Urgent besoin d'aide centre de sécu inactif

Résolu
Bonjour,

Voila mon centre de sécurité est inactif et je n'arrive pas a l'activé. De plus, au démarage de windows, j'ai le message d'erreur suivant : "services.exe a cessé de fonctionner" et windows me detecte le virus Win32/Small.CA

J'ai deja essayé de désinstalleer l'antivirus (Avast!) et j'ai mis Antivir, j'ai fait une analyse complète mais rien n'a changé :s

Svp aidez moi
Configuration: Windows Vista
Firefox 2.0.0.14

46 réponses

Résumé de la discussion

Le souci porte sur le centre de sécurité inactif sous Windows Vista et sur message d’erreur au démarrage indiquant que services.exe a cessé de fonctionner, avec la détection d’un virus Win32/Small.CA. Des conseils initiaux recommandent de passer en mode sans échec et d’utiliser Malwarebytes pour un examen complet, puis d’employer CCleaner afin de nettoyer les restes éventuels et optimiser le système. D’autres réponses évoquent l’analyse et la suppression des menaces, le contrôle des rapports et l’éventuelle vérification des fichiers système (SFC) après que l’intégrité a été signalée comme violée. En cas de persistance, la discussion suggère parfois une vérification plus approfondie et envisage une réinstallation ou une réparation du système lorsque les outils standards détectent des violations non résolues.

Bobot (l’IA à votre service)
  1. Contributeur
    Bonjour

    pour commencer
    Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

    - Vas dans "Démarrer" puis Panneau de configuration.
    - Double Clique sur l'icône Comptes d'utilisateurs et sur Activer ou désactiver le contrôle des comptes d'utilisateurs.
    - Clique sur Continuer.
    - Décoche la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
    - Valide par OK et redémarre.

    ensuite

    Télécharge sur le bureau

    ftp://ftp.commentcamarche.com/download/HJTInstall.exe

    = Double-clic dessus pour l'installer
    = Clic Do a system scan and save the log
    =coller le rapport
    si problème voir l'aide
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

    @+
    0
    1. Ok je fais ca et je reviens ds 5 min merci a tte suite
      0
      1. Voila

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 11:51:43, on 08/05/2008
        Platform: Windows Vista (WinNT 6.00.1904)
        MSIE: Internet Explorer v7.00 (7.00.6000.16643)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
        C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
        C:\Program Files\Microsoft IntelliType Pro\itype.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Windows\System32\DBR122\services.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
        C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
        C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        O1 - Hosts: ::1 localhost
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
        O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [Windows Security Center 1.22] C:\Windows\system32\DBR122\services.exe
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O13 - Gopher Prefix:
        O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
        O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/fr-fr/wlscctrl2.cab
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
        O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
        O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
        0
        1. ep44 tu es la ?

          Svp aidez moi je suis en panique :s
          0
          1. Contributeur
            pour commencer

            * Télécharge malwarebytes
            http://www.malwarebytes.org/mbam/program/mbam-setup.exe

            => Installe le
            => Ensuite va en mode sans echec

            Relance le Pc et tapote la touche F8 ( ou F5 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
            Avec les touches « flèches », sélectionne Mode sans échec ==> entrée ==>nom utilisateur habituel

            => Lance malwarebytes
            => Coche "Executer un examen complet"
            => Si tu es en présence d'une infection à la fin de l'examen clique sur "ok"
            => Clique sur Supprimer la sélection
            => Pour poster le rapport Clique sur l'onglet Rapports/Logs, sélectionne celui t'intéresse et clique sur Ouvrir
            => Fait copier coller et poste le rapport

            --------------------------

            ensuite

            * Télécharge CCleaner
            https://filehippo.com/download_ccleaner/
            => Aide toi de ce tuto pour l'utiliser
            https://www.malekal.com/tutoriel-ccleaner/
            0
            1. Voila le rapport de malwarebytes

