Plantage pc

Bonjour,
Mon pc portable , qui n'a que 3 mois d'ailleurs, plante soit au démarrage soit après. Au démarrage, j'ai un ecran noir avec uniquement la souris juste avant que l'on me demande mon mot de passe. Ou alors quand il démarre (c'est plus rare), il plante après quelques minutes d'utilisation, l'ecran se fige et plus rien ne marche, même ctrl+alt+supp.
Par contre en mode sans echec avec prise en charge réseau il fonctionne normalement.

C'est un toshiba P300D-11M
AMD Turion x2 TL-60 2.00 GHz
3 Go de ram
ATI Radeon 3650 HD

J'ai lancé une analyse antivirus (avast) et ccleaner. J'ai tenté une analyse antivirus en ligne mais en mode sans echec ca n'a pas l'air possible.

Voici le log d'HijackThis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:15:42, on 23/09/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\Users\Sylvain\AppData\Local\Temp\Rar$EX00.919\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: QXK Olive - {8B93A89B-7332-4B4B-830C-72EB6323D0DB} - C:\Windows\vmgspntbvlw.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
O4 - HKLM\..\Run: [HDMICtrlMan] C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Users\Sylvain\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

--
End of file - 9564 bytes

Merci d'avance pour votre aide.
Configuration: Windows Vista
Internet Explorer 7.0

13 réponses

  1. En fait, a la base j'avais bitdefender, quand mon pc a commencé a planté j'ai voulu faire une analyse avec et là surprise il me dit qu'il a expiré alors que l'ai depuis 3 mois !!!! Du coup j'ai installé avast mais je n'arrive pas à désinstaller bitdefender en mode sans echec.
    0
    1. Excuse moi jlpjlp, mais j'ai essayé et je ne comprends pas ce que je dois faire, est ce qu'il serait possible d'avoir un peu plus de détail. Merci
      Surtout en ce qui concerne smit fraud fix
      Qu'est ce que je dois faire dans HijackThis ?
      0
      1. SmitFraudFix v2.353

        Scan done at 10:43:54,03, 23/09/2008
        Run from C:\Users\Sylvain\Desktop\SmitfraudFix
        OS: Microsoft Windows [version 6.0.6001] - Windows_NT
        The filesystem type is
        Fix run in safe mode

        »»»»»»»»»»»»»»»»»»»»»»»» Process

        C:\Windows\system32\csrss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\Explorer.EXE
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Users\Sylvain\AppData\Local\Temp\Rar$EX00.451\HijackThis.exe
        C:\Windows\notepad.exe
        C:\Windows\system32\cmd.exe
        C:\Windows\system32\wbem\wmiprvse.exe

        »»»»»»»»»»»»»»»»»»»»»»»» hosts

        »»»»»»»»»»»»»»»»»»»»»»»» C:\

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

        C:\Windows\mqgldfvo.exe FOUND !

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

        C:\Windows\system32\tdssservers.dat detected, use a Rootkit scanner
        C:\Windows\system32\tdssadw.dll detected, use a Rootkit scanner
        C:\Windows\system32\tdssinit.dll detected, use a Rootkit scanner
        C:\Windows\system32\tdssl.dll detected, use a Rootkit scanner
        C:\Windows\system32\drivers\tdssserv.sys detected, use a Rootkit scanner

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Sylvain

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Sylvain\Application Data

        »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Sylvain\FAVORI~1

        »»»»»»»»»»»»»»»»»»»»»»»» Desktop

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

        »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

        »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

        »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
        !!!Attention, following keys are not inevitably infected!!!

        o4Patch
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
        !!!Attention, following keys are not inevitably infected!!!

        IEDFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» VACFix
        !!!Attention, following keys are not inevitably infected!!!

        VACFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri
        +--------------------------------------------------+
        [!] Suspicious: vmgspntbvlw.dll
        BHO: QXK Olive - {8B93A89B-7332-4B4B-830C-72EB6323D0DB}
        TypeLib: {CB367C75-6190-4CE0-A255-7C1199F0358E}
        Interface: {2F9B1A90-1E69-41EB-AD33-6202AAD9A554}
        Interface: {3A412635-30FD-42D0-A704-C9493BE88B9C}

        »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
        !!!Attention, following keys are not inevitably infected!!!

