Infécté par un Virus Heat !!!

Bonjour,

Je suis in fécté j'aimerai avoir de l'aide. Je ne m'y connais pas asser pour le faire tout seul.
J'ai téléchargé SmitFraudFix v2.319 et est fais un rapport.
Configuration: Windows XP
Internet Explorer 7.0

13 réponses

  1. Contributeur sécurité
    Salut !

    Je viens de voir ton post sur l'autre topic

    On continue !

    Option 2

    Redémarre en mode sans échec :
    Pour cela, tapotes la touche F8 (Si F8 ne marche pas utilise la touche F5).

    dès le début de l’allumage du pc sans t’arrêter.
    Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
    Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !

    comment demarrer en mode sans echec en images

    -------------------------------------------------------------------------------
    Double clique sur smitfraudfix.cmd
    Cette fois choisit l’option 2 !!
    répond oui (o) à tout

    Une fois le nettoyage terminé, SmitFraudfix ouvre le rapport de nettoyage sur le bloc-note.
    Redémarre l'ordinateur en mode normal (comme d'habitude),
    Sur le bureau doit se trouver le rapport enregistré (sinon il est sur le Poste de Travail / Disque C / rapport.txt)
    Refais un log Hitjackthis et poste les rapports s'il te plait !

    @+
    1
    1. Merci d'avoir réponu si vite .
      je t'envoie le rapport SmitFraudFix v2.319 et je m'occupe de Hitjackthis.

      Rapport fait à 9:41:23,20, 27/04/2008
      Executé à partir de C:\Documents and Settings\marie-jeanne\Bureau\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode sans echec

      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
      "{db763ed8-100a-481b-8913-50a2f41dcdc3}"="exegeses"