              Malwarebytes' Anti-Malware 1.12
              Version de la base de données: 722

              Type de recherche: Examen complet (C:\|D:\|K:\|)
              Eléments examinés: 244364
              Temps écoulé: 48 minute(s), 42 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 0
              Valeur(s) du Registre infectée(s): 0
              Elément(s) de données du Registre infecté(s): 0
              Dossier(s) infecté(s): 1
              Fichier(s) infecté(s): 0

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Valeur(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Elément(s) de données du Registre infecté(s):
              (Aucun élément nuisible détecté)

              Dossier(s) infecté(s):
              C:\Program Files\WebMediaPlayer (Adware.EGDAccess) -> Quarantined and deleted successfully.

              Fichier(s) infecté(s):
              (Aucun élément nuisible détecté)
              0
              1. Il a déja aprivoiser WebMediaPlayer, c'est déja sa. Sinon télécharges Spybot Search&Destroy
                0
                1. J'ai tout fait avec CCleaner mais toujours impossible d'activer le centre de sécurité :s
                  0
                  1. Fait une analyse pour voir les nuisibles de ton ordi et si possible les dizinguer.
                    www.bitdefender.fr/scan_fr/
                    0
                    1. Contributeur
                      refais un nouveau hijack
                      @+
                      0
                      1. Voila

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 19:20:26, on 08/05/2008
                        Platform: Windows Vista (WinNT 6.00.1904)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16643)
                        Boot mode: Normal

                        Running processes:
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\Explorer.EXE
                        C:\Program Files\Windows Defender\MSASCui.exe
                        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                        C:\Program Files\Microsoft IntelliType Pro\itype.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Windows\System32\DBR122\services.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                        C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
                        C:\Windows\ehome\ehtray.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
                        C:\Windows\ehome\ehmsas.exe
                        C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
                        C:\Program Files\Windows Media Player\wmpnscfg.exe
                        C:\Program Files\Windows Media Player\wmplayer.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\Program Files\MessengerDiscovery\MessengerDiscovery Live.exe
                        C:\Windows\system32\SearchFilterHost.exe
                        C:\Windows\system32\879_1210267162_36950\services.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        O1 - Hosts: ::1 localhost
                        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
                        O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        O4 - HKLM\..\Run: [Windows Security Center 1.22] C:\Windows\system32\DBR122\services.exe
                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                        O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
                        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                        O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O13 - Gopher Prefix:
                        O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
                        O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/fr-fr/wlscctrl2.cab
                        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                        O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
                        O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
                        O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                        0
                        1. Contributeur
                          Relance hijack et coche ceci

                          02 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                          O4 - HKLM\..\Run: [Windows Security Center 1.22] C:\Windows\system32\DBR122\services.exe
                          O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/fr-fr/wlscctrl2.cab

                          ensuite tu clique sur fix checked

                          ensuite

                          Télécharge OTMoveIt (de Old_Timer) sur ton Bureau.
                          http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
                          clic double sur OTMoveIt.exe pour le lancer.
                          copie la liste qui se trouve en citation ci-dessous,
                          et colle-la dans le cadre de gauche de OTMoveIt :
                          Paste List of Files/Folders to be moved.

                          C:\Windows\System32\DBR122\services.exe
                          C:\Windows\system32\879_1210267162_36950\services.exe
                          EmptyTemp

                          clique sur MoveIt! pour lancer la suppression.
                          le résultat apparaîtra dans le cadre Results.
                          clique sur Exit pour fermer.
                          poste le rapport situé dans C:\\\_OTMoveIt\MovedFiles.

                          il te sera peut-être demandé de redémarrer le pc pour achever la suppression.

