Probleme avec le virus virtumonde

Bonjour,
j'ai telechargé hijackthis et voila ce que le scann donLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:51: VIRUS ALERT!, on 15/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\UberIcon\UberIcon Manager.exe
C:\Windows\System32\VisualTaskTips.exe
C:\Program Files\TweakRAM\TweakRAM.exe
C:\Program Files\LClock\lclock.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/toolbar/ie8/sidebar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Ultimate Edition
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {34ea1c70-42cc-42c5-aa29-ec58b95a343e} - (no file)
O2 - BHO: {efae30ec-fb26-722a-5874-94cf38154510} - {01545183-fc49-4785-a227-62bfce03eafe} - C:\WINDOWS\system32\osrrvz.dll
O2 - BHO: (no name) - {055B7478-6984-4A5C-840C-C761A3AE5218} - (no file)
O2 - BHO: (no name) - {20744758-0A58-4BC9-B7A5-E7B0D9A81E05} - C:\WINDOWS\system32\awtTJCTk.dll (file missing)
O2 - BHO: (no name) - {25DAD5C0-CFDC-4965-B0C0-D57A1AA15257} - (no file)
O2 - BHO: (no name) - {2f1ed2e2-4139-4216-8a11-b99688a42c38} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7C6ADCC4-9C51-4162-96ED-50075F71E576} - (no file)
O2 - BHO: (no name) - {AA988EDB-78AC-4A6D-B39F-1C13071DF658} - C:\WINDOWS\system32\khfCRiJA.dll (file missing)
O2 - BHO: (no name) - {ad95a585-0635-4b3d-91a5-eb691ac9de3a} - (no file)
O2 - BHO: (no name) - {C933586E-2972-4503-A45C-D6E825527207} - (no file)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: (no name) - {34ea1c70-42cc-42c5-aa29-ec58b95a343e} - (no file)
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
O4 - HKLM\..\Run: [Vistadrv] C:\WINDOWS\system32\Vistadrive\vsdrv.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKCU\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe"
O4 - HKCU\..\Run: [VisualTaskTips] C:\Windows\System32\VisualTaskTips.exe
O4 - HKCU\..\Run: [Vistadrv] C:\Windows\System32\Vistadrive\vsdrv.exe
O4 - HKCU\..\Run: [TweakRAM] C:\Program Files\TweakRAM\TweakRAM.exe
O4 - HKCU\..\Run: [LClock] C:\Program Files\LClock\lclock.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [EPSON Stylus DX8400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICEE.EXE /FU "C:\WINDOWS\TEMP\E_S152.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [VisualTaskTips] C:\Windows\System32\VisualTaskTips.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [Vistadrv] C:\Windows\System32\Vistadrive\vsdrv.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [TweakRAM] C:\Program Files\TweakRAM\TweakRAM.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [LClock] C:\Program Files\LClock\lclock.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSection nLite.inf,C (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe" (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSection nLite.inf,C (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSection nLite.inf,C (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe" (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSection nLite.inf,C (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O20 - Winlogon Notify: awtTJCTk - awtTJCTk.dll (file missing)
O20 - Winlogon Notify: WinCtrl32 - C:\WINDOWS\SYSTEM32\WinCtrl32.dll
O21 - SSODL: eqvwamkl - {D634D209-A1E1-4583-8EA1-FF08994C4D24} - C:\WINDOWS\eqvwamkl.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe

--
End of file - 8108 bytes
ne:
Configuration: Windows XP sous vista

8 réponses

  1. Salut,

    # Télécharge ceci: (merci a S!RI pour ce petit programme).

    http://siri.urz.free.fr/Fix/SmitfraudFix.exe

    Exécute le, Double click sur Smitfraudfix.exe choisit l’option 1,
    voila a quoi cela ressemble : http://siri.urz.free.fr/Fix/SmitfraudFix.php
    il va générer un rapport : copie/colle le sur le poste stp.

    0
    1. Bonjour,pour commencer tu n'aurais pas deux antivirus ?
      0
      1. oui, j'ai deux anti virus je viens d'insttaller avast pour essayer de resoudre le probleme
        0
    2. je viens d'effectuer la recherche avec le logiciel SmitFraudFix v2.337

      Rapport fait à 14:00:57,75, 15/08/2008
      Executé à partir de C:\Documents and Settings\Administrateur.F8B5928C3948492\Bureau\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode normal

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\Program Files\Eset\nod32kui.exe
      C:\Program Files\Soft4Ever\looknstop\looknstop.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\UberIcon\UberIcon Manager.exe
      C:\Windows\System32\VisualTaskTips.exe
      C:\Program Files\TweakRAM\TweakRAM.exe
      C:\Program Files\LClock\lclock.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Executive Software\Diskeeper\DkService.exe
      C:\Program Files\Eset\nod32krn.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\WINDOWS\system32\NOTEPAD.EXE
      C:\WINDOWS\system32\cmd.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      Fichier hosts corrompu !