      »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      127.0.0.1 localhost
      127.0.0.1 bin.errorprotector.com ## added by CiD
      127.0.0.1 br.errorsafe.com ## added by CiD
      127.0.0.1 br.winantivirus.com ## added by CiD
      127.0.0.1 br.winfixer.com ## added by CiD
      127.0.0.1 cdn.drivecleaner.com ## added by CiD
      127.0.0.1 cdn.errorsafe.com ## added by CiD
      127.0.0.1 cdn.winsoftware.com ## added by CiD
      127.0.0.1 de.errorsafe.com ## added by CiD
      127.0.0.1 de.winantivirus.com ## added by CiD
      127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
      127.0.0.1 download.cdn.errorsafe.com ## added by CiD
      127.0.0.1 download.cdn.winsoftware.com ## added by CiD
      127.0.0.1 download.errorsafe.com ## added by CiD
      127.0.0.1 download.systemdoctor.com ## added by CiD
      127.0.0.1 download.winantispyware.com ## added by CiD
      127.0.0.1 download.windrivecleaner.com ## added by CiD
      127.0.0.1 download.winfixer.com ## added by CiD
      127.0.0.1 drivecleaner.com ## added by CiD
      127.0.0.1 dynamique.drivecleaner.com ## added by CiD
      127.0.0.1 errorprotector.com ## added by CiD
      127.0.0.1 errorsafe.com ## added by CiD
      127.0.0.1 es.winantivirus.com ## added by CiD
      127.0.0.1 fr.winantivirus.com ## added by CiD
      127.0.0.1 fr.winfixer.com ## added by CiD
      127.0.0.1 go.drivecleaner.com ## added by CiD
      127.0.0.1 go.errorsafe.com ## added by CiD
      127.0.0.1 go.winantispyware.com ## added by CiD
      127.0.0.1 go.winantivirus.com ## added by CiD
      127.0.0.1 hk.winantivirus.com ## added by CiD
      127.0.0.1 instlog.errorsafe.com ## added by CiD
      127.0.0.1 instlog.winantivirus.com ## added by CiD
      127.0.0.1 instlog.winfixer.com ## added by CiD
      127.0.0.1 jsp.drivecleaner.com ## added by CiD
      127.0.0.1 kb.errorsafe.com ## added by CiD
      127.0.0.1 kb.winantivirus.com ## added by CiD
      127.0.0.1 nl.errorsafe.com ## added by CiD
      127.0.0.1 se.errorsafe.com ## added by CiD
      127.0.0.1 secure.drivecleaner.com ## added by CiD
      127.0.0.1 secure.errorsafe.com ## added by CiD
      127.0.0.1 secure.winantispam.com ## added by CiD
      127.0.0.1 secure.winantispy.com ## added by CiD
      127.0.0.1 secure.winantivirus.com ## added by CiD
      127.0.0.1 support.winantivirus.com ## added by CiD
      127.0.0.1 trial.updates.winsoftware.com ## added by CiD
      127.0.0.1 ulog.winantivirus.com ## added by CiD
      127.0.0.1 utils.errorsafe.com ## added by CiD
      127.0.0.1 utils.winantivirus.com ## added by CiD
      127.0.0.1 utils.winfixer.com ## added by CiD
      127.0.0.1 winantispyware.com ## added by CiD
      127.0.0.1 winantivirus.com ## added by CiD
      127.0.0.1 winfixer.com ## added by CiD
      127.0.0.1 winfixer2006.com ## added by CiD
      127.0.0.1 winsoftware.com ## added by CiD
      127.0.0.1 www.drivecleaner.com ## added by CiD
      127.0.0.1 www.errorprotector.com ## added by CiD
      127.0.0.1 www.errorsafe.com ## added by CiD
      127.0.0.1 www.systemdoctor.com ## added by CiD
      127.0.0.1 www.utils.winfixer.com ## added by CiD
      127.0.0.1 www.win-anti-virus-pro.com ## added by CiD
      127.0.0.1 www.win-virus-pro.com ## added by CiD
      127.0.0.1 www.winantispam.com ## added by CiD
      127.0.0.1 www.winantispy.com ## added by CiD
      127.0.0.1 www.winantispyware.com ## added by CiD
      127.0.0.1 www.winantivirus.com ## added by CiD
      127.0.0.1 www.winantiviruspro.com ## added by CiD
      127.0.0.1 www.windrivecleaner.com ## added by CiD
      127.0.0.1 www.windrivesafe.com ## added by CiD
      127.0.0.1 www.winfixer.com ## added by CiD
      127.0.0.1 www.winfixer2006.com ## added by CiD
      127.0.0.1 www.winsoftware.com ## added by CiD

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

      S!Ri's WS2Fix: LSP not Found.

      »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

      GenericRenosFix by S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

      C:\WINDOWS\system32\bubbj.dll supprimé
      C:\Documents and Settings\marie-jeanne\Application Data\Microsoft\Internet Explorer\Quick Launch\VirusHeat 4.3.lnk supprimé
      C:\DOCUME~1\MARIE-~1\Favoris\Online Security Test.url supprimé
      C:\Program Files\NetProject\ supprimé
      C:\Program Files\Video ActiveX Object\ supprimé
      C:\Program Files\Video Add-on\ supprimé

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri
      C:\WINDOWS\pado32r.dll deleted.

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

      Nettoyage terminé.

      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
      "{db763ed8-100a-481b-8913-50a2f41dcdc3}"="exegeses"

      »»»»»»»»»»»»»»»»»»»»»»»» Fin
      0
  2. Contributeur sécurité
    Salut !

    Je vient de m'inscrire mais tony62 etait déja pris .

    Tu es tony62 ??

    Ceci est pour lui !

    on continue ...

    Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
    Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau.

    Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
    comment demarrer en mode sans echec en images

    Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
    A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
    Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
    Choisis ton compte.

    Déroule la liste des instructions ci-dessous :

    Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
    Appuie sur Y pour commencer le processus de nettoyage.
    Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
    Appuie sur une touche pour redémarrer le PC.
    Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
    Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
    Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
    Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
    Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum

    @+
    1
    1. Contributeur sécurité
      Supprime ta version obsolète de HijackThis via "Panneau de configuration" > "Ajout/Suppr. de programmes"

      Télécharge HIJACKTHIS <--- ici.