                          ensuite fait un scan en ligne

                          avec bitdefender et colle le rapport

                          https://www.bitdefender.com/toolbox/

                          Scan à faire sous Internet Explorer

                          un tuto
                          http://pageperso.aol.fr/rginformatique/mapage/defender.htm

                          plus un nouveau rapport hijack stp

                          @+

                          0
                          1. C:\Windows\System32\DBR122\services.exe moved successfully.
                            C:\Windows\system32\879_1210267162_36950\services.exe moved successfully.
                            < EmptyTemp >
                            Temp folders emptied.
                            IE temp folders emptied.

                            OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 05082008_201800
                            0
                            1. Je peux faire l'analyse avec autre chose que BitDefender car c'est beaucoup trop long, temps estimé : 5h :s ?
                              0
                              1. Contributeur
                                oui je sais que l'analyse avec bitdefender est très longue
                                mais toutes les anlyses en lignes seront
                                il t'affiche 5h mais ça sera surement moins
                                j'espère ;-)

                                sinon
                                https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                                ==>Choisis Kaspersky.
                                ==>Tu dois réaliser le scan en utilisant Internet explorer. Une information apparait en haut, près de la barre d'état. Tu dois accepter et installer l'activeX proposé. La mise à jour de l'antivirus se lance.
                                ==>Réalise un scan complet du système.
                                ==> Sauvegarde le rapport en mode texte à l'issue du scan.

                                0
                                1. Avira AntiVir Personal
                                  Report file date: jeudi 8 mai 2008 20:58

                                  Scanning for 1255449 virus strains and unwanted programs.

                                  Licensed to: Avira AntiVir PersonalEdition Classic
                                  Serial number: 0000149996-ADJIE-0001
                                  Platform: Windows Vista
                                  Windows version: (plain) [6.0.6000]
                                  Boot mode: Normally booted
                                  Username: SYSTEM
                                  Computer name: GODIN

                                  Version information:
                                  BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
                                  AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 09:02:56
                                  AVSCAN.DLL : 8.1.1.0 53505 Bytes 07/02/2008 08:43:37
                                  LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 08:41:23
                                  LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 08:28:40
                                  ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
                                  ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 13:08:58
                                  ANTIVIR2.VDF : 7.0.4.0 1554432 Bytes 05/05/2008 21:47:23
                                  ANTIVIR3.VDF : 7.0.4.13 55808 Bytes 07/05/2008 21:47:25
                                  Engineversion : 8.1.0.39
                                  AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
                                  AESCRIPT.DLL : 8.1.0.28 233851 Bytes 07/05/2008 21:48:07
                                  AESCN.DLL : 8.1.0.16 119156 Bytes 07/05/2008 21:48:05
                                  AERDL.DLL : 8.1.0.20 418165 Bytes 07/05/2008 21:48:04
                                  AEPACK.DLL : 8.1.1.4 364918 Bytes 07/05/2008 21:48:00
                                  AEOFFICE.DLL : 8.1.0.18 192890 Bytes 07/05/2008 21:47:57
                                  AEHEUR.DLL : 8.1.0.21 1196407 Bytes 07/05/2008 21:47:55
                                  AEHELP.DLL : 8.1.0.14 115063 Bytes 07/05/2008 21:47:36
                                  AEGEN.DLL : 8.1.0.20 299380 Bytes 07/05/2008 21:47:34
                                  AEEMU.DLL : 8.1.0.6 430451 Bytes 07/05/2008 21:47:29
                                  AECORE.DLL : 8.1.0.28 168310 Bytes 07/05/2008 21:47:26
                                  AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 17:07:53
                                  AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 10:37:50
                                  AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:26:47
                                  AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 17:07:49
                                  AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                                  AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 08:31:31
                                  SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                                  SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 17:08:39
                                  NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                                  RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 14:37:25
                                  RCTEXT.DLL : 8.0.32.0 86273 Bytes 06/03/2008 12:02:11

