Virus Alert! Barre des tâches

Résolu
Bonjour,

J'ai apparemment chopé un virus, mais j'avais pourtant reformaté le disque, à part les 8 Mo d'espace non partitionné, et réinstallé Windows XP. Je n'ai plus accès à rien du menu démarrer, à part mes documents, je n'ai plus mes disques durs dans poste de travail, à part ce qui est amovible, et quand je fais clic droit dans le bureau ou tente d'activer le gestionnaire des taches, je reçois un message m'avertissant de restrictions de mon administrateur (mon c... !). Enfin, j'ai le droit à un fond d'écran bleu avec un cadre jaune et bleu au centre où il est marqué "Warning ! Spyware detected on your computer ! Install an antivirus or spyware remover to clean your computer", et un message "VIRUS ALERT!" à côté de l'heure dans la barre des tâches.
J'ai tenté de prendre les mises à jour de Microsoft, mais je devais passer par Internet, or à chaque fois que j'y vais (car j'ai Firefox 3), je suis directement conduit à un certain "antivirus 2008" que je pourrais "get free for 49.99 dollars" XD
En vrai, ça me fais pas trop rire, puisque quand j'ai téléchargé SmitFraudFix, j'ai reçu un message d'erreur en lançant l'exécutable, et la commande me dit qu'il manque un winmachin.exe, et j'ai noté que certaines pages firefox sur lesquelles j'ai voulu me rendre sont bloquées, et que je n'ai pas réussi à aller plus d'une fois sur un lien pour télécharger ce dernier logiciel.
PS : l'analyse la plus complète de Kaspersky Internet Security 2009 ne détecte absolument rien. Embêtant d'avoir un truc comme ça quand on y a mis 75 euros...
Quelqu'un peut-il m'aider ?
--
Pourquoi chercher le problème ? Je nous propose, ensembles, de chercher la Solution !
Cher associé : il n'est pas interdit, en France, d'écrire en français... ni de cocher "Résolu"...
Configuration: Windows XP
Firefox 3.0.1

24 réponses

  1. Modérateur
    Salut,

    Si Windows déconnait juste après le formatage, c'est que l'installation s'est mal déroulée et il faut recommencer.
    0
    1. C'est en fait après les mises à jour automatiques et plusieurs redémarrages qu'en lançant le "setup" de GTA San Andreas, cet écran m'est apparu, après qu'un invité de commande soit brièvement apparu 2 ou 3 fois, avec un message du genre "1 fichier copié". Avant le formatage, c'est en lançant un "DOS4GW.exe" par curiosité, que je pensais avoir été mis par mon frère ou quelqu'un d'autre qui aurait profité de mes vacances, que l'invité de commande est apparu. Pourtant, mon frère, sur son ordinateur, n'a pas eu de problème avec le setup de GTA.
      PS : J'ai installé Vista Inspirat Pack 2 de Bricopacks, qui a modifié pas mal de dll, c'est peut-être à prendre en compte...
      0
      1. Modérateur
        Pas de problème avec Vista Inspirat Pack 2.

        - Télécharge et installe MalwareByte's Anti-Malware :
        http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm

        - Mets-le à jour

        - Redémarre en mode sans échec (Recommandé) :
        https://www.malekal.com/demarrer-windows-mode-sans-echec/

        - Choisis ta session habituelle

        - Fais un scan complet avec MalwareByte's Anti-Malware

        - Supprime tout ce que le logiciel trouve, enregistre le rapport

        - Redémarre en mode normal et poste le rapport ici

        Tutorial :
        https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
        0
        1. Merci à toi, j'ai enregistré le rapport, il a détecté (et supprimé) 16 objets infectés. Par contre, le fichier texte que j'avais mis sur mon bureau en MSE ne s'y trouve plus en normal. Dois-je aller sur firefox en MSE avec prise en charge réseau pour l'avoir ?
          0
          1. Je suis en mode sans échec, je t'envoie le rapport :

            Malwarebytes' Anti-Malware 1.24
            Database version: 1017
            Windows 5.1.2600 Service Pack 3

            11:58:07 04/08/2008
            mbam-log-8-4-2008 (11-57-59).txt

            Scan type: Full Scan (C:\|D:\|E:\|G:\|)
            Objects scanned: 118825
            Time elapsed: 33 minute(s), 22 second(s)

