Trojan

Résolu
Bonjour,

J'ai un trojan qui m'envoie des messages en permance

trojan spy htlm bankfraud dq.

Merci de votre aide pour m'en débarasser...
Configuration: Windows XP
Internet Explorer 7.0

68 réponses

Résumé de la discussion

La problématique porte sur un Trojan qui génère des messages persistants et collecte/transmet des informations, affectant Windows XP avec Internet Explorer 7. Plusieurs réponses recommandent d’installer ou d’utiliser Malwarebytes et d’activer le pare-feu Windows, puis d’initier une détection et une suppression via des outils spécialisés. Des étapes détaillées évoquent ToolBar S&D, smitfraudfix et la génération de rapports, ainsi que des précautions concernant certains composants jugés risqués mais potentiellement utiles. En parallèle, des rapports de détection et des indications comme NaviProm et Navilog apparaissent, soulignant la nécessité de partager les résultats pour analyse avant toute désinfection.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Salut !!

    Fais un rapport hijackthis pour que je puisse vérifier les infections de ton pc stp

    ▶ Télécharge hijackthis à cette adresse, tout est expliqué pour bien l installer et pour savoir s'en servir :

    https://www.androidworld.fr/

    Comment copier/coller le rapport :

    Quand tu as le rapport à l écran, tu fais ctrl A pour "sélectionner tout" puis ctrl C pour "copier".

    ensuite tu viens sur le forum pour me répondre et tu fais ctrl V pour "coller" le rapport.

    Une explication des raccourcis clavier sont illustrés sur mon site web à cette adresse :

    https://www.androidworld.fr/
    1. Voila le rapport hijackthis

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 15:29:07, on 24/09/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\Program Files\Unlocker\UnlockerAssistant.exe
      C:\Program Files\Search Settings\SearchSettings.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\WINDOWS\system32\lphccbdj0e557.exe
      C:\Program Files\POP Peeper\POPPeeper.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\system32\pwbibwjq.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\PROGRA~1\AVG\AVG8\avgemc.exe
      C:\WLCI\TP5G APPLICATION\TP5G.exe
      C:\WINDOWS\system32\fxssvc.exe
      C:\Program Files\NOLIS\Felix\Felix.exe
      C:\Documents and Settings\Philippe\Mes documents\Downloads\HiJackThis.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb126\SearchSettings.dll
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb126\Dealio.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb126\SearchSettings.dll
      O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb126\Dealio.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
      O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe
      O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
      O4 - HKLM\..\Run: [lphccbdj0e557] C:\WINDOWS\system32\lphccbdj0e557.exe
      O4 - HKCU\..\Run: [POP Peeper] "C:\Program Files\POP Peeper\POPPeeper.exe" -min
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [acten] C:\WINDOWS\system32\pwbibwjq.exe
      O4 - HKLM\..\Policies\Explorer\Run: [aE85JJajLV] C:\Documents and Settings\Philippe\Mes documents\Downloads\AdobeFlashPlayerHD.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
      O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\Philippe\Application Data\Dealio\kb126\res\DealioSearch.html
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb126\Dealio.dll
      O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb126\Dealio.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - AppInit_DLLs: avgrsstx.dll
      O21 - SSODL: AdmSmart - {134272DE-2C37-14CA-F8F5-08E00F25118C} - C:\Program Files\yyzkdmc\AdmSmart.dll
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
      1. Contributeur sécurité
        commence par faire ceci stp :

        ▶ Télécharge Toolbar-S&D (de Team IDN) sur ton Bureau

        (c est le numéro 6 en bas de la page) :

        ▶ Lance l'installation du programme en exécutant le fichier téléchargé.
        ▶ Double-clique maintenant sur le raccourci de Toolbar-S&D.
        ▶ Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
        ▶ Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
        ▶ Poste le rapport généré. (C:\TB.txt)
        1. Voila le rapport demandé.

