Virus/trojan besoin aide svp

Résolu
Bonjour,

J'ai attrapé un virus ou trojan je ne sais pas mais c'est trop tanant et j'aimerais avoir de l'aide pouyr m'en débarrasser, souvent il y as comme un triangle jaune qui aparrais en bas de l'écran ou il y as l'horloge et le triangle flash pis sa sort une boite qui dit que j'ai des virus et je dois qcliquer dessus pour downloader anti virus 2008, et ya des page internet qui souvre tout seul qui m'ammene sur des site qui analyze mon systeme et veulent que je download cette antivirus... j'ai fais ce que j'ai vue dans un autre forum scan with Hijackthis sa ma donné ca:

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] "RUNDLL32.EXE" C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\Applications\wcs.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgemc.exe (file missing)
O23 - Service: AVG8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 8456 bytes
Configuration: Windows Vista
Internet Explorer 7.0

24 réponses

  1. slt

    ton rapport est imcomplé recolle le entierement stp
    0
    1. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 13:09:18, on 2008-08-02
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Applications\wcs.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\hp\support\hpsysdrv.exe
      C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
      C:\Windows\system32\schtasks.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\Applications\wcm.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Windows\system32\ctfmon.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
      C:\Windows\system32\jusched.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Windows\ehome\ehmsas.exe
      C:\hp\kbd\kbd.exe
      C:\Program Files\Internet Explorer\IEUser.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ca/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hp-consumer.my.aol.qc.ca/?icid=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hp-consumer.my.aol.qc.ca/?icid=desktop
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
      O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
      O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
      O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [NvSvc] "RUNDLL32.EXE" C:\Windows\system32\nvsvc.dll,nvsvcStart
      O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
      O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\Applications\wcs.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O13 - Gopher Prefix:
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: AVG8 E-mail Scanner (avg8emc) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgemc.exe (file missing)
      O23 - Service: AVG8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
      O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
      0
      1. Mon antivirus depuis que j'Ai mon ordi est webroot spy sweeper et j'ai jamais eu de problemme avec mais la, je vient d'ajouter spybot pour voir s'il me sortirais + de chose et j'ai smitfraud-c qui est une menace et je ne peut pas la suprimer pcq sa dit que je ne suis pas administrateur et pourtant je le suis.
        0
        1. Non, si je l'ais je l'ignorais
          0
          1. je vient de voir que dans le triangle sa dit virus network worm, damage level high, virus taht infect executable file...
            0
            1. ok c'est ton antivirus qui t'alerte ? si oui ignore tout

              # Double clique sur l'icone de smitfraud pui choisis l'option 1 et poste le rapport.

              Tient moi au courant a+.
              0
              1. non ce n'est pas mon antivirus qui m'alerte, je ne sais meme pas c est quoi et j'aimerais recommencer du debut si possible, juste me dire ce que je dois faire et quel programme installer qui est efficace pour que je vous disent ce qui infecte mon ordi, si sa ne vous dérange pas trop, merci
                0
                1. Le programme en question c'est smitfraudfix !

                  Essaye ca ca va faire avancer les choses:

                  Telecharge malwarebytes

                  Tu l´instale; le programme va se mettre automatiquement a jour.

                  Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

                  Click maintenant sur l´onglet recherche et coche la case : "executer un examun complet".

                  Puis click sur "rechercher".

                  Laisse le scanner le pc...

                  Si des elements on ete trouvés > click sur supprimer la selection.

                  si il t´es demandé de redemarrer > click sur "yes".

                  A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

                  Copie et colle le rapport stp.
                  0
                  1. Malwarebytes' Anti-Malware 1.24
                    Version de la base de données: 1017
                    Windows 6.0.6001 Service Pack 1

                    16:50:18 2008-08-02
                    mbam-log-8-2-2008 (16-50-18).txt

                    Type de recherche: Examen complet (C:\|D:\|E:\|)
                    Eléments examinés: 138631
                    Temps écoulé: 1 hour(s), 9 minute(s), 1 second(s)

                    Processus mémoire infecté(s): 1
                    Module(s) mémoire infecté(s): 0
                    Clé(s) du Registre infectée(s): 0
                    Valeur(s) du Registre infectée(s): 1
                    Elément(s) de données du Registre infecté(s): 0
                    Dossier(s) infecté(s): 0
                    Fichier(s) infecté(s): 3

                    Processus mémoire infecté(s):
                    C:\Program Files\Applications\wcs.exe (Trojan.Zlob) -> Failed to unload process.

                    Module(s) mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Clé(s) du Registre infectée(s):
                    (Aucun élément nuisible détecté)

                    Valeur(s) du Registre infectée(s):
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\some (Trojan.Zlob) -> Quarantined and deleted successfully.

                    Elément(s) de données du Registre infecté(s):
                    (Aucun élément nuisible détecté)

                    Dossier(s) infecté(s):
                    (Aucun élément nuisible détecté)

                    Fichier(s) infecté(s):
                    C:\Program Files\Applications\wcm.exe (Trojan.Zlob) -> Delete on reboot.
                    C:\Program Files\Applications\wcs.exe (Trojan.Zlob) -> Delete on reboot.
                    C:\Program Files\Applications\wcu.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
                    0
                    1. ok redémarre le PC Puis clique droit sur smitrfaudfix et clik sur utiliser en tant k'administrateur puis dis moi si sa marche.
                      0
                      1. C'est quoi smitfraudfix, j'ai pas ce programme la moi
                        0
                        1. Est-ce que je dois absolument telecharger ce programme ?
                          0
                          1. Oui mais tu ma pas dit que tu l'avait déjà ?