        404Fix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
        !!!Attention, following keys are not inevitably infected!!!

        AntiXPVSTFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
        !!!Attention, following keys are not inevitably infected!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
        !!!Attention, following keys are not inevitably infected!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
        "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~3\\GOEC62~1.DLL"
        "LoadAppInit_DLLs"=dword:00000001

        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
        !!!Attention, following keys are not inevitably infected!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
        "Userinit"="C:\\Windows\\system32\\userinit.exe,"

        »»»»»»»»»»»»»»»»»»»»»»»» RK

        »»»»»»»»»»»»»»»»»»»»»»»» DNS

        Description: Adaptateur réseau USB 2.0 54Mbps, 802.11b/g sans fil Realtek RTL8187B
        DNS Server Search Order: 89.2.0.1
        DNS Server Search Order: 89.2.0.2

        HKLM\SYSTEM\CCS\Services\Tcpip\..\{96020708-D4A2-47CA-9B88-6F7B30941A44}: DhcpNameServer=89.2.0.1 89.2.0.2
        HKLM\SYSTEM\CCS\Services\Tcpip\..\{A0ECE9D8-20EF-407F-B0DB-89D406C69A29}: DhcpNameServer=89.2.0.1 89.2.0.2
        HKLM\SYSTEM\CS1\Services\Tcpip\..\{96020708-D4A2-47CA-9B88-6F7B30941A44}: DhcpNameServer=89.2.0.1 89.2.0.2
        HKLM\SYSTEM\CS1\Services\Tcpip\..\{A0ECE9D8-20EF-407F-B0DB-89D406C69A29}: DhcpNameServer=89.2.0.1 89.2.0.2
        HKLM\SYSTEM\CS2\Services\Tcpip\..\{96020708-D4A2-47CA-9B88-6F7B30941A44}: DhcpNameServer=89.2.0.1 89.2.0.2
        HKLM\SYSTEM\CS2\Services\Tcpip\..\{A0ECE9D8-20EF-407F-B0DB-89D406C69A29}: DhcpNameServer=89.2.0.1 89.2.0.2
        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=89.2.0.1 89.2.0.2
        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=89.2.0.1 89.2.0.2
        HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=89.2.0.1 89.2.0.2

        »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

        »»»»»»»»»»»»»»»»»»»»»»»» End
        0
        1. Malwarebytes' Anti-Malware 1.28
          Version de la base de données: 1134
          Windows 6.0.6001 Service Pack 1

          23/09/2008 12:58:14
          mbam-log-2008-09-23 (12-58-14).txt

          Type de recherche: Examen rapide
          Eléments examinés: 43065
          Temps écoulé: 2 minute(s), 26 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 1
          Clé(s) du Registre infectée(s): 4
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 6

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          C:\Windows\System32\tdssserf.dll (Trojan.Agent) -> Delete on reboot.

          Clé(s) du Registre infectée(s):
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\fqbewlna.bemv (Trojan.FakeAlert) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\fqbewlna.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          C:\Windows\System32\tdssadw.dll (Trojan.Agent) -> Delete on reboot.
          C:\Windows\System32\tdssl.dll (Trojan.Agent) -> Delete on reboot.
          C:\Windows\System32\tdssserf.dll (Trojan.Agent) -> Delete on reboot.
          C:\Windows\System32\tdssinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.
          C:\Windows\System32\tdssservers.dat (Trojan.Agent) -> Quarantined and deleted successfully.
          C:\Windows\System32\drivers\tdssserv.sys (Trojan.Agent) -> Delete on reboot.