      C'est un outil de diagnostic pour voir si tout est en ordre ( ou pas ) sur ton pc ( MàJ, infections, etc...)

      Dézippe le dans un dossier prévu à cet effet.
      Par exemple C:\hijackthis < Enregistre le bien dans c : !
      Démo : (Merci a Balltrap34 pour cette réalisation)
      http://pageperso.aol.fr/balltrap34/Hijenr.gif

      Relance Hijackthis en double cliquant sur son raccourci sur le Bureau.
      Choisis l'option "Do a system scan and save a log file"
      voir ici

      Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
      Clique sur "Edition" ->> "Sélectionner tout", puis sur "Edition" ->> Copier" pour copier tout le contenu du rapport
      Comment fixer les lignes ou générer un rapport <---- voir ici
      Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement

      IMPERATIF !! Avant de lancer HIJACKTHIS , il faut fermer tous les programmes ouverts, se déconnecter d' INTERNET !!

      @+
      1
      1. Voici mon rapport:

        SmitFraudFix v2.319

        Rapport fait à 15:42:26,71, 26/04/2008
        Executé à partir de C:\Documents and Settings\marie-jeanne\Bureau\SmitfraudFix
        OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
        Le type du système de fichiers est NTFS
        Fix executé en mode normal

        »»»»»»»»»»»»»»»»»»»»»»»» Process

        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\Program Files\NetProject\sbmntr.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\NetProject\sbsm.exe
        C:\Program Files\Microsoft IntelliType Pro\type32.exe
        C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\Microsoft IntelliPoint\point32.exe
        C:\WINDOWS\system32\spoolsv.exe
        c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
        C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
        c:\APPS\HIDSERVICE\HIDSERVICE.exe
        C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
        C:\WINDOWS\system32\svchost.exe
        c:\APPS\Powercinema\Kernel\TV\CLSched.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\System32\alg.exe
        C:\Program Files\PSW\SurfWifi.exe
        C:\Program Files\PSW\ComComp.exe
        C:\Program Files\PSW\Watch.exe
        C:\WINDOWS\system32\ctfmon.exe
        c:\windows\system32\nhqvknzhd.exe
        C:\WINDOWS\explorer.exe
        C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
        C:\WINDOWS\system32\cmd.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe

        »»»»»»»»»»»»»»»»»»»»»»»» hosts

        »»»»»»»»»»»»»»»»»»»»»»»» C:\

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

        C:\WINDOWS\system32\bubbj.dll PRESENT !

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\marie-jeanne

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\marie-jeanne\Application Data

        C:\Documents and Settings\marie-jeanne\Application Data\Microsoft\Internet Explorer\Quick Launch\VirusHeat 4.3.lnk PRESENT !

        »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

        »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MARIE-~1\Favoris

        C:\DOCUME~1\MARIE-~1\Favoris\Online Security Test.url PRESENT !

        »»»»»»»»»»»»»»»»»»»»»»»» Bureau

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

        C:\Program Files\NetProject\ PRESENT !
        C:\Program Files\Video ActiveX Object\ PRESENT !
        C:\Program Files\Video Add-on\ PRESENT !

        »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

        »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
        "Source"="About:Home"
        "SubscribedURL"="About:Home"
        "FriendlyName"="Ma page d'accueil"

        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        IEDFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri
        +--------------------------------------------------+
        [!] Suspicious: pado32r.dll
        BHO: Pinch - {96F8931D-BB55-41DE-9AF7-257A7EB43D2A}
        CLSID: {96F8931D-BB55-41DE-9AF7-257A7EB43D2A}
        AppID: {96F8931D-BB55-41DE-9AF7-257A7EB43D2A}
        AppID: pado32r.dll
        Classes: cuskina.AVideo
        TypeLib: {7165223D-D2C9-422B-8126-411B11842B8B}
        Interface: {D263B532-C528-49E5-8BB6-80FA67332C9A}