          -----------\\ ToolBar S&D 1.2.0 XP/Vista

          Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
          X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.00GHz )
          BIOS : Default System BIOS
          USER : Philippe ( Administrator )
          BOOT : Normal boot
          Antivirus : AVG Anti-Virus Free 8.0 (Activated)
          A:\ (USB)
          C:\ (Local Disk) - NTFS - Total : 35 Go Free : 10 Go
          D:\ (Local Disk) - FAT32 - Total : 35 Go Free : 7 Go
          E:\ (CD or DVD)

          "C:\ToolBar SD" ( MAJ : 14-09-2008|23:30 )
          Option : [1] ( 24/09/2008|15:42 )

          -----------\\ Recherche de Fichiers / Dossiers ...

          C:\DOCUME~1\Philippe\APPLIC~1\Dealio
          C:\DOCUME~1\Philippe\APPLIC~1\Dealio\dinstallhelper.2CF719EF65BF4170824C917A9AFD659A.dll
          C:\DOCUME~1\Philippe\APPLIC~1\Dealio\kb126
          C:\Program Files\Dealio
          C:\Program Files\Dealio\DealioAU.exe
          C:\Program Files\Dealio\kb126
          C:\Program Files\Dealio\SearchSettingsKit.exe
          C:\WINDOWS\Prefetch\DEALIOAU.EXE-17E14027.pf
          C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Dealio
          C:\WINDOWS\Prefetch\SEARCHSETTINGS.EXE-0107F828.pf
          C:\DOCUME~1\Philippe\APPLIC~1\Search Settings
          C:\DOCUME~1\Philippe\APPLIC~1\Search Settings\kb126
          C:\Program Files\Search Settings
          C:\Program Files\Search Settings\kb126
          C:\Program Files\Search Settings\SearchSettings.exe

          -----------\\ Extensions

          (Philippe) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

          -----------\\ [..\Internet Explorer\Main]

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
          "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
          "Start Page"="https://www.google.com/?hl=fr&gws_rd=ssl"
          "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
          "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
          "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Start Page"="http://www.ustart.org"

          --------------------\\ Recherche d'autres infections

          Aucune autre infection trouvée !

          1 - "C:\ToolBar SD\TB_1.txt" - 24/09/2008|15:42 - Option : [1]

          -----------\\ Fin du rapport a 15:42:44,26
          1. Contributeur sécurité
            ok maintenant :

            ▶ Relance Toolbar-S&D en double-cliquant sur le raccourci.
            ▶ Tape sur "2" puis valide en appuyant sur "Entrée".
            /!\ Ne ferme pas la fenêtre lors de la suppression !
            ▶ Un rapport sera généré, poste son contenu ici.

            NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
            Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
            Tape explorer puis valide.

            ensuite :

            Option 1 - Recherche :

            ▶ télécharge smitfraudfix et enregistre le sur le bureau

            (c est le numéro 2 en bas de la page) :

            ▶ Ensuite double clique sur smitfraudfix puis exécuter

            ▶ Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.

            (attention : N utilises pas l option 2 si je ne te l ai pas demandé !!)

            ▶ copier/coller le rapport dans la réponse.

            Un tutoriel sonore et animé est à ta disposition sur le site.

            (Attention : "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool".
            Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains,
            cet utilitaire pourrait arrêter des logiciels de sécurité.)
            1. Voila

              -----------\\ ToolBar S&D 1.2.0 XP/Vista

              Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
              X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.00GHz )
              BIOS : Default System BIOS
              USER : Philippe ( Administrator )
              BOOT : Normal boot
              Antivirus : AVG Anti-Virus Free 8.0 (Activated)
              A:\ (USB)
              C:\ (Local Disk) - NTFS - Total : 35 Go Free : 10 Go
              D:\ (Local Disk) - FAT32 - Total : 35 Go Free : 7 Go
              E:\ (CD or DVD)

              "C:\ToolBar SD" ( MAJ : 14-09-2008|23:30 )
              Option : [2] ( 24/09/2008|15:54 )