          SmitFraudFix v2.353

          Scan done at 12:59:38,78, 23/09/2008
          Run from C:\Users\Sylvain\Desktop\SmitfraudFix
          OS: Microsoft Windows [version 6.0.6001] - Windows_NT
          The filesystem type is
          Fix run in safe mode

          »»»»»»»»»»»»»»»»»»»»»»»» Process

          C:\Windows\system32\csrss.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\winlogon.exe
          C:\Windows\system32\services.exe
          C:\Windows\system32\lsass.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Windows\explorer.exe
          C:\Windows\system32\wbem\unsecapp.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
          C:\Windows\system32\cmd.exe
          C:\Windows\system32\cmd.exe
          C:\Windows\system32\wbem\wmiprvse.exe

          »»»»»»»»»»»»»»»»»»»»»»»» hosts

          »»»»»»»»»»»»»»»»»»»»»»»» C:\

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

          C:\Windows\system32\tdssadw.dll detected, use a Rootkit scanner
          C:\Windows\system32\tdssl.dll detected, use a Rootkit scanner
          C:\Windows\system32\drivers\tdssserv.sys detected, use a Rootkit scanner

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Sylvain

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Sylvain\Application Data

          »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Sylvain\FAVORI~1

          »»»»»»»»»»»»»»»»»»»»»»»» Desktop

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

          »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

          »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

          »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
          !!!Attention, following keys are not inevitably infected!!!

          o4Patch
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
          !!!Attention, following keys are not inevitably infected!!!

          IEDFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» VACFix
          !!!Attention, following keys are not inevitably infected!!!

          VACFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
          !!!Attention, following keys are not inevitably infected!!!

          404Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
          !!!Attention, following keys are not inevitably infected!!!

          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
          !!!Attention, following keys are not inevitably infected!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
          !!!Attention, following keys are not inevitably infected!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~3\\GOEC62~1.DLL"
          "LoadAppInit_DLLs"=dword:00000001

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
          !!!Attention, following keys are not inevitably infected!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "Userinit"="C:\\Windows\\system32\\userinit.exe,"

          »»»»»»»»»»»»»»»»»»»»»»»» RK

          »»»»»»»»»»»»»»»»»»»»»»»» DNS

          Description: Adaptateur réseau USB 2.0 54Mbps, 802.11b/g sans fil Realtek RTL8187B
          DNS Server Search Order: 89.2.0.1
          DNS Server Search Order: 89.2.0.2

          HKLM\SYSTEM\CCS\Services\Tcpip\..\{96020708-D4A2-47CA-9B88-6F7B30941A44}: DhcpNameServer=89.2.0.1 89.2.0.2
          HKLM\SYSTEM\CCS\Services\Tcpip\..\{A0ECE9D8-20EF-407F-B0DB-89D406C69A29}: DhcpNameServer=89.2.0.1 89.2.0.2
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{96020708-D4A2-47CA-9B88-6F7B30941A44}: DhcpNameServer=89.2.0.1 89.2.0.2
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{A0ECE9D8-20EF-407F-B0DB-89D406C69A29}: DhcpNameServer=89.2.0.1 89.2.0.2
          HKLM\SYSTEM\CS2\Services\Tcpip\..\{96020708-D4A2-47CA-9B88-6F7B30941A44}: DhcpNameServer=89.2.0.1 89.2.0.2
          HKLM\SYSTEM\CS2\Services\Tcpip\..\{A0ECE9D8-20EF-407F-B0DB-89D406C69A29}: DhcpNameServer=89.2.0.1 89.2.0.2
          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=89.2.0.1 89.2.0.2
          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=89.2.0.1 89.2.0.2
          HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=89.2.0.1 89.2.0.2

          »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

          »»»»»»»»»»»»»»»»»»»»»»»» End

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 13:01:24, on 23/09/2008
          Platform: Windows Vista SP1 (WinNT 6.00.1905)
          MSIE: Internet Explorer v7.00 (7.00.6001.18000)
          Boot mode: Safe mode with network support