      127.0.0.1 www.legal-at-spybot.info
      127.0.0.1 legal-at-spybot.info

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrateur.F8B5928C3948492

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrateur.F8B5928C3948492\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

      C:\DOCUME~1\ADMINI~1.F8B\MENUDM~1\Antivirus 2009 PRESENT !

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1.F8B\Favoris

      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="Ma page d'accueil"

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» RK

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: VIA Rhine II Fast Ethernet Adapter - Miniport d'ordonnancement de paquets
      DNS Server Search Order: 212.27.40.240
      DNS Server Search Order: 212.27.40.241

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{D7D01D59-FF08-4BFD-8D47-DC411EA05451}: DhcpNameServer=212.27.40.240 212.27.40.241
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{D7D01D59-FF08-4BFD-8D47-DC411EA05451}: DhcpNameServer=212.27.40.240 212.27.40.241
      HKLM\SYSTEM\CS2\Services\Tcpip\..\{D7D01D59-FF08-4BFD-8D47-DC411EA05451}: DhcpNameServer=212.27.40.240 212.27.40.241
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241

      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

      »»»»»»»»»»»»»»»»»»»»»»»» Fin

      que vous m'avez recommandé, voici les resultats:
      0
      1. Télécharge cet outil de SiRi:

        http://siri.urz.free.fr/Softs/RHosts.exe)
        http://siri.urz.free.fr/RHosts.php

        Double cliquer dessus pour l'exécuter

        et cliquer sur " Restore original Hosts "

        ps : c est normal que rien ne se passe

        ensuite :

        # Démarre en mode sans échec :
        Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
        Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
        Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
        (Si F8 ne marche pas utilise la touche F5).
        ----------------------------------------------------------------------------
        # Relance le programme Smitfraud :
        Cette fois choisit l’option 2, répond oui a tous ;
        Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

        ensuite :

        Telecharge malwarebytes

        -> http://www.malwarebytes.org/mbam/program/mbam-setup.exe

        Tu l´instale; le programme va se mettre automatiquement a jour.

        Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

        Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".

        Puis click sur "rechercher".

        Laisse le scanner le pc...

        Si des elements on ete trouvés > click sur supprimer la selection.

        si il t´es demandé de redemarrer > click sur "yes".

        A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
        Copie et colle le rapport stp.

        PS : les rapport sont aussi rangé dans l onglet rapport/log

        0
        1. j'ai lancé le programme smitfraud en mode sans echec et voici le resultat:

          SmitFraudFix v2.337

          Rapport fait à 14:25:12,04, 15/08/2008
          Executé à partir de C:\Documents and Settings\Administrateur.F8B5928C3948492\Bureau\SmitfraudFix
          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
          Le type du système de fichiers est NTFS
          Fix executé en mode sans echec

          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

          »»»»»»»»»»»»»»»»»»»»»»»» hosts

          127.0.0.1 localhost

          »»»»»»»»»»»»»»»»»»»»»»»» VACFix

          VACFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

          S!Ri's WS2Fix: LSP not Found.

          »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

          GenericRenosFix by S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

          C:\DOCUME~1\ADMINI~1.F8B\MENUDM~1\Antivirus 2009 supprimé

          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

          IEDFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

          404Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» RK

          »»»»»»»»»»»»»»»»»»»»»»»» DNS

          HKLM\SYSTEM\CCS\Services\Tcpip\..\{D7D01D59-FF08-4BFD-8D47-DC411EA05451}: DhcpNameServer=212.27.40.240 212.27.40.241
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{D7D01D59-FF08-4BFD-8D47-DC411EA05451}: DhcpNameServer=212.27.40.240 212.27.40.241
          HKLM\SYSTEM\CS2\Services\Tcpip\..\{D7D01D59-FF08-4BFD-8D47-DC411EA05451}: DhcpNameServer=212.27.40.240 212.27.40.241
          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
          HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241

          »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "System"=""

          »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

          Nettoyage terminé.

          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» Fin
          0
          1. ok parfait , passe a l suite (malewarebyte)
            0
            1. j'ai demaré le scan de malwarebytes et la d'un coup il s'est fermé, enfin il n'est plus sur le bureau mais quand j'ouvre le gestionnaire des taches il est toujours ouvert dans les applications. je comprends pas...
              0
          2. redémarer en mode sans echec et fait le scan malewarebyte en MSE (mode sans echec)

            Comment redémarrer en mode sans echec?

            Tu redemarre le pc et tapote la touche F8 des le début de l allumage sans t´arrêter.
            Une fenêtre sur fond noir va s’ouvrir, tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
            Une fois sur le bureau si il n y a pas toutes les couleurs et autres c´est normal!
            Ps : si F8 ne marche pas utilise la touche F5.