              -----------\\ SUPPRESSION

              Supprime! - C:\DOCUME~1\Philippe\APPLIC~1\Dealio\dinstallhelper.2CF719EF65BF4170824C917A9AFD659A.dll
              Supprime! - C:\DOCUME~1\Philippe\APPLIC~1\Dealio\kb126
              Supprime! - C:\Program Files\Dealio\DealioAU.exe
              Supprime! - C:\Program Files\Dealio\kb126
              Supprime! - C:\Program Files\Dealio\SearchSettingsKit.exe
              Supprime! - C:\WINDOWS\Prefetch\DEALIOAU.EXE-17E14027.pf
              Supprime! - C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Dealio
              Supprime! - C:\WINDOWS\Prefetch\SEARCHSETTINGS.EXE-0107F828.pf
              Supprime! - C:\DOCUME~1\Philippe\APPLIC~1\Search Settings\kb126
              Supprime! - C:\Program Files\Search Settings\kb126
              Supprime! - C:\Program Files\Search Settings\SearchSettings.exe
              Supprime! - C:\DOCUME~1\Philippe\APPLIC~1\Dealio
              Supprime! - C:\Program Files\Dealio
              Supprime! - C:\DOCUME~1\Philippe\APPLIC~1\Search Settings
              Supprime! - C:\Program Files\Search Settings

              -----------\\ Recherche de Fichiers / Dossiers ...

              -----------\\ Extensions

              (Philippe) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

              -----------\\ [..\Internet Explorer\Main]

              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
              "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
              "Start Page"="https://www.google.com/?hl=fr&gws_rd=ssl"
              "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
              "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
              "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
              "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
              "Start Page"="https://www.msn.com/fr-fr/"

              --------------------\\ Recherche d'autres infections

              Aucune autre infection trouvée !

              1 - "C:\ToolBar SD\TB_1.txt" - 24/09/2008|15:42 - Option : [1]
              2 - "C:\ToolBar SD\TB_2.txt" - 24/09/2008|15:55 - Option : [2]

              -----------\\ Fin du rapport a 15:55:56,54
              1. Contributeur sécurité
                ok maintenant fais une recherche avec smitfraudfix stp
                1. SmitFraudFix v2.354

                  Rapport fait à 16:04:32,20, 24/09/2008
                  Executé à partir de C:\Documents and Settings\Philippe\Mes documents\Downloads\SmitfraudFix
                  OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                  Le type du système de fichiers est NTFS
                  Fix executé en mode normal

                  »»»»»»»»»»»»»»»»»»»»»»»» Process

                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                  C:\Program Files\Unlocker\UnlockerAssistant.exe
                  C:\PROGRA~1\AVG\AVG8\avgtray.exe
                  C:\WINDOWS\system32\lphccbdj0e557.exe
                  C:\Program Files\POP Peeper\POPPeeper.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\WINDOWS\system32\pwbibwjq.exe
                  C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                  C:\PROGRA~1\AVG\AVG8\avgemc.exe
                  C:\WLCI\TP5G APPLICATION\TP5G.exe
                  C:\WINDOWS\system32\fxssvc.exe
                  C:\Program Files\NOLIS\Felix\Felix.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Documents and Settings\Philippe\Mes documents\Downloads\SmitfraudFix\Policies.exe
                  C:\WINDOWS\system32\cmd.exe

                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Philippe

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Philippe\Application Data

                  »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Philippe\Favoris

                  »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                  C:\Program Files\akl\ PRESENT !