        »»»»»»»»»»»»»»»»»»»»»»»» VACFix
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        VACFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        404Fix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
        "{db763ed8-100a-481b-8913-50a2f41dcdc3}"="exegeses"

        »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
        "AppInit_DLLs"=""

        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
        "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
        "System"=""

        »»»»»»»»»»»»»»»»»»»»»»»» Rustock

        »»»»»»»»»»»»»»»»»»»»»»»» DNS

        Description: WAN (PPP/SLIP) Interface
        DNS Server Search Order: 194.2.0.20
        DNS Server Search Order: 194.2.0.50

        HKLM\SYSTEM\CCS\Services\Tcpip\..\{B7BD63C7-3844-449F-90D0-8A3BB069204F}: NameServer=194.2.0.20 194.2.0.50
        HKLM\SYSTEM\CS1\Services\Tcpip\..\{B7BD63C7-3844-449F-90D0-8A3BB069204F}: NameServer=194.2.0.20 194.2.0.50

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

        »»»»»»»»»»»»»»»»»»»»»»»» Fin
        0
        1. Voila, ça a été un peu long je n'avez plus le programme et j'ai du le rechercher .

          Logfile of HijackThis v1.99.1
          Scan saved at 10:51:21, on 27/04/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16640)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\Explorer.EXE
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\Microsoft IntelliType Pro\type32.exe
          C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\Program Files\Microsoft IntelliPoint\point32.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\ctfmon.exe
          c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
          C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
          c:\APPS\HIDSERVICE\HIDSERVICE.exe
          C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
          C:\WINDOWS\system32\HPZipm12.exe
          C:\WINDOWS\system32\svchost.exe
          c:\APPS\Powercinema\Kernel\TV\CLSched.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\System32\alg.exe
          C:\Program Files\PSW\SurfWifi.exe
          C:\Program Files\PSW\ComComp.exe
          C:\Program Files\PSW\Watch.exe
          C:\PROGRA~1\MSNMES~1\msnmsgr.exe
          C:\Program Files\OFFICE ONE6.5\OFFICE One Zip v6\OFFICE One Zip v6.exe
          C:\Documents and Settings\marie-jeanne\Mes documents\OFFICE One Zip\hijackthis_199\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Pinch - {96F8931D-BB55-41DE-9AF7-257A7EB43D2A} - C:\WINDOWS\pado32r.dll (file missing)
          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O4 - HKLM\..\Run: [PSWWATCH] C:\PROGRA~1\PSW\Watch.exe
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
          O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
          O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
          O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
          O4 - HKCU\..\Run: [Instant Access] C:\WINDOWS\system32\nsinet.exe /res
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
          O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
          O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O11 - Options group: [INTERNATIONAL] International*
          O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
          O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
          O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
          O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
          O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
          O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
          O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
          O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

          Merci, a plus.
          0
          1. Je vient de m'inscrire mais tony62 etait déja pris .
            voila!!
            0
        2. Oui, je suis bien tony62.
          Voila le rapport SDFix

          [b]SDFix: Version 1.175 [/b]
          Run by marie-jeanne on 27/04/2008 at 13:46

          Microsoft Windows XP [version 5.1.2600]
          Running From: C:\SDFix

          [b]Checking Services [/b]:

          Restoring Windows Registry Values
          Restoring Windows Default Hosts File

          Rebooting

          [b]Checking Files [/b]:

          Trojan Files Found:

          C:\smp.bat - Deleted

          Folder C:\WINDOWS\system32\892267 - Removed

          Removing Temp Files

          [b]ADS Check [/b]:

          [b]Final Check [/b]:

          catchme 0.3.1353.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-04-27 13:56:01
          Windows 5.1.2600 Service Pack 2 NTFS

          scanning hidden processes ...

          scanning hidden services & system hive ...