            -> Tuto :https://www.malekal.com/demarrer-windows-mode-sans-echec/
            0
            1. voici le rapport du scan que j'ai effectué en mode sans echec:

              Malwarebytes' Anti-Malware 1.24
              Version de la base de données: 1054
              Windows 5.1.2600 Service Pack 2

              00:23:13 16/08/2008
              mbam-log-8-16-2008 (00-23-13).txt

              Type de recherche: Examen complet (C:\|F:\|)
              Eléments examinés: 176798
              Temps écoulé: 4 hour(s), 6 minute(s), 13 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 1
              Clé(s) du Registre infectée(s): 16
              Valeur(s) du Registre infectée(s): 3
              Elément(s) de données du Registre infecté(s): 0
              Dossier(s) infecté(s): 12
              Fichier(s) infecté(s): 22

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              C:\WINDOWS\system32\WinCtrl32.dll (Trojan.Agent) -> Delete on reboot.

              Clé(s) du Registre infectée(s):
              HKEY_CLASSES_ROOT\CLSID\{20744758-0a58-4bc9-b7a5-e7b0d9a81e05} (Trojan.Vundo) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{20744758-0a58-4bc9-b7a5-e7b0d9a81e05} (Trojan.Vundo) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\rhcj0gj0ead9 (Rogue.Multiple) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\rhcj0gj0ead9 (Rogue.Multiple) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 (Trojan.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\fdkowvbp.bqxr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\fdkowvbp.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.

              Valeur(s) du Registre infectée(s):
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{20744758-0a58-4bc9-b7a5-e7b0d9a81e05} (Trojan.Vundo) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\eqvwamkl (Trojan.FakeAlert) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully.

              Elément(s) de données du Registre infecté(s):
              (Aucun élément nuisible détecté)

              Dossier(s) infecté(s):
              C:\Program Files\rhcj0gj0ead9 (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Documents and Settings\Administrateur.F8B5928C3948492\Application Data\rhcj0gj0ead9 (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Documents and Settings\Administrateur.F8B5928C3948492\Application Data\rhcj0gj0ead9\Quarantine (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Documents and Settings\Administrateur.F8B5928C3948492\Application Data\rhcj0gj0ead9\Quarantine\Autorun (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Documents and Settings\Administrateur.F8B5928C3948492\Application Data\rhcj0gj0ead9\Quarantine\Autorun\HKCU (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Documents and Settings\Administrateur.F8B5928C3948492\Application Data\rhcj0gj0ead9\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Documents and Settings\Administrateur.F8B5928C3948492\Application Data\rhcj0gj0ead9\Quarantine\Autorun\HKLM (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Documents and Settings\Administrateur.F8B5928C3948492\Application Data\rhcj0gj0ead9\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Documents and Settings\Administrateur.F8B5928C3948492\Application Data\rhcj0gj0ead9\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Documents and Settings\Administrateur.F8B5928C3948492\Application Data\rhcj0gj0ead9\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Documents and Settings\Administrateur.F8B5928C3948492\Application Data\rhcj0gj0ead9\Quarantine\BrowserObjects (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Documents and Settings\Administrateur.F8B5928C3948492\Application Data\rhcj0gj0ead9\Quarantine\Packages (Rogue.Multiple) -> Quarantined and deleted successfully.

              Fichier(s) infecté(s):
              C:\WINDOWS\system32\utisakam.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\makasitu.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\Documents and Settings\Administrateur.F8B5928C3948492\Local Settings\Temporary Internet Files\Content.IE5\0DQFGPIV\kb767887[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\Documents and Settings\Administrateur.F8B5928C3948492\Local Settings\Temporary Internet Files\Content.IE5\672RG561\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\System Volume Information\_restore{61A1E9AF-C5F9-416B-BA6D-93C8DEFB198D}\RP306\A0045739.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\System Volume Information\_restore{61A1E9AF-C5F9-416B-BA6D-93C8DEFB198D}\RP306\A0045740.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\System Volume Information\_restore{61A1E9AF-C5F9-416B-BA6D-93C8DEFB198D}\RP306\A0045741.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\System Volume Information\_restore{61A1E9AF-C5F9-416B-BA6D-93C8DEFB198D}\RP306\A0045742.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\System Volume Information\_restore{61A1E9AF-C5F9-416B-BA6D-93C8DEFB198D}\RP306\A0045743.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\Program Files\rhcj0gj0ead9\database.dat (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Program Files\rhcj0gj0ead9\license.txt (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Program Files\rhcj0gj0ead9\MFC71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Program Files\rhcj0gj0ead9\MFC71ENU.DLL (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Program Files\rhcj0gj0ead9\msvcp71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Program Files\rhcj0gj0ead9\msvcr71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Program Files\rhcj0gj0ead9\rhcj0gj0ead9.exe.local (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\Program Files\rhcj0gj0ead9\Uninstall.exe (Rogue.Multiple) -> Quarantined and deleted successfully.
              C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\WinCtrl32.dll (Trojan.Agent) -> Delete on reboot.
              C:\WINDOWS\system32\syssetub.dll (Trojan.Agent) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\blphcn0gj0ead9.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
              C:\Documents and Settings\All Users.WINDOWS\Bureau\Antivirus XP 2008.lnk (Rogue.Antivirus) -> Quarantined and deleted successfully.
              0
          3. réouvre malewarebyte
            va sur quarantaine
            supprime tout

            refais un scan hijackthis et post le rapport stp
            0