                  »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                  »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                  "Source"="About:Home"
                  "SubscribedURL"="About:Home"
                  "FriendlyName"="Ma page d'accueil"

                  »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  o4Patch
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  IEDFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  VACFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  404Fix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  AntiXPVSTFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                  "AppInit_DLLs"="avgrsstx.dll"
                  "LoadAppInit_DLLs"=dword:00000001

                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                  "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                  "System"=""

                  »»»»»»»»»»»»»»»»»»»»»»»» RK

                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                  Description: Marvell Yukon 88E8001/8003/8010 PCI Gigabit Ethernet Controller - Miniport d'ordonnancement de paquets
                  DNS Server Search Order: 192.168.0.250

                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{F2D1A137-6683-4905-8428-C78F1616D8BB}: DhcpNameServer=192.168.0.250
                  HKLM\SYSTEM\CS1\Services\Tcpip\..\{F2D1A137-6683-4905-8428-C78F1616D8BB}: DhcpNameServer=192.168.0.250
                  HKLM\SYSTEM\CS3\Services\Tcpip\..\{F2D1A137-6683-4905-8428-C78F1616D8BB}: DhcpNameServer=192.168.0.250
                  HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.250
                  HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.250
                  HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.250

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Fin
                  1. Contributeur sécurité
                    ok maintenant :

                    Option 2 - Nettoyage :

                    ▶ Redémarrer l'ordinateur en mode sans échec (tapoter rapidement la touche F8 au démarrage du pc pour obtenir le menu des options avancées).

                    ▶ Double cliquer sur smitfraudfix

                    ▶ Sélectionner 2 pour supprimer les fichiers responsables de l'infection.

                    ▶ A la question Voulez-vous nettoyer le registre ? répondre O (oui) afin de débloquer le fond d'écran et supprimer les clés de démarrage automatique de l'infection.

                    Le fix déterminera si le fichier wininet.dll est infecté. A la question Corriger le fichier infecté ? répondre O (oui) pour remplacer le fichier corrompu.

                    ▶ Enregistre le rapport sur ton bureau

                    ▶ Redémarrer en mode normal et poster le rapport.

                    ensuite :

                    ▶ Télécharger malwarebytes

                    ▶ Voici un tuto pour bien l installer et bien l utiliser :

                    https://www.androidworld.fr/

                    aide toi bien du tuto pour supprimer correctement ce qu il aura trouvé

                    Après l analyse, redémarrer le pc et poste le rapport !!

                    Et refais un nouveau rapport hijackthis stp
                    1. Voila le rapport

                      SmitFraudFix v2.354

                      Rapport fait à 16:19:21,31, 24/09/2008
                      Executé à partir de C:\Documents and Settings\Philippe\Mes documents\Downloads\SmitfraudFix
                      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                      Le type du système de fichiers est NTFS
                      Fix executé en mode sans echec

                      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                      »»»»»»»»»»»»»»»»»»»»»»»» hosts

                      127.0.0.1 localhost

                      »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                      VACFix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                      S!Ri's WS2Fix: LSP not Found.

                      »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                      GenericRenosFix by S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                      C:\Program Files\akl\ supprimé

                      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                      IEDFix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                      404Fix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

                      AntiXPVSTFix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» RK

                      »»»»»»»»»»»»»»»»»»»»»»»» DNS

                      HKLM\SYSTEM\CCS\Services\Tcpip\..\{F2D1A137-6683-4905-8428-C78F1616D8BB}: DhcpNameServer=192.168.0.250
                      HKLM\SYSTEM\CS1\Services\Tcpip\..\{F2D1A137-6683-4905-8428-C78F1616D8BB}: DhcpNameServer=192.168.0.250
                      HKLM\SYSTEM\CS3\Services\Tcpip\..\{F2D1A137-6683-4905-8428-C78F1616D8BB}: DhcpNameServer=192.168.0.250
                      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.250
                      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.250
                      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.250

                      »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                      "System"=""

                      »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                      Nettoyage terminé.

                      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      »»»»»»»»»»»»»»»»»»»»»»»» Fin

                      l'ordi me dit que je n'ai plus de pare feu.....