          scanning hidden registry entries ...

          scanning hidden files ...

          scan completed successfully
          hidden processes: 0
          hidden services: 0
          hidden files: 9

          [b]Remaining Services [/b]:

          Authorized Application Key Export:

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
          "%ProgramFiles%\\AOL 9.0\\aol.exe"="%ProgramFiles%\\AOL 9.0\\aol.exe:*:Enabled:AOL"
          "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"="%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe:*:Enabled:SPLINTER CELL PANDORA"
          "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"="%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe:*:Enabled:PANDORA"
          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
          "C:\\APPS\\Inventime\\my.exe"="C:\\APPS\\Inventime\\my.exe:*:Enabled:INVENTIME"
          "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
          "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
          "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
          "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
          "C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"="C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe:*:Enabled:Veoh Client"
          "C:\\Program Files\\ICQLite\\ICQLite.exe"="C:\\Program Files\\ICQLite\\ICQLite.exe:*:Enabled:ICQ Lite"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
          "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
          "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

          [b]Remaining Files [/b]:

          File Backups: - C:\SDFix\backups\backups.zip

          [b]Files with Hidden Attributes [/b]:

          Sun 28 May 2006 215 A.SHR --- "C:\BOOT.BAK"
          Wed 3 May 2006 163,328 ..SHR --- "C:\WINDOWS\system32\flvDX.dll"
          Wed 21 Feb 2007 31,232 ..SHR --- "C:\WINDOWS\system32\msfDX.dll"
          Mon 17 Dec 2007 27,648 ..SH. --- "C:\WINDOWS\system32\Smab0.dll"
          Mon 4 Feb 2008 151,040 ..SH. --- "C:\WINDOWS\system32\VistaUltm.dll"
          Sat 10 Nov 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
          Sun 26 Jun 2005 616,448 ..SHR --- "C:\Program Files\eRightSoft\SUPER\cygwin1.dll"
          Tue 21 Jun 2005 45,568 ..SHR --- "C:\Program Files\eRightSoft\SUPER\cygz.dll"
          Sun 23 Mar 2008 72,704 ..SHR --- "C:\Program Files\eRightSoft\SUPER\Setup.exe"
          Fri 27 Oct 2006 15,872 A.SHR --- "C:\Program Files\eRightSoft\SUPER\_Setup.dll"
          Mon 2 Oct 2006 635 A..H. --- "C:\Program Files\InterActual\InterActual Player\iti10.tmp"
          Fri 15 Jun 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
          Tue 4 Jun 2002 84,992 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\14_43260.dll"
          Tue 4 Jun 2002 44,032 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\28_83260.dll"
          Tue 10 Dec 2002 73,766 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\atrc3260.dll"
          Tue 10 Dec 2002 65,575 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\cook3260.dll"
          Sun 9 Jun 2002 36,864 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\ddnt3260.dll"
          Tue 4 Jun 2002 20,480 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\dnet3260.dll"
          Tue 10 Dec 2002 102,437 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv13260.dll"
          Tue 10 Dec 2002 176,165 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv23260.dll"
          Tue 10 Dec 2002 208,935 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv33260.dll"
          Tue 10 Dec 2002 217,127 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv43260.dll"
          Sun 9 Jun 2002 40,448 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\dspr3260.dll"
          Sun 4 Nov 2001 225,280 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\ivvideo.dll"
          Tue 10 Apr 2001 225,280 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\qtmlClient.dll"
          Fri 20 Feb 2004 232,960 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\raac.dll"
          Sun 9 Jun 2002 525,824 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rnco3260.dll"
          Tue 10 Dec 2002 245,805 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rnlt3260.dll"
          Tue 10 Dec 2002 45,093 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv103260.dll"
          Tue 10 Dec 2002 98,341 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv203260.dll"
          Tue 10 Dec 2002 94,247 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv303260.dll"
          Tue 10 Dec 2002 90,151 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv403260.dll"
          Tue 10 Dec 2002 102,439 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\sipr3260.dll"
          Sun 9 Jun 2002 49,152 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\tokr3260.dll"
          Sun 17 Jun 2007 25,839,664 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\60ca6af11040112be1355236afadeb90\BIT11.tmp"

