3 SPYWARE

Bonjour à tous,

Voila, j'ai des pages d'antivirus que je n'ai pas installé qui s'ouvre automatiquement.

Merci d'avnce pour votre aide.

Voila mon hitjackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:43:02, on 16/09/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Softwin\BitDefender10\bdmcon.exe
C:\Program Files\Softwin\BitDefender10\bdagent.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Windows\System32\YURFB6E.exe
C:\Windows\System32\YURFCD5.exe
C:\Windows\System32\YURBB.exe
C:\Windows\System32\YUR84E8.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\System32\YUR435.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\igfxsrvc.exe
C:\Users\LYES\AppData\Local\Temp\RtkBtMnt.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\explorer.exe
C:\Users\LYES\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U4N03T2B\HiJackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.yahoo.com/?p=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*https://fr.yahoo.com/?p=us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [\YURFB6E.exe] C:\Windows\system32\YURFB6E.exe
O4 - HKLM\..\Run: [\YURFCD5.exe] C:\Windows\system32\YURFCD5.exe
O4 - HKLM\..\Run: [\YURBB.exe] C:\Windows\system32\YURBB.exe
O4 - HKLM\..\Run: [\YUR435.exe] C:\Windows\system32\YUR435.exe
O4 - HKLM\..\Run: [ANTIVIRUS] C:\Program Files\MicroAV\MicroAV.exe
O4 - HKLM\..\Run: [\YUR84E8.exe] C:\Windows\system32\YUR84E8.exe
O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [\YURFB6E.exe] C:\Windows\system32\YURFB6E.exe
O4 - HKCU\..\Run: [\YURFCD5.exe] C:\Windows\system32\YURFCD5.exe
O4 - HKCU\..\Run: [\YURBB.exe] C:\Windows\system32\YURBB.exe
O4 - HKCU\..\Run: [\YUR435.exe] C:\Windows\system32\YUR435.exe
O4 - HKCU\..\Run: [ANTIVIRUS] C:\Program Files\MicroAV\MicroAV.exe
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\LYES\AppData\Local\Temp\ljJdcCVM.dll,#1
O4 - HKCU\..\Run: [\YUR84E8.exe] C:\Windows\system32\YUR84E8.exe
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\LYES\AppData\Local\Temp\geBUmklK.dll,c
O4 - HKCU\..\Run: [98e83a53] rundll32.exe "C:\Users\LYES\AppData\Local\Temp\nfsehwqb.dll",b
O4 - HKCU\..\Run: [\YURCD4C.exe] C:\Windows\system32\YURCD4C.exe
O4 - HKCU\..\Run: [\YURCA9E.exe] C:\Windows\system32\YURCA9E.exe
O4 - HKCU\..\Run: [\YURCA9F.exe] C:\Windows\system32\YURCA9F.exe
O4 - HKCU\..\Run: [\YUR482.exe] C:\Windows\system32\YUR482.exe
O4 - HKCU\..\Run: [\YUR47C9.exe] C:\Windows\system32\YUR47C9.exe
O4 - HKCU\..\Run: [\YURB20F.exe] C:\Windows\system32\YURB20F.exe
O4 - HKCU\..\Run: [\YURB3A5.exe] C:\Windows\system32\YURB3A5.exe
O4 - HKCU\..\Run: [\YURB2F9.exe] C:\Windows\system32\YURB2F9.exe
O4 - HKCU\..\Run: [\YURF6FB.exe] C:\Windows\system32\YURF6FB.exe
O4 - HKCU\..\Run: [\YUR311D.exe] C:\Windows\system32\YUR311D.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe
O13 - Gopher Prefix:
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://ma-config.com/activex/hardwaredetection_3_0_3_0.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?e=1218994935203&h=3a4e8775d566f441b41140572151c493/&filename=jinstall-6u7-windows-i586-jc.cab
O16 - DPF: {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe

--
End of file - 11267 bytes
Configuration: Windows Vista
Internet Explorer 7.0

62 réponses

Résumé de la discussion

Problème central : des pages d'antivirus s'ouvrent automatiquement et un rapport HijackThis montre de multiples processus et fichiers potentiellement malveillants sur un système Windows Vista, signe d'infection. Pour y remédier, les répondants privilégient Malwarebytes Anti-Malware en version française, installation suivie d'une mise à jour et d'un balayage complet en mode sans échec. Des conseils complémentaires évoquent l'utilisation de Combofix ou d'autres outils comme OAD, et l'importance de redémarrer en mode sans échec puis de générer un rapport après nettoyage. D'autres propositions complètent la démarche avec des outils tels que ComboFix ou OAD, et insistent sur l'importance d'effectuer le nettoyage en mode sans échec et de partager les rapports pour validation.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Salut,

    protocole à suivre pour Windows Vista :

    *Désactiver le contrôle des comptes utilisateurs ou UAC (le réactiver seulement à la fin de la désinfection) :

    Aller dans "démarrer" puis "panneau de configuration" :
    --->Sur la droite de la fenêtre , cliques sur " affichage classique "
    --->Double-Cliquer sur l'icône "Comptes d'utilisateurs"
    --->Cliquer ensuite sur "Activer ou désactiver le contrôle ..." .
    --->Décocher la case "utlisiser le contrôle ..." et cliquer sur OK .
    Puis redémarrer le PC quand il le vous saura demandé ...

    Tuto : https://forum.malekal.com/viewtopic.php?f=59&t=6517

    * Important :
    Pour installer ou pour lancer les outils, que tu utiliseras au court de la désinfection, fait toujours ainsi :
    cliques DROIT ( sur le setup d'installe ou l'outil )-> choisis " Exécuter entant qu'administrateur " .
    Fais ce-ci systématiquement ! ...

    ****************************************

    Une fois ceci fait et pris en compte , on commence :

    Télécharges SmitfraudFix (de S!Ri, balltrap34 et moe31 ) :
    http://siri.urz.free.fr/Fix/SmitfraudFix.exe

    Installes le soft sur ton bureau ( et pas ailleurs! ) .

    !! Déconnectes toi, fermes toute tes applications et désactives tes défenses ( anti-virus ,anti-spyware,...) le temps de la manipe !!

    Tuto ( aide ) : http://siri.urz.free.fr/Fix/SmitfraudFix.php

    Utilisation ---> option 1 / Recherche :
    Double cliques sur l'icône "Smitfraudfix.exe" et sélectionnes 1 (et pas sur autre chose sans notre accord !) pour créer un rapport des fichiers responsables de l'infection.

    Postes le rapport ( "rapport.txt" qui se trouve sous C\: ) et attends la suite ...

    (Attention : "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool". Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité.)
    0
    1. Avant tout merci, par contre je n'arrive pas a utiliser le logiciel.
      Le tuto ne décrit pas la marche à suivre et je ne m'y connais pas en informatique.
      0
      1. Contributeur sécurité
        Re,

        -_-'

        la marche a suivre , je te l'ai donné ( c'est en gros le résumé du tuto ) .... Le logiciel est un outil qui sert à scanner , trouver et nettoyer une infection ...

        Ce que je te demande est la phase de scan ...

        tu fais donc ceci dans l'ordre bien sûr :

        Télécharges SmitfraudFix (de S!Ri, balltrap34 et moe31 ) :
        http://siri.urz.free.fr/Fix/SmitfraudFix.exe

        Installes le soft sur ton bureau ( et pas ailleurs! ) .

        !! Déconnectes toi, fermes toute tes applications et désactives tes défenses ( anti-virus ,anti-spyware,...) le temps de la manipe !!

        Tuto ( aide ) : http://siri.urz.free.fr/Fix/SmitfraudFix.php

        Utilisation ---> option 1 / Recherche :
        c.a.d ,
        double cliques sur l'icône "Smitfraudfix.exe" et sélectionnes 1 (et pas sur autre chose sans notre accord !) pour créer un rapport des fichiers responsables de l'infection.