            Memory Processes Infected: 0
            Memory Modules Infected: 0
            Registry Keys Infected: 8
            Registry Values Infected: 1
            Registry Data Items Infected: 2
            Folders Infected: 0
            Files Infected: 15

            Memory Processes Infected:
            (No malicious items detected)

            Memory Modules Infected:
            (No malicious items detected)

            Registry Keys Infected:
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> No action taken.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webvideo (Trojan.FakeAlert) -> No action taken.
            HKEY_CLASSES_ROOT\TypeLib\{90ad35a8-01ee-43d8-93ed-ed61f17a7622} (Trojan.FakeAlert) -> No action taken.
            HKEY_CLASSES_ROOT\Interface\{1d5dd220-6d42-4907-958e-065cedd53d9d} (Trojan.FakeAlert) -> No action taken.
            HKEY_CLASSES_ROOT\Interface\{6a63f59b-9563-4564-9c38-5d98fa846f68} (Trojan.FakeAlert) -> No action taken.
            HKEY_CLASSES_ROOT\CLSID\{153f0a06-a9a9-4329-af94-683b14cabf12} (Trojan.FakeAlert) -> No action taken.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{153f0a06-a9a9-4329-af94-683b14cabf12} (Trojan.FakeAlert) -> No action taken.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> No action taken.

            Registry Values Infected:
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows (Backdoor.Bot) -> No action taken.

            Registry Data Items Infected:
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId (Trojan.FakeAlert) -> Bad: (VIRUS ALERT!) Good: (55274-640-8365391-23635) -> No action taken.
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.

            Folders Infected:
            (No malicious items detected)

            Files Infected:
            C:\Documents and Settings\Zildjiann\Local Settings\Temp\ac8zt2\eaxf.exe (Trojan.FakeAlert) -> No action taken.
            C:\WINDOWS\eaxf.exe (Trojan.FakeAlert) -> No action taken.
            C:\WINDOWS\edot.exe (Trojan.FakeAlert) -> No action taken.
            C:\Documents and Settings\Zildjiann\Local Settings\Temp\Setup_ver1.1400.0.exe (Backdoor.Bot) -> No action taken.
            C:\WINDOWS\grswptdl.exe (Trojan.FakeAlert) -> No action taken.
            C:\WINDOWS\nfavxwdbqst.dll (Trojan.FakeAlert) -> No action taken.
            C:\WINDOWS\system32\lphc7nlj0ee5p.exe (Trojan.FakeAlert) -> No action taken.
            C:\WINDOWS\system32\phc7nlj0ee5p.bmp (Trojan.FakeAlert) -> No action taken.
            C:\Documents and Settings\Zildjiann\Local Settings\Temp\s1265.php (Trojan.FakeAlert) -> No action taken.
            C:\Documents and Settings\Zildjiann\Bureau\Spyware&Malware Protection.url (Rogue.Link) -> No action taken.
            C:\Documents and Settings\Zildjiann\Bureau\Privacy Protector.url (Rogue.Link) -> No action taken.
            C:\Documents and Settings\Zildjiann\Bureau\Error Cleaner.url (Rogue.Link) -> No action taken.
            C:\Documents and Settings\Zildjiann\Favoris\Error Cleaner.url (Rogue.Link) -> No action taken.
            C:\Documents and Settings\Zildjiann\Favoris\Privacy Protector.url (Rogue.Link) -> No action taken.
            C:\Documents and Settings\Zildjiann\Favoris\Spyware&Malware Protection.url (Rogue.Link) -> No action taken.
            0
            1. Modérateur
              - Télécharge SmitfraudFix (de de S!Ri, balltrap34 et moe31) :
              http://siri.urz.free.fr/Fix/SmitfraudFix.exe ou http://www.geekstogo.com/forum/files/file/6-smitfraudfix/

              - Enregistre-le sur le bureau

              - Double-clique sur SmitfraudFix.exe et choisis l'option 1 puis Entrée

              - Un rapport sera généré, poste-le dans ta prochaine réponse.