                      Je passe à la suite avec malwarebytes ???
                      1. Contributeur sécurité
                        oui tu peux maintenant faire malwarebytes

                        Tu utilises bien le pare feu windows ??
                        1. Contributeur sécurité
                          alors vas dans le panneau de configuration => pare feu windows et réactives le tout simplement ;-)
                          1. Malwarebytes' Anti-Malware 1.28
                            Version de la base de données: 1201
                            Windows 5.1.2600 Service Pack 3

                            24/09/2008 16:40:18
                            mbam-log-2008-09-24 (16-40-18).txt

                            Type de recherche: Examen rapide
                            Eléments examinés: 38768
                            Temps écoulé: 4 minute(s), 2 second(s)

                            Processus mémoire infecté(s): 1
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 28
                            Valeur(s) du Registre infectée(s): 4
                            Elément(s) de données du Registre infecté(s): 2
                            Dossier(s) infecté(s): 3
                            Fichier(s) infecté(s): 69

                            Processus mémoire infecté(s):
                            C:\WINDOWS\system32\lphccbdj0e557.exe (Trojan.FakeAlert) -> Unloaded process successfully.

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            HKEY_CLASSES_ROOT\CLSID\{134272DE-2C37-14CA-F8F5-08E00F25118C} (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
                            HKEY_CLASSES_ROOT\CLSID\{0656a137-b161-cadd-9777-e37a75727e78} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            HKEY_CLASSES_ROOT\CLSID\{0b682cc1-fb40-4006-a5dd-99edd3c9095d} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            HKEY_CLASSES_ROOT\CLSID\{0e1230f8-ea50-42a9-983c-d22abc2eeb4c} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            HKEY_CLASSES_ROOT\CLSID\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            HKEY_CLASSES_ROOT\CLSID\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            HKEY_CLASSES_ROOT\CLSID\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            HKEY_CLASSES_ROOT\CLSID\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            HKEY_CLASSES_ROOT\CLSID\{54645654-2225-4455-44a1-9f4543d34545} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            HKEY_CLASSES_ROOT\CLSID\{5c7f15e1-f31a-44fd-aa1a-2ec63aaffd3a} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\typelib (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\HOL5_VXIEWER.FULL.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Classes\applications\accessdiver.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\fwbd (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\HolLol (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Inet Delivery (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mslagent (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Golden Palace Casino NEW (Trojan.DNSChanger) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\iTunesMusic (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\rdriv (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\wkey (Malware.Trace) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\mwc (Malware.Trace) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.

                            Valeur(s) du Registre infectée(s):
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\admsmart (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SystemCheck2 (Trojan.Agent) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphccbdj0e557 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully.

                            Elément(s) de données du Registre infecté(s):
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

                            Dossier(s) infecté(s):
                            C:\WINDOWS\mslagent (Adware.EGDAccess) -> Quarantined and deleted successfully.
                            C:\Program Files\Inet Delivery (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\smp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.