          [b]Finished![/b]

          Il y a aussi un autre rapport qui c'est affiché sur mon bureau : catchme.log

          catchme 0.3.1353.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-04-27 13:56:01
          Windows 5.1.2600 Service Pack 2 NTFS

          scanning hidden processes ...

          scanning hidden services & system hive ...

          scanning hidden registry entries ...

          scanning hidden files ...

          scan completed successfully
          hidden processes: 0
          hidden services: 0
          hidden files: 9

          Merci . A plus
          0
          1. Merci de répondre aussi vite.
            Voici le dernier rapport Hijackthis:

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 15:18:24, on 27/04/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16640)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
            C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
            c:\APPS\HIDSERVICE\HIDSERVICE.exe
            C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
            C:\WINDOWS\system32\HPZipm12.exe
            C:\WINDOWS\system32\svchost.exe
            c:\APPS\Powercinema\Kernel\TV\CLSched.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\Program Files\Microsoft IntelliType Pro\type32.exe
            C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
            C:\WINDOWS\SOUNDMAN.EXE
            C:\Program Files\Microsoft IntelliPoint\point32.exe
            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Pinch - {96F8931D-BB55-41DE-9AF7-257A7EB43D2A} - C:\WINDOWS\pado32r.dll (file missing)
            O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O4 - HKLM\..\Run: [PSWWATCH] C:\PROGRA~1\PSW\Watch.exe
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
            O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
            O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
            O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            O4 - HKCU\..\Run: [Instant Access] C:\WINDOWS\system32\nsinet.exe /res
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [nhqvknzhd] c:\windows\system32\nhqvknzhd.exe nhqvknzhd
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
            O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
            O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O22 - SharedTaskScheduler: exegeses - {db763ed8-100a-481b-8913-50a2f41dcdc3} - (no file)
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
            O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
            O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
            O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
            O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
            0
            1. Contributeur sécurité
              Télécharge navilog.exe << ICI
              Choisis Enregistrer sous.... et enregistre-le sur ton bureau.
              Ensuite double clique sur navilog1.exe pour lancer l'installation.
              Une fois l'installation terminée, fais un Clic-droit sur le raccourci Navilog1 présent sur ton Bureau .

              Laisse-toi guider. Au menu principal, choisis 1 et valides.
              (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

              Patiente jusqu'au message :
              *** Analyse Termine le ..... ***
              Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
              Copie-colle l'intégralité du rapport dans ta réponse. Referme le blocnote.
              Le rapport est en outre sauvegardé à la racine du disque C:\ (fixnavi.txt)

              @+
              0
              1. Voila le rapport navilog

                Search Navipromo version 3.5.5 commencé le 27/04/2008 à 19:57:13,53

                !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                !!! Postez ce rapport sur le forum pour le faire analyser !!!
                !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                Outil exécuté depuis C:\Program Files\navilog1
                Session actuelle : "marie-jeanne"

                Mise à jour le 27.04.2008 à 10h00 par IL-MAFIOSO

                Microsoft Windows XP [version 5.1.2600]
                Internet Explorer : 7.0.5730.11
                Système de fichiers : NTFS

                Executé en mode normal

                *** Recherche Programmes installés ***

                Instant Access

                *** Recherche dossiers dans "C:\WINDOWS" ***

                *** Recherche dossiers dans "C:\Program Files" ***

                *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                *** Recherche dossiers dans "c:\docume~1\alluse~1\menudÉ~1\progra~1" ***