        Postes le rapport ( "rapport.txt" qui se trouve sous C:\rapport.txt ) et attends la suite ...

        0
    2. Ce que je veux dire par la c'est que quand j'ouvre "smitfraudfix" , je n'est auune option à choisir (1) et la page n'est pas bleue mais rouge, donc lorsque j'appuie sur une touche, ca ne fait rien du tout (aucun rapport).
      0
      1. Contributeur sécurité
        bien ...

        As tu bien désactivé l'UAC comme je te l'ai demandé ? ...

        Pour lancer Smithfraudfix, tu fais bien clique droit dessus / "exécuter entant qu'administrateur " comme je te l'ai demandé ? ...
        0
        1. Oui biensur.A la lettre.
          0
          1. Contributeur sécurité
            Alors suprimes Smithfraudfix et retélechargex le ... Retentes la manipe et dis moi ....
            0
            1. Le problème persiste!
              Ce ne serais pas une version non compatible avec vista ?
              Merci encore.
              0
              1. Contributeur sécurité
                je pense surtout que c'est ton infection qui contre l'outil ou encore tes défences ... :-/

                As-tu désactivé la protection de Bitdefender avant de lancer l'outil ? ...
                0
                1. Oui ou enfin j'ai mis quitté sur bit defender par-ce qu'il n'y pas moyens de le desactiver.
                  0
                  1. Contributeur sécurité
                    bien ...

                    changeons le fusil d'épaule ...

                    Télécharges MalwareByte's :
                    ici ftp://ftp.commentcamarche.com/download/mbam-setup.exe
                    ou ici : http://www.malwarebytes.org/mbam.php

                    Installes le ( choisis bien "francais" ; ne modifies pas les paramètres d'installe ) et mets le à jour .

                    (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharges le ici : https://www.malekal.com/tutorial-aboutbuster/ )

                    Potasses le tuto pour te familiariser avec le prg : https://forum.pcastuces.com/sujet.asp?f=31&s=3
                    ( cela dis, il est très simple d'utilisation ).

                    Impératif : redémarres en mode sans échec :
                    Comment aller en Mode sans échec
                    1) Redémarres ton ordi
                    2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                    3) Tu verras un écran avec options de démarrage apparaître
                    4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                    5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
                    (attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...)

                    Lances Malwarebyte's .

                    Fais un scan dit "complet" ( sélectionnes bien tous tes disks avant le scan ! ) et supprimes tout ce qu'il peut trouver, c'est à dire :
                    -->Laisses le scan se terminer,puis à la fin tu cliques sur "résultat" .
                    -->Vérifies que tous les objets infectés soient validés, puis cliques sur " suppression " .

                    Redémarres ton PC ( mode normal ).

                    Postes le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date) accompagné d'un nouvel hijackthis ( fait en mode normal ) ...
                    0
                    1. A propos de de malwarebit, il à trouvé 170 infections (c'est enorme non ?).Je ne sais pas ou truvé le rapport !

                      Voici un nouveau hitjackthis :
                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 19:36:10, on 17/09/2008
                      Platform: Windows Vista SP1 (WinNT 6.00.1905)
                      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                      Boot mode: Normal