              [*] process.exe est détecté par certains antivirus comme étant un risktool. Il ne s'agit pas d'un virus mais d'un utilitaire destiné à mettre fin à des processus.[*]

              ** Ne fais l'étape 2 que si on te le demande, on doit d'abord examiner le premier rapport de SmitfraudFix
              0
              1. Voilà le rapport SmitFraudFix, rien ne m'a signalé que je devais passer à l'étape 2 :

                SmitFraudFix v2.333

                Rapport fait à 12:43:26,93, 04/08/2008
                Executé à partir de C:\Documents and Settings\Administrateur\Bureau\SmitfraudFix
                OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                Le type du système de fichiers est NTFS
                Fix executé en mode sans echec

                »»»»»»»»»»»»»»»»»»»»»»»» Process

                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Windows Defender\MsMpEng.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Mozilla Firefox\firefox.exe
                C:\Documents and Settings\Administrateur\Bureau\HiJackThis.exe
                C:\WINDOWS\system32\cmd.exe

                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                Fichier hosts corrompu !

                127.0.0.1 channels.lockergnome.com
                127.0.0.1 mobile.lockergnome.com
                127.0.0.1 microsoft.com.org
                127.0.0.1 legal-at-spybot.info
                127.0.0.1 www.legal-at-spybot.info

                »»»»»»»»»»»»»»»»»»»»»»»» C:\

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrateur

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrateur\Application Data

                »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\Favoris

                »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                "Source"="About:Home"
                "SubscribedURL"="About:Home"
                "FriendlyName"="Ma page d'accueil"

                »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                IEDFix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                VACFix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                404Fix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                SrchSTS.exe by S!Ri
                Search SharedTaskScheduler's .dll

                »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                "AppInit_DLLs"="C:\\PROGRA~1\\KASPER~1\\KASPER~1\\mzvkbd.dll,C:\\PROGRA~1\\KASPER~1\\KASPER~1\\adialhk.dll,C:\\PROGRA~1\\KASPER~1\\KASPER~1\\kloehk.dll,"

                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                "System"=""

                »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                »»»»»»»»»»»»»»»»»»»»»»»» DNS

                Description: NVIDIA nForce Networking Controller - Miniport d'ordonnancement de paquets
                DNS Server Search Order: 192.168.1.1
                DNS Server Search Order: 0.0.0.0

                HKLM\SYSTEM\CCS\Services\Tcpip\..\{C89B98CC-3C7B-4124-A13A-D3C0E9189658}: DhcpNameServer=192.168.1.1 0.0.0.0
                HKLM\SYSTEM\CS1\Services\Tcpip\..\{C89B98CC-3C7B-4124-A13A-D3C0E9189658}: DhcpNameServer=192.168.1.1 0.0.0.0
                HKLM\SYSTEM\CS3\Services\Tcpip\..\{C89B98CC-3C7B-4124-A13A-D3C0E9189658}: DhcpNameServer=192.168.1.1 0.0.0.0
                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
                HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0

                »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                »»»»»»»»»»»»»»»»»»»»»»»» Fin

                0
                1. Modérateur
                  - Télécharge HijackThis V 2.02 (HijackThis Installer) :
                  http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe

                  - Fais un double-clic sur HJTInstall.exe afin de lancer l'installation

                  - Clique sur Install ensuite sur I Accept

                  - Clique sur Do a scan system and save log file

                  - Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
                  0
                  1. Et voilà :)

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 12:51:32, on 04/08/2008
                    Platform: Windows XP SP3 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.20815)
                    Boot mode: Safe mode with network support

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Windows Defender\MsMpEng.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Documents and Settings\Administrateur\Bureau\HiJackThis.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr/keyword/%s
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.fr/?gws_rd=ssl
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://www.google.fr/?gws_rd=ssl
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Ultimate Edition
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O1 - Hosts: ::1 localhost
                    O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                    O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\styler\TB\StylerTB.dll
                    O3 - Toolbar: (no name) - {FB3486FF-2A37-4536-B847-D999BA4E7776} - (no file)
                    O3 - Toolbar: (no name) - {AE7F9E1E-0A21-46C0-91D9-01F9D1ACB887} - (no file)
                    O4 - HKLM\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe"
                    O4 - HKLM\..\Run: [VisualTaskTips] C:\Windows\System32\VisualTaskTips.exe
                    O4 - HKLM\..\Run: [Vistadrv] C:\WINDOWS\system32\Vistadrive\vsdrv.exe
                    O4 - HKLM\..\Run: [Styler] C:\Program Files\styler\Styler.exe
                    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
                    O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
                    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs"
                    O4 - HKCU\..\RunOnce: [TSClientAXDisabler] cmd.exe /C "%systemroot%\Installer\TSClientMsiTrans\tscdsbl.bat"
                    O4 - HKUS\S-1-5-19\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSection nLite.inf,C (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-20\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (User 'SYSTEM')
                    O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (User 'Default user')
                    O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
                    O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll,
                    O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
                    O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                    O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                    O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
                    0
                    1. Modérateur
                      Tu as encore des problèmes ?
                      0
                      1. Je vais voir, je redémarre en mode normal. Mais dès que je suis en mode sans échec, plus rien ne pose problème et j'accède à tout correctement (disques, panneau de cfg, gestionnaire des taches...), sans le message "virus alert!" en bas à droite. Bref tout est nickel... Voyons ce que ça donne en mode normal...
                        0
                        1. ... -_-