                                  Configuration settings for the scan:
                                  Jobname..........................: Complete system scan
                                  Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                                  Logging..........................: low
                                  Primary action...................: interactive
                                  Secondary action.................: ignore
                                  Scan master boot sector..........: on
                                  Scan boot sector.................: on
                                  Boot sectors.....................: C:, D:, K:,
                                  Scan memory......................: on
                                  Process scan.....................: on
                                  Scan registry....................: on
                                  Search for rootkits..............: off
                                  Scan all files...................: All files
                                  Scan archives....................: on
                                  Recursion depth..................: 20
                                  Smart extensions.................: on
                                  Macro heuristic..................: on
                                  File heuristic...................: medium

                                  Start of the scan: jeudi 8 mai 2008 20:58

                                  The scan of running processes will be started
                                  Scan process 'avscan.exe' - '1' Module(s) have been scanned
                                  Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                                  Scan process 'SearchFilterHost.exe' - '1' Module(s) have been scanned
                                  Scan process 'SearchProtocolHost.exe' - '1' Module(s) have been scanned
                                  Scan process 'MessengerDiscovery Live.exe' - '1' Module(s) have been scanned
                                  Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                                  Scan process 'mfpmp.exe' - '0' Module(s) have been scanned
                                  Scan process 'wmplayer.exe' - '1' Module(s) have been scanned
                                  Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
                                  Scan process 'ehrecvr.exe' - '1' Module(s) have been scanned
                                  Scan process 'iPodService.exe' - '1' Module(s) have been scanned
                                  Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
                                  Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
                                  Scan process 'NMIndexingService.exe' - '1' Module(s) have been scanned
                                  Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                                  Scan process 'soffice.bin' - '1' Module(s) have been scanned
                                  Scan process 'ehsched.exe' - '1' Module(s) have been scanned
                                  Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
                                  Scan process 'soffice.exe' - '1' Module(s) have been scanned
                                  Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
                                  Scan process 'ehtray.exe' - '1' Module(s) have been scanned
                                  Scan process 'NMIndexStoreSvr.exe' - '1' Module(s) have been scanned
                                  Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                                  Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
                                  Scan process 'itype.exe' - '1' Module(s) have been scanned
                                  Scan process 'jusched.exe' - '1' Module(s) have been scanned
                                  Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
                                  Scan process 'explorer.exe' - '1' Module(s) have been scanned
                                  Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                                  Scan process 'dwm.exe' - '1' Module(s) have been scanned
                                  Scan process 'WUDFHost.exe' - '1' Module(s) have been scanned
                                  Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'IoctlSvc.exe' - '1' Module(s) have been scanned
                                  Scan process 'NBService.exe' - '1' Module(s) have been scanned
                                  Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
                                  Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
                                  Scan process 'avguard.exe' - '1' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'sched.exe' - '1' Module(s) have been scanned
                                  Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                                  Scan process 'aawservice.exe' - '1' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
                                  Scan process 'audiodg.exe' - '0' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                                  Scan process 'lsm.exe' - '1' Module(s) have been scanned
                                  Scan process 'lsass.exe' - '1' Module(s) have been scanned
                                  Scan process 'services.exe' - '1' Module(s) have been scanned
                                  Scan process 'csrss.exe' - '1' Module(s) have been scanned
                                  Scan process 'wininit.exe' - '1' Module(s) have been scanned
                                  Scan process 'csrss.exe' - '1' Module(s) have been scanned
                                  Scan process 'smss.exe' - '1' Module(s) have been scanned
                                  60 processes with 60 modules were scanned

                                  Starting master boot sector scan:
                                  Master boot sector HD0
                                  [INFO] No virus was found!
                                  Master boot sector HD1
                                  [INFO] No virus was found!
                                  [WARNING] Le périphérique n'est pas prêt.
                                  [INFO] Please restart the search with Administrator rights
                                  Master boot sector HD2
                                  [INFO] No virus was found!
                                  [WARNING] Le périphérique n'est pas prêt.
                                  [INFO] Please restart the search with Administrator rights
                                  Master boot sector HD3
                                  [INFO] No virus was found!
                                  [WARNING] Le périphérique n'est pas prêt.
                                  [INFO] Please restart the search with Administrator rights
                                  Master boot sector HD4
                                  [INFO] No virus was found!
                                  [WARNING] Le périphérique n'est pas prêt.
                                  [INFO] Please restart the search with Administrator rights
                                  Master boot sector HD5
                                  [INFO] No virus was found!