                            Fait ca entierement

                            Désactive le contrôle des comptes utilisateurs :

                            - Va dans démarrer puis panneau de configuration
                            - Double Clique sur l'icône "Comptes d'utilisateurs"
                            - Clique ensuite sur désactiver et valide.

                            télécharge smitfraudfix: smitfraudfix

                            # Double clique sur l'icone de smitfraud pui choisis l'option 1 et poste le rapport.

                            Tient moi au courant a+.
                            0
                            1. mon antivirus bloque l'ouverture du programme
                              0
                              1. C'est normal il le détécte comme une menace ! Désactive le le temps du scan puis réactive le ensuite n'oublie pas !!

                                Je vais me coucher a demin matin .
                                0
                                1. ok merci je te redonne des nouvelles.
                                  0
                                  1. voila:

                                    SmitFraudFix v2.333

                                    Scan done at 18:46:35,09, 2008-08-02
                                    Run from C:\Users\Utilisateur\Documents\Install\SmitfraudFix
                                    OS: Microsoft Windows [version 6.0.6001] - Windows_NT
                                    The filesystem type is NTFS
                                    Fix run in normal mode

                                    »»»»»»»»»»»»»»»»»»»»»»»» Process

                                    C:\Windows\system32\csrss.exe
                                    C:\Windows\system32\wininit.exe
                                    C:\Windows\system32\csrss.exe
                                    C:\Windows\system32\services.exe
                                    C:\Windows\system32\lsass.exe
                                    C:\Windows\system32\lsm.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\system32\winlogon.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\system32\SLsvc.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\System32\spoolsv.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    C:\Program Files\Bonjour\mDNSResponder.exe
                                    C:\Windows\system32\svchost.exe
                                    c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\system32\PnkBstrA.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\system32\SearchIndexer.exe
                                    C:\Windows\system32\DRIVERS\xaudio.exe
                                    C:\Windows\system32\WUDFHost.exe
                                    C:\Windows\system32\taskeng.exe
                                    C:\Windows\system32\Dwm.exe
                                    C:\Windows\Explorer.EXE
                                    C:\Windows\System32\mobsync.exe
                                    C:\Program Files\Windows Defender\MSASCui.exe
                                    C:\Windows\system32\taskeng.exe
                                    C:\hp\support\hpsysdrv.exe
                                    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                                    C:\Windows\RtHDVCpl.exe
                                    C:\Windows\system32\schtasks.exe
                                    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                                    C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                                    C:\Windows\system32\jusched.exe
                                    C:\Windows\System32\rundll32.exe
                                    C:\Windows\System32\rundll32.exe
                                    C:\Program Files\iTunes\iTunesHelper.exe
                                    C:\Program Files\Windows Sidebar\sidebar.exe
                                    C:\Windows\ehome\ehtray.exe
                                    C:\Windows\system32\wbem\wmiprvse.exe
                                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                    C:\Program Files\Windows Media Player\wmpnscfg.exe
                                    C:\Windows\ehome\ehmsas.exe
                                    C:\Program Files\Windows Media Player\wmpnetwk.exe
                                    C:\Windows\ehome\ehsched.exe
                                    C:\Program Files\iPod\bin\iPodService.exe
                                    C:\Windows\ehome\ehRecvr.exe
                                    C:\Program Files\Windows Live\Messenger\usnsvc.exe
                                    C:\Windows\system32\SearchProtocolHost.exe
                                    C:\Windows\system32\SearchFilterHost.exe
                                    c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                                    C:\hp\kbd\kbd.exe
                                    C:\Windows\system32\cmd.exe
                                    C:\Windows\system32\wbem\wmiprvse.exe

                                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Utilisateur

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Utilisateur\Application Data

                                    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\UTILIS~1\FAVORI~1

                                    »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                                    C:\Program Files\Applications\ FOUND !

                                    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                                    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                                    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                                    !!!Attention, following keys are not inevitably infected!!!

                                    IEDFix
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                                    !!!Attention, following keys are not inevitably infected!!!

                                    VACFix
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                                    !!!Attention, following keys are not inevitably infected!!!

                                    404Fix
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                                    !!!Attention, following keys are not inevitably infected!!!

                                    SrchSTS.exe by S!Ri
                                    Search SharedTaskScheduler's .dll

                                    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                                    !!!Attention, following keys are not inevitably infected!!!

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                                    "AppInit_DLLs"=""
                                    "LoadAppInit_DLLs"=dword:00000000

                                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                                    !!!Attention, following keys are not inevitably infected!!!

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                    "Userinit"="C:\\Windows\\system32\\userinit.exe,"

                                    »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                    Description: NVIDIA nForce Networking Controller
                                    DNS Server Search Order: 192.168.2.1

                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{15CCAADB-1A89-409F-8E5C-D2CB91E4EAEB}: DhcpNameServer=192.168.2.1
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{15CCAADB-1A89-409F-8E5C-D2CB91E4EAEB}: DhcpNameServer=192.168.2.1
                                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{15CCAADB-1A89-409F-8E5C-D2CB91E4EAEB}: DhcpNameServer=192.168.2.1
                                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                                    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

                                    »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                                    »»»»»»»»»»»»»»»»»»»»»»»» End
                                    0
                                    1. re

                                      On continue,

                                      Redémarre ton ordinateur en mode sans échec
                                      Ouvre le dossier SmitfraudFix
                                      Double clic sur Smitfraud.cmd choisis l'option 2 et Entrée
                                      Réponds O aux deux questions suivantes:
                                      -Voulez-vous nettoyer le registre ?
                                      -Corriger le fichier infecté ?
                                      Un rapport.txt sera généré et tu le postes pour contrôle.

                                      puis un nouveau rapport hijackthis stp
                                      0
                                      • 1
                                      • 2