                      Running processes:
                      C:\Windows\system32\taskeng.exe
                      C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\Windows\RtHDVCpl.exe
                      C:\Program Files\Apoint2K\Apoint.exe
                      C:\Program Files\Softwin\BitDefender10\bdmcon.exe
                      C:\Program Files\Softwin\BitDefender10\bdagent.exe
                      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                      C:\Windows\System32\hkcmd.exe
                      C:\Windows\System32\igfxpers.exe
                      C:\Program Files\Logitech\QuickCam\Quickcam.exe
                      C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
                      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                      C:\Windows\system32\wbem\unsecapp.exe
                      C:\Windows\system32\igfxsrvc.exe
                      C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                      C:\Program Files\Apoint2K\ApMsgFwd.exe
                      C:\Program Files\Apoint2K\Apntex.exe
                      C:\Users\LYES\AppData\Local\Temp\RtkBtMnt.exe
                      C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
                      C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Windows\system32\conime.exe
                      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\Users\LYES\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\11WA87EN\HiJackThis[1].exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.yahoo.com/?p=us
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*https://fr.yahoo.com/?p=us
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                      O1 - Hosts: ::1 localhost
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                      O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                      O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
                      O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
                      O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
                      O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                      O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
                      O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                      O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                      O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                      O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
                      O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                      O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe (file missing)
                      O13 - Gopher Prefix:
                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://ma-config.com/activex/hardwaredetection_3_0_3_0.cab
                      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?e=1218994935203&h=3a4e8775d566f441b41140572151c493/&filename=jinstall-6u7-windows-i586-jc.cab
                      O16 - DPF: {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                      O20 - AppInit_DLLs: tbpenj.dll
                      O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                      O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
                      O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
                      O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                      O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                      O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
                      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                      O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                      O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
                      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                      O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
                      0
                      1. Contributeur sécurité
                        Postes moi le rapport de Malwarebytes .

                        Pour le trouver , c'est tout expliqué dans les deux dernières lignes ici ...
                        0
                        1. Je crois bien que j'ai fait une connerie, je pense que je l'avais déjà éffacé et que celui-ci c'est celui de ma deuxième analyse rapide :Malwarebytes' Anti-Malware 1.28
                          Version de la base de données: 1164
                          Windows 6.0.6001 Service Pack 1

                          17/09/2008 19:36:33
                          mbam-log-2008-09-17 (19-36-33).txt

                          Type de recherche: Examen rapide
                          Eléments examinés: 39034
                          Temps écoulé: 3 minute(s), 11 second(s)

                          Processus mémoire infecté(s): 0
                          Module(s) mémoire infecté(s): 0
                          Clé(s) du Registre infectée(s): 0
                          Valeur(s) du Registre infectée(s): 0
                          Elément(s) de données du Registre infecté(s): 0
                          Dossier(s) infecté(s): 0
                          Fichier(s) infecté(s): 0

                          Processus mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Module(s) mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Clé(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Valeur(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Elément(s) de données du Registre infecté(s):
                          (Aucun élément nuisible détecté)

                          Dossier(s) infecté(s):
                          (Aucun élément nuisible détecté)

                          Fichier(s) infecté(s):
                          (Aucun élément nuisible détecté)
                          0
                          1. Contributeur sécurité
                            Celui-ci n'a aucun intéret ... ;)
                            Quand tu ouvres l'onglet "rapport/log" tu dois en avoir d'autre non ? .... si oui , ouvres celui où il y a 170 objets infectés et postes le stp , c'est celui-la qui m'intéresse ...

                            mais d'avis aussi que tu l'as passé en mode normal , non ?
                            0
                        2. Etant donné que je l'ai éffacé, dois-je recommencer une analyse ?
                          0
                          1. Contributeur sécurité
                            Grrrr , j'aurais bien aimé voir ce qu'il a supprimé ...

                            Soit ...

                            1- Télécharges : - CCleaner
                            https://www.pcastuces.com/logitheque/ccleaner.htm
                            Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corrigé ton registre .Lors de l'installation, avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 première.
                            Une fois le prg instalé et lancé, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures"( Par la suite, laisse-le avec ses réglages par défaut. C'est tout ).

                            Un tuto ( aide ):
                            http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

                            ---> Utilisation:
                            ! déconnectes toi et fermes toutes applications en cours !
                            * vas dans "nettoyeur" : fait analyse puis nettoyage
                            * vas dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .

                            ( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )

                            2- retentes Smithfraudfix maintenant et dis moi ...
                            0
                            1. Tu avais raison.