                            Fichier(s) infecté(s):
                            C:\Program Files\yyzkdmc\AdmSmart.dll (Trojan.FakeAlert.H) -> Delete on reboot.
                            C:\WINDOWS\mslagent\2_mslagent.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
                            C:\WINDOWS\mslagent\mslagent.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
                            C:\WINDOWS\mslagent\uninstall.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
                            C:\Program Files\Inet Delivery\inetdl.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            C:\Program Files\Inet Delivery\intdel.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\smp\msrc.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\phccbdj0e557.bmp (Trojan.Downloader) -> Quarantined and deleted successfully.
                            C:\WINDOWS\a.bat (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            C:\WINDOWS\base64.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            C:\WINDOWS\FVProtect.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            C:\WINDOWS\userconfig9x.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            C:\WINDOWS\winsystem.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            C:\WINDOWS\zip1.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            C:\WINDOWS\zip2.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            C:\WINDOWS\zip3.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            C:\WINDOWS\zipped.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                            C:\WINDOWS\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\iTunesMusic.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\akttzn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\anticipator.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\awtoolb.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\bsva-egihsg52.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\dpcproxy.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\emesx.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\h@tkeysh@@k.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\hoproxy.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\hxiwlgpm.dat (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\hxiwlgpm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\medup012.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\medup020.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\msgp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\msnbho.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\msvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\mtr2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\mwin32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\netode.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\newsd32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\ps1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\psof1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\psoft1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\regc64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\regm64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\Rundl1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\sncntr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\ssurf022.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\ssvchost.com (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\ssvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\sysreq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\taack.dat (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\taack.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\temp#01.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\thun.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\thun32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\VBIEWER.OCX (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\vcatchpi.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\winlogonpc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\winsystem.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\WINWGPX.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\vbsys2.dll (Trojan.Clicker) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\blphccbdj0e557.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\lphccbdj0e557.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                            C:\Documents and Settings\Philippe\Local Settings\Temp\.tt1.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
                            C:\Documents and Settings\Philippe\Local Settings\Temp\.tt3.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
                            C:\Documents and Settings\Philippe\Local Settings\Temp\.tt7.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
                            C:\Documents and Settings\Philippe\Local Settings\Temp\.tt1.tmp.vbs (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                            1. Contributeur sécurité
                              ok..il a déjà supprimé pas mal d infections mais tu as fais une analyse rapide :s

                              fais une analyse complete comme je te l avais demandé stp

                              poste le rapport et ensuite refais un nouveau rapport hijackthis pour vérifier stp
                              1. Oups !!!! pour moi c'est un peu comme du grec ancien lol

                                je fais de suite et te reposte.

                                Merci
                                1. Contributeur sécurité
                                  ok...

                                  je vais m absenter pendant 2 ptites heures, je vérifierai tes rapports dès mon retour et te dirai la suite ;-)

                                  @+
                                  1. Malwarebytes' Anti-Malware 1.28
                                    Version de la base de données: 1201
                                    Windows 5.1.2600 Service Pack 3

                                    24/09/2008 17:14:33
                                    mbam-log-2008-09-24 (17-14-33).txt

                                    Type de recherche: Examen complet (C:\|D:\|)
                                    Eléments examinés: 78525
                                    Temps écoulé: 24 minute(s), 20 second(s)

                                    Processus mémoire infecté(s): 0
                                    Module(s) mémoire infecté(s): 0
                                    Clé(s) du Registre infectée(s): 0
                                    Valeur(s) du Registre infectée(s): 0
                                    Elément(s) de données du Registre infecté(s): 0
                                    Dossier(s) infecté(s): 0
                                    Fichier(s) infecté(s): 0

                                    Processus mémoire infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Module(s) mémoire infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Clé(s) du Registre infectée(s):
                                    (Aucun élément nuisible détecté)

                                    Valeur(s) du Registre infectée(s):
                                    (Aucun élément nuisible détecté)

                                    Elément(s) de données du Registre infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Dossier(s) infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Fichier(s) infecté(s):
                                    (Aucun élément nuisible détecté)

                                    et pour hijakthis

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 17:16:05, on 24/09/2008
                                    Platform: Windows XP SP3 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\Ati2evxx.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\WINDOWS\system32\Ati2evxx.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                                    C:\Program Files\Unlocker\UnlockerAssistant.exe
                                    C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                    C:\Program Files\POP Peeper\POPPeeper.exe
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\WINDOWS\system32\pwbibwjq.exe
                                    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                                    C:\PROGRA~1\AVG\AVG8\avgemc.exe
                                    C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                                    C:\Program Files\Mozilla Firefox\firefox.exe
                                    C:\WINDOWS\system32\NOTEPAD.EXE
                                    C:\Documents and Settings\Philippe\Mes documents\Downloads\HiJackThis.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                                    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
                                    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
                                    O4 - HKCU\..\Run: [POP Peeper] "C:\Program Files\POP Peeper\POPPeeper.exe" -min
                                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - HKCU\..\Run: [acten] C:\WINDOWS\system32\pwbibwjq.exe
                                    O4 - HKLM\..\Policies\Explorer\Run: [aE85JJajLV] C:\Documents and Settings\Philippe\Mes documents\Downloads\AdobeFlashPlayerHD.exe
                                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                    O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                                    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                                    O20 - AppInit_DLLs: avgrsstx.dll
                                    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                                    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
                                    1. Contributeur sécurité
                                      ok pas de problèmes ;-)