          Running processes:
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Windows\explorer.exe
          C:\Windows\system32\wbem\unsecapp.exe
          C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
          C:\Program Files\WinRAR\WinRAR.exe
          C:\Users\Sylvain\AppData\Local\Temp\Rar$EX00.232\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O1 - Hosts: ::1 localhost
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
          O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
          O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
          O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
          O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
          O4 - HKLM\..\Run: [HDMICtrlMan] C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
          O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
          O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
          O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
          O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
          O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
          O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
          O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
          O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
          O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
          O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
          O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [Google Update] "C:\Users\Sylvain\AppData\Local\Google\Update\GoogleUpdate.exe" /c
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (User 'Default user')
          O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
          O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
          O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
          O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
          O13 - Gopher Prefix:
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
          O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
          O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
          O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
          O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
          O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
          O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
          O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
          O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
          O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
          O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
          O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
          O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
          O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
          0
          1. Je n'ai pas fait la dernière chose que tu m'as conseillé et cela fait maintenant 45 mn que mon pc fonctionne normalement sans être en mode sans echec alors je pense que mon problème est résolu, en tout cas je l'espère !!!
            Un grand merci pour votre aide, surtout à toi jlpjlp !
            à plus
            0
            1. Bonjour,

              En plus d'Avast, il semblerait que tu es Bit Defender. Ce n'est pas recommandé d'avoir deux anti-virus. Commence par désinstaller l'un des deux, fais un nettoyage avec CCleaner et vois ce que ça donne.
              -1
              1. Contributeur sécurité
                slt oui un seul antivirus sur un ordi sinon cela palnte!!!

                vire avast comme ceci
                https://www.avast.com/fr-fr/uninstall-utility

                ensuite tu as une infection ici:

                O2 - BHO: QXK Olive - {8B93A89B-7332-4B4B-830C-72EB6323D0DB} - C:\Windows\vmgspntbvlw.dll

                donc fais ceci:

                smit fraud fix (colle le rapport)

                1/ telecharger :

                http://siri.urz.free.fr/Fix/SmitfraudFix.php

                2/ double clique sur smitfraudfix. puis sélectionne 1 et appuyer sur entrée afin de créer le rapport des infection présentes.
                -1
                1. Il me semble qu'il existe un outil pour supprimer Bit Defender. S'il a expiré, autant le désinstaller.
                  -1
                  1. Contributeur sécurité
                    pour virer bitdefender: regarde ici http://www.bitdefender.fr/KB333-fr--Desinstaller-BitDefender.html

                    et colle le rapport smitfraudfix aussi:!
                    -1
                    1. Contributeur sécurité
                      pour smitfraudfix tu clique sur le lien donné en bleu pour le telecharger sur ton bureau puis tu lance le logiciel téléchargé et tu fais l'option 1 et tu me colle le rapport

                      pour hijackhtis on ne fixe rien!
                      -1
                      1. Contributeur sécurité
                        ok

                        redémarre en mode sans échec (en appuyant sur F8 ou suppr, ou F5 au démarrage en général) puis lance smitfraudfix , sélectionne l'option 2 et appuyer sur entrée pour commencer la désinfection. lorsque le programme demande si tu veut nettoyer le registre mets oui en tapant 0 et entrée

                        _______________________

                        scan avec
                        MalwareByte's Anti-Malware et vire ce qui est trouvé et colle le rapport

                        https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

                        _______________________

                        remets un rapport smitfraudfix avec l'option 1
                        et hijakchtis

                        a plus
                        -1
                        1. Contributeur sécurité
                          avant de faire smitfraudfix: tu avais redemarré pour finir de nettoyer avec malwarebyte comme il est demandé ????

                          __________________

                          si c'est pas le cas redemarre et finit de nettoyer avec Malwarebyte

                          puis recolle un rapport smitfraudfix

                          ______________

                          si tu l'avais fais:

                          télécharge combofix (par sUBs) ici :

                          http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                          et enregistre le sur le bureau.

                          déconnecte toi d'internet et ferme toutes tes applications.

                          désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

                          double-clique sur combofix.exe et suis les instructions

                          à la fin, il va produire un rapport C:\ComboFix.txt

                          réactive ton parefeu, ton antivirus, la garde de ton antispyware

                          copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

                          Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

                          Tu as un tutoriel complet ici :

                          https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                          a plus
                          -1
                          1. Contributeur sécurité
                            recolle moi un rapport smitfraudfix avec option 1 SVP
                            -1