                              Le rapport sitfraudfix :

                              SmitFraudFix v2.352

                              Scan done at 20:29:52,82, 17/09/2008
                              Run from C:\Users\LYES\Desktop\SmitfraudFix
                              OS: Microsoft Windows [version 6.0.6001] - Windows_NT
                              The filesystem type is NTFS
                              Fix run in normal mode

                              »»»»»»»»»»»»»»»»»»»»»»»» Process

                              C:\Windows\system32\csrss.exe
                              C:\Windows\system32\wininit.exe
                              C:\Windows\system32\csrss.exe
                              C:\Windows\system32\services.exe
                              C:\Windows\system32\lsass.exe
                              C:\Windows\system32\lsm.exe
                              C:\Windows\system32\winlogon.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\SLsvc.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\spoolsv.exe
                              C:\Windows\system32\svchost.exe
                              C:\Acer\ALaunch\ALaunchSvc.exe
                              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                              C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                              C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                              C:\Acer\Mobility Center\MobilityService.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\SearchIndexer.exe
                              C:\Windows\system32\DRIVERS\xaudio.exe
                              C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
                              C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                              C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
                              C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\Explorer.EXE
                              C:\Program Files\Windows Defender\MSASCui.exe
                              C:\Windows\RtHDVCpl.exe
                              C:\Program Files\Apoint2K\Apoint.exe
                              C:\Program Files\Softwin\BitDefender10\bdmcon.exe
                              C:\Program Files\Softwin\BitDefender10\bdagent.exe
                              C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                              C:\Windows\System32\hkcmd.exe
                              C:\Windows\System32\igfxpers.exe
                              C:\Program Files\Logitech\QuickCam\Quickcam.exe
                              C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
                              C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                              C:\Program Files\Windows Media Player\wmpnscfg.exe
                              C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                              C:\Program Files\Softwin\BitDefender10\vsserv.exe
                              C:\Windows\system32\wbem\unsecapp.exe
                              C:\Windows\system32\wbem\wmiprvse.exe
                              C:\Windows\system32\igfxsrvc.exe
                              C:\Program Files\Windows Media Player\wmpnetwk.exe
                              C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                              C:\Program Files\Apoint2K\ApMsgFwd.exe
                              C:\Program Files\Apoint2K\Apntex.exe
                              C:\Users\LYES\AppData\Local\Temp\RtkBtMnt.exe
                              C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\Windows\system32\conime.exe
                              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                              C:\Program Files\Windows Live\Messenger\usnsvc.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Windows\system32\SearchProtocolHost.exe
                              C:\Windows\system32\SearchFilterHost.exe
                              C:\Windows\system32\cmd.exe
                              C:\Windows\system32\wbem\wmiprvse.exe

                              »»»»»»»»»»»»»»»»»»»»»»»» hosts

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\LYES

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\LYES\Application Data

                              »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\LYES\FAVORI~1

                              »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                              »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                              »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                              »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                              !!!Attention, following keys are not inevitably infected!!!

                              IEDFix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                              !!!Attention, following keys are not inevitably infected!!!

                              VACFix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                              !!!Attention, following keys are not inevitably infected!!!

                              404Fix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
                              !!!Attention, following keys are not inevitably infected!!!

                              »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                              !!!Attention, following keys are not inevitably infected!!!

                              SrchSTS.exe by S!Ri
                              Search SharedTaskScheduler's .dll

                              »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                              !!!Attention, following keys are not inevitably infected!!!

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                              "LoadAppInit_DLLs"=dword:00000001
                              "AppInit_DLLs"="tbpenj.dll"

                              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                              !!!Attention, following keys are not inevitably infected!!!

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                              "Userinit"="C:\\Windows\\system32\\userinit.exe,"

                              »»»»»»»»»»»»»»»»»»»»»»»» RK

                              »»»»»»»»»»»»»»»»»»»»»»»» DNS

                              Description: Atheros AR5007EG Wireless Network Adapter
                              DNS Server Search Order: 192.168.1.1

                              HKLM\SYSTEM\CCS\Services\Tcpip\..\{28883261-738E-4157-82F4-37E0F0CCDFCC}: DhcpNameServer=192.168.1.1

                              »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                              »»»»»»»»»»»»»»»»»»»»»»»» End
                              0
                              1. Contributeur sécurité
                                Suite de la manipe ( nettoyage ), fais exactement ce qui suit :

                                * Impératif : Redémarrer l'ordinateur en mode sans échec .
                                Comment aller en Mode sans échec
                                1) Redémarre ton ordi
                                2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                                3) Tu verras un écran avec options de démarrage apparaître
                                4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                                5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
                                ( ps : n'oublies pas , en mode sans échec , pas de connexion ! Donc copies ou imprimes bien les info ci-dessous ...)