                                  Start scanning boot sectors:
                                  Boot sector 'C:\'
                                  [INFO] No virus was found!
                                  Boot sector 'D:\'
                                  [INFO] No virus was found!
                                  Boot sector 'K:\'
                                  [INFO] No virus was found!

                                  Starting to scan the registry.
                                  The registry was scanned ( '2' files ).

                                  Starting the file scan:

                                  Begin scan in 'C:\' <OS>
                                  C:\hiberfil.sys
                                  [WARNING] The file could not be opened!
                                  C:\pagefile.sys
                                  [WARNING] The file could not be opened!
                                  C:\Windows\System32\drivers\sptd.sys
                                  [WARNING] The file could not be opened!
                                  Begin scan in 'D:\' <RECOVERY>
                                  Begin scan in 'K:\' <IOMEGA HDD>

                                  End of the scan: jeudi 8 mai 2008 21:41
                                  Used time: 42:57 min

                                  The scan has been done completely.

                                  27739 Scanning directories
                                  406941 Files were scanned
                                  0 viruses and/or unwanted programs were found
                                  0 Files were classified as suspicious:
                                  0 files were deleted
                                  0 files were repaired
                                  0 files were moved to quarantine
                                  0 files were renamed
                                  3 Files cannot be scanned
                                  406941 Files not concerned
                                  1902 Archives were scanned
                                  7 Warnings
                                  0 Notes
                                  0
                                  1. J'ai fait une analyse avec Antivir c'est bon ?
                                    0
                                    1. Voil le rapport Bitdefender

                                      BitDefender Online Scanner

                                      Scan report generated at: Thu, May 08, 2008 - 22:53:49

                                      Scan path: C:\;D:\;E:\;G:\;H:\;I:\;J:\;K:\;

                                      Statistics

                                      Time

                                      01:01:14

                                      Files

                                      382086

                                      Folders

                                      26644

                                      Boot Sectors

                                      4

                                      Archives

                                      2112

                                      Packed Files

                                      15580

                                      Results

                                      Identified Viruses

                                      0

                                      Infected Files

                                      0

                                      Suspect Files

                                      0

                                      Warnings

                                      0

                                      Disinfected

                                      0

                                      Deleted Files

                                      0

                                      Engines Info

                                      Virus Definitions

                                      1190724

                                      Engine build

                                      AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

                                      Scan plugins

                                      16

                                      Archive plugins

                                      42

                                      Unpack plugins

                                      7

                                      E-mail plugins

                                      6

                                      System plugins

                                      5

                                      Scan Settings

                                      First Action

                                      Disinfect

                                      Second Action

                                      Delete

                                      Heuristics

                                      Yes

                                      Enable Warnings

                                      Yes

                                      Scanned Extensions

                                      *;

                                      Exclude Extensions

                                      Scan Emails

                                      Yes

                                      Scan Archives

                                      Yes

                                      Scan Packed

                                      Yes

                                      Scan Files

                                      Yes

                                      Scan Boot

                                      Yes

                                      Scanned File

                                      Status

                                      No virus found.
                                      0
                                      1. Et le rapport Hijack

                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                        O1 - Hosts: ::1 localhost
                                        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                        O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
                                        O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                        O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
                                        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                        O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
                                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O13 - Gopher Prefix:
                                        O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
                                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                        O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                        O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                        O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                        O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                                        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
                                        O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
                                        O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                        0
                                        • 1
                                        • 2
                                        • 3