                *** Recherche dossiers dans "C:\Documents and Settings\marie-jeanne\applic~1" ***

                *** Recherche dossiers dans "C:\DOCUME~1\PROPRI~1\applic~1" ***

                *** Recherche dossiers dans "C:\Documents and Settings\marie-jeanne\locals~1\applic~1" ***

                *** Recherche dossiers dans "C:\Documents and Settings\marie-jeanne\menudm~1\progra~1" ***

                *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                pour + d'infos : http://www.gmer.net

                Fichier(s) caché(s) :

                C:\WINDOWS\system32\fretimnou.dat
                C:\WINDOWS\system32\fretimnou.exe
                C:\WINDOWS\system32\fretimnou_nav.dat
                C:\WINDOWS\system32\fretimnou_navps.dat

                *** Recherche avec GenericNaviSearch ***
                !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                !!! A vérifier impérativement avant toute suppression manuelle !!!

                * Recherche dans "C:\WINDOWS\system32" *

                Fichiers trouvés :

                fretimnou.exe trouvé !

                Fichiers suspects :

                nsinet.exe trouvé !

                * Recherche dans "C:\Documents and Settings\marie-jeanne\locals~1\applic~1" *

                *** Recherche fichiers ***

                C:\WINDOWS\system32\nvs2.inf trouvé !

                *** Recherche clés spécifiques dans le Registre ***

                *** Module de Recherche complémentaire ***
                (Recherche fichiers spécifiques)

                1)Recherche nouveaux fichiers Instant Access :

                C:\WINDOWS\system32\nsinet.exe trouvé !

                2)Recherche Heuristique :

                * Dans "C:\WINDOWS\system32" :

                fretimnou.dat trouvé !
                nhqvknzhd.dat trouvé !

                * Dans "C:\Documents and Settings\marie-jeanne\locals~1\applic~1" :

                3)Recherche Certificats :

                Certificat Egroup absent !
                Certificat Electronic-Group trouvé !
                Certificat OOO-Favorit absent !
                Certificat Sunny-Day-Design-Ltd absent !

                4)Recherche fichiers connus :

                *** Analyse terminée le 27/04/2008 à 20:01:19,32 ***

                merci a plus
                0
                1. Contributeur sécurité
                  On continue :

                  Option 2

                  Double cliques sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
                  Au menu principal, choisis 2 et valides.

                  Le fix va t'informer qu'il va alors redémarrer ton PC
                  Fermes toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts.
                  Appuies sur une touche comme demandé.
                  (si ton Pc ne redémarre pas automatiquement, fais le toi même)
                  Au redémarrage de ton PC, choisis ta session habituelle.

                  Patiente jusqu'au message :
                  *** Nettoyage Termine le ..... ***
                  Le bloc-notes va s'ouvrir.
                  Sauvegarde le rapport de manière à le retrouver
                  Referme le bloc-notes. Ton bureau va réapparaitre

                  PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
                  Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
                  Tape explorer et valide. Celà te fera apparaitre ton bureau.

                  Poste le rapport ici.

                  Ferme internet explorer puis Démarrer/panneau de configuration/options internet
                  - onglet "Contenu" puis onglet "Certificats" et si tu trouves ceci, en particulier dans "éditeurs approuvés", mais regarde ailleurs :

                  electronic-group
                  egroup
                  Montorgueil
                  VIP
                  "Sunny Day Design Ltd"
                  Certificat OOO-Favorit


                  Tu les supprimes.

                  Reposte moi un nouvel Hijackthis...

                  @+
                  0
                  1. Désolé mais je ne vais pas pouvoir continuer ce soir et ne pourrai t'envoyé les rapport que mercredi aprés-midi.
                    merci de l'aide que tu m'a apporté il y a déja un net progrés.

                    A mercredi
                    0
                    1. Contributeur sécurité
                      ok, je serais là a partir de 17h

                      @+
                      0
                      1. Bonjour j'ai pus me libérer plus tot .

                        J'ai un probléme avec navilog1 ,je le lance et ça ne fais rien et quand je redémarre mon ordi il n se passe rien non plus dois relancer navilog ou faire autre chose .

                        merci
                        0