                                *Double click sur SmitfraudFix.exe

                                * Sélectionnes 2 et presses "Entrée" dans le menu pour supprimer les fichiers responsables de l'infection.

                                -> Si besion :
                                * A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et presser Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection.

                                ( Le correctif déterminera si le fichier wininet.dll est infecté.)

                                * A la question: "Corriger le fichier infecté ?" répondre O (oui) et presser Entrée
                                pour remplacer le fichier corrompu.

                                * Un redémarrage sera peut être nécessaire pour terminer la procédure de nettoyage ( sinon fais le manuellement )

                                Le rapport se trouve à la racine de C\:
                                (dans le fichier "rapport.txt")

                                Postes moi ce dernier rapport accompagné, dans la même réponse, d'un nouveau rapport
                                hijackthis ( fais en mode normal ) et attends les instructions ...
                                0
                                1. Merci tous les virus ont l'air d'avoir disparu.

                                  SmitFraudFix v2.352

                                  Scan done at 21:45:58,05, 17/09/2008
                                  Run from C:\Users\LYES\Desktop\SmitfraudFix
                                  OS: Microsoft Windows [version 6.0.6001] - Windows_NT
                                  The filesystem type is NTFS
                                  Fix run in normal mode

                                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                                  !!!Attention, following keys are not inevitably infected!!!

                                  SrchSTS.exe by S!Ri
                                  Search SharedTaskScheduler's .dll

                                  »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                  127.0.0.1 localhost
                                  ::1 localhost

                                  »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                                  VACFix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                                  S!Ri's WS2Fix: LSP not Found.

                                  »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                                  GenericRenosFix by S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                                  »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                                  IEDFix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                                  404Fix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

                                  »»»»»»»»»»»»»»»»»»»»»»»» RK

                                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                  Description: Atheros AR5007EG Wireless Network Adapter
                                  DNS Server Search Order: 192.168.1.1

                                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{28883261-738E-4157-82F4-37E0F0CCDFCC}: DhcpNameServer=192.168.1.1

                                  »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

                                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                                  !!!Attention, following keys are not inevitably infected!!!

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                                  »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                                  Registry Cleaning done.

                                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                                  !!!Attention, following keys are not inevitably infected!!!

                                  SrchSTS.exe by S!Ri
                                  Search SharedTaskScheduler's .dll

                                  »»»»»»»»»»»»»»»»»»»»»»»» End
                                  0
                                  1. Et voici le hitjackthis ;