                          J'ai toujours le "virus alert!", pas d'accès aux disques, panneau de cfg, gestionnaire des tâches... La seule chose qui ait changé, c'est le fond d'écran, qui est désormais noir, sans ce message sur fond bleu... Deux détails me paraissent bizarre : j'ai désinstallé Vista Inspirate Pack, mais le skin n'a pas changé, et en mode sans échec, j'avais l'écran de sessions au démarrage, avec celle "Administrateur", et celle "Zildjiann". Là, en démarrant en mode normal, je vais directement sur une session sans aucun choix ni écran d'accueil. Et l'image du compte dans le menu démarrer n'est pas une de celles des deux sessions normalement existantes sur mon ordinateur...
                          0
                          1. Modérateur
                            Fais l'option 1 de SmitfraudFix en mode normal et poste le rapport.
                            0
                            1. OK, voilà le rapport SmitFraudFix en mode normal :

                              SmitFraudFix v2.333

                              Rapport fait à 13:31:30,51, 04/08/2008
                              Executé à partir de C:\Documents and Settings\Constantin Lounis\Bureau\SmitfraudFix
                              OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                              Le type du système de fichiers est NTFS
                              Fix executé en mode normal

                              »»»»»»»»»»»»»»»»»»»»»»»» Process

                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Windows Defender\MsMpEng.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\UberIcon\UberIcon Manager.exe
                              C:\Windows\System32\VisualTaskTips.exe
                              C:\Program Files\styler\Styler.exe
                              C:\Program Files\Windows Defender\MSASCui.exe
                              C:\WINDOWS\system32\RUNDLL32.EXE
                              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
                              C:\Program Files\MSI\Live Update 3\LMonitor.exe
                              C:\WINDOWS\RTHDCPL.EXE
                              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
                              C:\Program Files\CDBurnerXP\NMSAccessU.exe
                              C:\WINDOWS\system32\nvsvc32.exe
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              C:\Documents and Settings\Constantin Lounis\Bureau\SmitfraudFix\Policies.exe
                              C:\WINDOWS\system32\cmd.exe

                              »»»»»»»»»»»»»»»»»»»»»»»» hosts

                              Fichier hosts corrompu !

                              127.0.0.1 channels.lockergnome.com
                              127.0.0.1 mobile.lockergnome.com
                              127.0.0.1 microsoft.com.org
                              127.0.0.1 legal-at-spybot.info
                              127.0.0.1 www.legal-at-spybot.info

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Constantin Lounis

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Constantin Lounis\Application Data

                              »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\CONSTA~1\Favoris

                              »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                              »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                              »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                              "Source"="About:Home"
                              "SubscribedURL"="About:Home"
                              "FriendlyName"="Ma page d'accueil"

                              »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                              IEDFix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                              VACFix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                              404Fix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                              SrchSTS.exe by S!Ri
                              Search SharedTaskScheduler's .dll

                              »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                              "AppInit_DLLs"="C:\\PROGRA~1\\KASPER~1\\KASPER~1\\mzvkbd.dll,C:\\PROGRA~1\\KASPER~1\\KASPER~1\\adialhk.dll,C:\\PROGRA~1\\KASPER~1\\KASPER~1\\kloehk.dll,"

                              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                              "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                              "System"=""

                              »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                              »»»»»»»»»»»»»»»»»»»»»»»» DNS

                              Description: NVIDIA nForce Networking Controller - Miniport d'ordonnancement de paquets
                              DNS Server Search Order: 192.168.1.1
                              DNS Server Search Order: 0.0.0.0

                              HKLM\SYSTEM\CCS\Services\Tcpip\..\{C89B98CC-3C7B-4124-A13A-D3C0E9189658}: DhcpNameServer=192.168.1.1 0.0.0.0
                              HKLM\SYSTEM\CS1\Services\Tcpip\..\{C89B98CC-3C7B-4124-A13A-D3C0E9189658}: DhcpNameServer=192.168.1.1 0.0.0.0
                              HKLM\SYSTEM\CS3\Services\Tcpip\..\{C89B98CC-3C7B-4124-A13A-D3C0E9189658}: DhcpNameServer=192.168.1.1 0.0.0.0
                              HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
                              HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
                              HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0