                                      tu pourras faire ceci dès que tu sais pour vérifier car j ai un doute :

                                      ▶ Télécharge sur le bureau Navilog1 (c est le numéro 1 en bas de la page)

                                      *Si votre antivirus s'affole , le désactiver
                                      sous vista : Clic-droit sur le raccourci Navilog1 présent sur le bureau et choisis "Exécuter en tant qu'administrateur
                                      sous XP : double-clic dessus pour l'installer et le lancer

                                      ▶ Quand installé
                                      ▶ taper F
                                      ▶ Appuyer sur une touche jusqu' arriver aux options
                                      ▶ Choisir Recherche ( = taper 1 )

                                      ▶ne pas utiliser les autres sans avis , il peut y avoir des processus légitimes

                                      ▶un rapport : fixnavi.txt dans ==> C:

                                      ▶le copier et le coller dans la réponse
                                      1. Et voila le rapport au passage je confirme encore avoir eu le message de trojan.....

                                        Search Navipromo version 3.6.5 commencé le 24/09/2008 à 17:29:06,50

                                        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                                        !!! Postez ce rapport sur le forum pour le faire analyser !!!
                                        !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                                        Outil exécuté depuis C:\Program Files\navilog1
                                        Session actuelle : "Philippe"

                                        Mise à jour le 22.08.2008 à 17h30 par IL-MAFIOSO

                                        Microsoft Windows XP [version 5.1.2600]
                                        Internet Explorer : 7.0.5730.13
                                        Système de fichiers : NTFS

                                        Recherche executé en mode normal

                                        *** Recherche Programmes installés ***

                                        *** Recherche dossiers dans "C:\WINDOWS" ***

                                        *** Recherche dossiers dans "C:\Program Files" ***

                                        *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

                                        *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

                                        *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                                        *** Recherche dossiers dans "C:\Documents and Settings\Philippe\applic~1" ***

                                        *** Recherche dossiers dans "C:\Documents and Settings\Philippe\locals~1\applic~1" ***

                                        *** Recherche dossiers dans "C:\Documents and Settings\Philippe\menudm~1\progra~1" ***

                                        *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                                        pour + d'infos : http://www.gmer.net

                                        *** Recherche avec GenericNaviSearch ***
                                        !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                                        !!! A vérifier impérativement avant toute suppression manuelle !!!

                                        * Recherche dans "C:\WINDOWS\system32" *

                                        * Recherche dans "C:\Documents and Settings\Philippe\locals~1\applic~1" *

                                        *** Recherche fichiers ***

                                        *** Recherche clés spécifiques dans le Registre ***

                                        *** Module de Recherche complémentaire ***
                                        (Recherche fichiers spécifiques)

                                        1)Recherche nouveaux fichiers Instant Access :

                                        2)Recherche Heuristique :

                                        * Dans "C:\WINDOWS\system32" :

                                        * Dans "C:\Documents and Settings\Philippe\locals~1\applic~1" :

                                        3)Recherche Certificats :

                                        Certificat Egroup absent !
                                        Certificat Electronic-Group absent !
                                        Certificat Montorgueil absent !
                                        Certificat OOO-Favorit absent !
                                        Certificat Sunny-Day-Design-Ltd absent !

                                        4)Recherche fichiers connus :

                                        *** Analyse terminée le 24/09/2008 à 17:33:34,56 ***
                                        • 1
                                        • 2
                                        • 3
                                        • 4