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 21:54:48, on 17/09/2008
                                    Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\Windows\system32\taskeng.exe
                                    C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                                    C:\Windows\system32\Dwm.exe
                                    C:\Program Files\Windows Defender\MSASCui.exe
                                    C:\Windows\RtHDVCpl.exe
                                    C:\Program Files\Apoint2K\Apoint.exe
                                    C:\Program Files\Softwin\BitDefender10\bdmcon.exe
                                    C:\Program Files\Softwin\BitDefender10\bdagent.exe
                                    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                                    C:\Windows\System32\hkcmd.exe
                                    C:\Windows\System32\igfxpers.exe
                                    C:\Program Files\Logitech\QuickCam\Quickcam.exe
                                    C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
                                    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                                    C:\Program Files\Windows Media Player\wmpnscfg.exe
                                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                    C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                    C:\Windows\System32\mobsync.exe
                                    C:\Windows\system32\wbem\unsecapp.exe
                                    C:\Windows\system32\igfxsrvc.exe
                                    C:\Program Files\Apoint2K\ApMsgFwd.exe
                                    C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Windows\system32\conime.exe
                                    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                    C:\Program Files\Apoint2K\Apntex.exe
                                    C:\Users\LYES\AppData\Local\Temp\RtkBtMnt.exe
                                    C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
                                    C:\Windows\system32\cmd.exe
                                    C:\Windows\explorer.exe
                                    C:\Windows\notepad.exe
                                    C:\Users\LYES\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GQCIZW9Q\HiJackThis[1].exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                    O1 - Hosts: ::1 localhost
                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                                    O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                                    O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
                                    O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
                                    O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
                                    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                                    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
                                    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                                    O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                    O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                                    O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
                                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
                                    O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
                                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
                                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
                                    O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe (file missing)
                                    O13 - Gopher Prefix:
                                    O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://ma-config.com/activex/hardwaredetection_3_0_3_0.cab
                                    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?e=1218994935203&h=3a4e8775d566f441b41140572151c493/&filename=jinstall-6u7-windows-i586-jc.cab
                                    O16 - DPF: {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                    O20 - AppInit_DLLs: tbpenj.dll
                                    O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                                    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
                                    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
                                    O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                                    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                                    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
                                    O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                                    O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                                    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                                    O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
                                    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                                    O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
                                    0
                                    1. Contributeur sécurité
                                      bien ...

                                      Je vien de remarquer que ton Hijackthis est dans les fichiers temp ( tu as exécuté le prg au téléchargement ) . En cas d"erreur d'utilisation de celui-ci , pas de possibilité de revenir en arrière ...

                                      Donc fais ce qui suit dans l'ordre :

                                      1- Télécharges et installes le logiciel HijackThis :

                                      ici ftp://ftp.commentcamarche.com/download/HJTInstall.exe
                                      ou ici http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
                                      ou ici https://www.clubic.com/telecharger-fiche17891-hijackthis.html

                                      -> Cliques sur le setup pour lancer l'installe : laisses toi guider et ne modifies pas les paramètres d'installation .
                                      A la fin de l'installe , le prg ce lance automatiquement : fermes le en cliquant sur la croix rouge .
                                      Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
                                      "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

                                      ( ne fais pas de scan pour le momment )

                                      2-refais un coup de CCleaner (registre compris ) .

                                      3- fais exactement ce qui suit :

                                      Télécharges ComboFix (par sUBs) sur ton Bureau (et pas ailleurs !):
                                      http://download.bleepingcomputer.com/sUBs/ComboFix.exe <--- clik droit sur ce lien et choisis "enregistrer la cible sous ... " : dans la fenêtre qui s'ouvre tape C-Fix et valide .

                                      --------------------------------------------- [ ! ATTENTION ! ] ----------------------------------------------------------
                                      !! Déconnectes toi,fermes tes applications en cours et DESACTIVES TOUTES TES DEFENSES (anti-virus, guardes anti spy-ware, pare-feu) le temps de la manipe :
                                      en effet , activés, ils pourraient gêner fortement la procédure de recherche et de nettoyage de l'outil ( voir planter le PC )...Tu les réactiveras donc après !!
                                      --->Important : si tu rencontres des difficultés à ce niveau là, fais m'en part avant de poursuivre ...
                                      Tuto ( aide ) ici : https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                                      ---------------------------------------------------------------------------------------------------------------------------------

                                      Ensuite :
                                      double-cliques C-Fix.exe ( = combofix.exe ) .

                                      Appuyes sur la touche Y (Yes) pour démarrer le scan .

                                      Attention :
                                      --> n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi .
                                      --> Il se peut que le PC redémarre de lui même ( pour finaliser le nettoyage ) , laisses le faire .
                                      --> si un message d'erreur windows apparait à un momment : clik sur la croix rouge en haut à droite de la fenêtre pour la fermer ( et pas sur autre chose ! sinon pas de rapport ... )

                                      Le rapport sera crée dans: C:\Combofix.txt

                                      Postes le rapport Combofix accompagné d'un nouveau rapport hijackthis pour analyse ...

                                      0
                                      • 1
                                      • 2
                                      • 3
                                      • 4