                              »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                              »»»»»»»»»»»»»»»»»»»»»»»» Fin

                              0
                              1. Modérateur
                                - Double-clique sur SmitfraudFix.exe, choisis l'option 2 et Entrée

                                - Réponds O(oui) à ces deux questions si elles te sont posées

                                Voulez-vous nettoyer le registre ?
                                Corriger le fichier infecté ?

                                - Un rapport sera généré, sauvegarde-le sur le bureau

                                - Poste le rapport SmitfraudFix et poste un nouveau rapport HijackThis
                                0
                                1. Rapport HijackThis :

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 13:49:15, on 04/08/2008
                                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v7.00 (7.00.6000.20815)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\Program Files\Windows Defender\MsMpEng.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\UberIcon\UberIcon Manager.exe
                                  C:\Windows\System32\VisualTaskTips.exe
                                  C:\Program Files\styler\Styler.exe
                                  C:\Program Files\Windows Defender\MSASCui.exe
                                  C:\WINDOWS\system32\RUNDLL32.EXE
                                  C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
                                  C:\Program Files\MSI\Live Update 3\LMonitor.exe
                                  C:\WINDOWS\RTHDCPL.EXE
                                  C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                                  C:\WINDOWS\system32\ctfmon.exe
                                  C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
                                  C:\Program Files\CDBurnerXP\NMSAccessU.exe
                                  C:\WINDOWS\system32\nvsvc32.exe
                                  C:\WINDOWS\explorer.exe
                                  C:\WINDOWS\notepad.exe
                                  C:\Program Files\Mozilla Firefox\firefox.exe
                                  C:\Documents and Settings\Constantin Lounis\Bureau\HiJackThis.exe

                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Ultimate Edition
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  O1 - Hosts: ::1 localhost
                                  O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
                                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                  O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\styler\TB\StylerTB.dll
                                  O3 - Toolbar: (no name) - {FB3486FF-2A37-4536-B847-D999BA4E7776} - (no file)
                                  O3 - Toolbar: (no name) - {AE7F9E1E-0A21-46C0-91D9-01F9D1ACB887} - (no file)
                                  O4 - HKLM\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe"
                                  O4 - HKLM\..\Run: [VisualTaskTips] C:\Windows\System32\VisualTaskTips.exe
                                  O4 - HKLM\..\Run: [Vistadrv] C:\WINDOWS\system32\Vistadrive\vsdrv.exe
                                  O4 - HKLM\..\Run: [Styler] C:\Program Files\styler\Styler.exe
                                  O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                  O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
                                  O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
                                  O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                  O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                  O4 - HKUS\S-1-5-19\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-19\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-19\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSection nLite.inf,C (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (User 'SERVICE RÉSEAU')
                                  O4 - HKUS\S-1-5-20\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE RÉSEAU')
                                  O4 - HKUS\S-1-5-18\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (User 'SYSTEM')
                                  O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
                                  O4 - HKUS\.DEFAULT\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (User 'Default user')
                                  O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
                                  O8 - Extra context menu item: Ajouter à Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
                                  O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
                                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll,
                                  O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
                                  O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                                  O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
                                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                  O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
                                  0
                                  1. IL veut pas poster le rapport de l'option 2 de SmitFraudFix, c'est apparemment trop long... Mais il ne m'a pas posé la question de savoir si je voulais corriger le fichier infecté.
                                    0
                                    1. Modérateur
                                      Ok,

                                      ---> Télécharge HostsXpert sur ton Bureau :
                                      http://www.funkytoad.com/download/HostsXpert.zip

                                      ---> Décompresse-le (Clic droit >> Extraire ici)

                                      ---> Double-clique sur HostsXpert pour le lancer

                                      ---> clique sur le bouton "Restore MS Hosts File" puis ferme le programme

                                      PS : Avant de cliquer sur le bouton "Restore MS Hosts File", vérifie que le cadenas en haut à gauche est ouvert sinon tu vas avoir un message d'erreur.
                                      0
                                      1. Modérateur
                                        Ton PC buggue toujours en mode normal ?
                                        0
                                        • 1
                                        • 2