dll"

                          [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{db763ed8-100a-481b-8913-50a2f41dcdc3}\InProcServer32]
                          @="C:\WINDOWS\system32\bubbj.dll"

                          »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                          »»»»»»»»»»»»»»»»»»»»»»»» hosts

                          127.0.0.1 localhost

                          »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                          VACFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                          S!Ri's WS2Fix: LSP not Found.
                          »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                          GenericRenosFix by S!Ri

                          C:\WINDOWS\system32\bubbj.dll -> Hoax.Win32.Renos.gen.o
                          C:\WINDOWS\system32\bubbj.dll -> Deleted

                          »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                          C:\WINDOWS\system32\892267\ supprimé
                          C:\DOCUME~1\HOMER\FAVORIS\Online Security Test.url supprimé
                          C:\Program Files\NetProject\ supprimé

                          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                          IEDFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» DNS

                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{97D7574E-CDB6-4D56-8A51-47870A9486D1}: DhcpNameServer=82.216.111.125 82.216.111.121 82.216.111.122
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{97D7574E-CDB6-4D56-8A51-47870A9486D1}: DhcpNameServer=82.216.111.125 82.216.111.121 82.216.111.122
                          HKLM\SYSTEM\CS2\Services\Tcpip\..\{97D7574E-CDB6-4D56-8A51-47870A9486D1}: DhcpNameServer=82.216.111.125 82.216.111.121 82.216.111.122
                          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=82.216.111.125 82.216.111.121 82.216.111.122
                          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=82.216.111.125 82.216.111.121 82.216.111.122
                          HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=82.216.111.125 82.216.111.121 82.216.111.122

                          »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                          "System"=""

                          »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                          Nettoyage terminé.

                          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» Fin
                          0
                          1. Voila !

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 14:10:48, on 19/04/2008
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv51.exe
                            C:\Program Files\Panda Software\Panda Antivirus 2007\AVENGINE.EXE
                            C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\WINDOWS\System32\igfxtray.exe
                            C:\WINDOWS\System32\hkcmd.exe
                            C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            C:\Progra~1\Launch Manager\LaunchAp.exe
                            C:\Progra~1\Launch Manager\PowerKey.exe
                            C:\Progra~1\Launch Manager\HotkeyApp.exe
                            C:\Progra~1\Launch Manager\CtrlVol.exe
                            C:\Progra~1\Launch Manager\Wbutton.exe
                            C:\Program Files\Acer\Notebook Manager\almxptray.exe
                            C:\WINDOWS\AGRSMMSG.exe
                            C:\Program Files\ltmoh\Ltmoh.exe
                            C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\UberIcon\UberIcon Manager.exe
                            C:\Documents and Settings\Homer\Application Data\SpeedRunner\SpeedRunner.exe
                            C:\Documents and Settings\Homer\Application Data\Microsoft\Windows\jmkoqv.exe
                            C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                            c:\program files\panda software\panda antivirus 2007\WebProxy.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                            C:\Program Files\Panda Software\Panda Antivirus 2007\psimreal.exe
                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.acer.com/worldwide/selection.html
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                            O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll
                            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                            O4 - HKLM\..\Run: [LaunchApp] LaunApp
                            O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
                            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                            O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            O4 - HKLM\..\Run: [LaunchAp] C:\Progra~1\Launch Manager\LaunchAp.exe
                            O4 - HKLM\..\Run: [PowerKey] "C:\Progra~1\Launch Manager\PowerKey.exe"
                            O4 - HKLM\..\Run: [LManager] C:\Progra~1\Launch Manager\HotkeyApp.exe
                            O4 - HKLM\..\Run: [CtrlVol] C:\Progra~1\Launch Manager\CtrlVol.exe
                            O4 - HKLM\..\Run: [Wbutton] "C:\Progra~1\Launch Manager\Wbutton.exe"
                            O4 - HKLM\..\Run: [AcerNotebookManager] C:\Program Files\Acer\Notebook Manager\almxptray.exe
                            O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                            O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
                            O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE" /s
                            O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe"
                            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            O4 - HKCU\..\Run: [SpeedRunner] C:\Documents and Settings\Homer\Application Data\SpeedRunner\SpeedRunner.exe
                            O4 - HKCU\..\Run: [SfKg6wIP] C:\Documents and Settings\Homer\Application Data\Microsoft\Windows\jmkoqv.exe
                            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                            O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                            O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                            O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                            O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                            O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
                            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                            O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus 2007\pavsrv51.exe
                            O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus 2007\PsImSvc.exe
                            0
                            1. Va sur virustotal et fais analyser ces fichiers: Colle les rapport !!

                              C:\Documents and Settings\Homer\Application Data\SpeedRunner\SpeedRunner.exe
                              C:\Documents and Settings\Homer\Application Data\Microsoft\Windows\jmkoqv.exe

                              https://www.virustotal.com/gui/

                              Pas de pare feu ?
                              0
                              1. Rapport SpeedRunner.exe : http://www.virustotal.com/fr/analisis/c8fd75eca285624e6e8aefb2a1d02a79

                                Rapport jmkoqv.exe : Quand j'envoie le fichier aprés ça me dit : 0 bytes size received j'ai essayé plusieurs fois ça me dit tout le tempslamême chose .

                                J'ai le pare feu normele de Windows et j'ai Panda antivirus 2007 version test.
                                0
                                1. J'ai un RDV j'repasserai ce soir !
                                  Merci beaucoup ! Et j'éspère a ce soir !
                                  0
                                  1. ok

                                    télécharge OTMoveIt OTMoveit sur ton Bureau.
                                    double-clique sur OTMoveIt.exe pour le lancer.
                                    copie la liste qui se trouve en citation ci-dessous,

                                    CITATION

                                    C:\Documents and Settings\Homer\Application Data\SpeedRunner\SpeedRunner.exe

                                    et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.
                                    clique sur MoveIt! pour lancer la suppression.
                                    le résultat apparaitra dans le cadre "Results".
                                    clique sur Exit pour fermer.
                                    poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                                    il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
                                    0
                                    1. Le lien OTMoveIt n'est plus valide mais je l'ai trouvé sur le net bref !

                                      Voici le rapport situé dans C:\_OTMoveIt\MovedFiles.

                                      File move failed. C:\Documents and Settings\Homer\Application Data\SpeedRunner\SpeedRunner.exe scheduled to be moved on reboot.

                                      Created on 04/19/2008 18:46:55
                                      0
                                      • 1
                                      • 2