Pubs qui s ouvre toute seul

Résolu
Bonjour,
Voila j ai un petit probléme j ai toujours des pages internets qui s ouvre se sont des pubs j aimerai bien voir sa disparaitre si quelqu un peut m aider merci
je vous poste mon rapports HijackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:15:02, on 02/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\ezNTSvc.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\HP_Administrateur\Bureau\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://fr.search.yahoo.com/?fr=cb-hp06
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
O4 - HKLM\..\Run: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus
O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [MsgCenterExe] "C:\Program Files\Fichiers communs\Real\Update_OB\RealOneMessageCenter.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [e8d826b9] rundll32.exe "C:\WINDOWS\system32\upwiwkuv.dll",b
O4 - HKLM\..\Run: [BMebeb1525] Rundll32.exe "C:\WINDOWS\system32\ovmnwkwj.dll",s
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.05\AMVConverter\grab.html
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.05\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://www.securitoo.com/ols/fscax.cab
O20 - AppInit_DLLs: zzagxy.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\WINDOWS\system32\ezNTSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 8309 bytes
Configuration: Windows XP
Internet Explorer 6.0

39 réponses

Résumé de la discussion

Une suspicion d'infection entraîne des pages publicitaires intempestives et nécessite une désinfection du système, notamment en s'appuyant sur des rapports HijackThis pour identifier les éléments indésirables. Plusieurs réponses préconisent une désinfection manuelle avec des outils comme HijackThis et SmitFraudFix, puis l'exécution de corrections ciblées sur les clés de registre et les programmes au démarrage pour neutraliser les mouchards publicitaires. Des échanges évoquent aussi des nettoyages complémentaires avec Ad-Aware, la suppression d'anciennes versions Java, et la suppression de fichiers et raccourcis indésirables repérés par des outils comme Navilog1 ou SmitFraudFix. En parallèle, des conseils portent sur la nécessité de maintenir le système à jour, d'éliminer les programmes auto-démarrés indésirables et d'effectuer des analyses régulières pour éviter une reprise.

Bobot (l’IA à votre service)
  1. bonjour voici mon rapport

    SmitFraudFix v2.356

    Rapport fait à 13:30:04,78, 02/10/2008
    Executé à partir de C:\Documents and Settings\HP_Administrateur\Bureau\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
    Le type du système de fichiers est NTFS
    Fix executé en mode normal

    »»»»»»»»»»»»»»»»»»»»»»»» Process

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\arservice.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\WINDOWS\system32\ezNTSvc.exe
    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\documents and settings\hp_administrateur\local settings\application data\aeymagq.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\HP_Administrateur\Bureau\SmitfraudFix\Policies.exe
    C:\WINDOWS\system32\cmd.exe

    »»»»»»»»»»»»»»»»»»»»»»»» hosts

    »»»»»»»»»»»»»»»»»»»»»»»» C:\

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Administrateur

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Administrateur\Application Data

    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\HP_ADM~1\Favoris

    »»»»»»»»»»»»»»»»»»»»»»»» Bureau

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="Ma page d'accueil"

    »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    o4Patch
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    IEDFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    VACFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    404Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    AntiXPVSTFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "LoadAppInit_DLLs"=dword:00000001
    "AppInit_DLLs"=""

    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "Userinit"="C:\\WINDOWS\\SYSTEM32\\Userinit.exe,"
    "Windows Shell (ezShellStart)"="C:\\WINDOWS\\system32\\userinit.exe,"
    "System"=""

    »»»»»»»»»»»»»»»»»»»»»»»» RK

    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    Description: Realtek RTL8139/810x Family Fast Ethernet NIC - Miniport d'ordonnancement de paquets
    DNS Server Search Order: 16.92.3.242
    DNS Server Search Order: 16.92.3.243
    DNS Server Search Order: 16.81.3.243
    DNS Server Search Order: 16.118.3.243

    Description: Realtek RTL8139/810x Family Fast Ethernet NIC - Miniport d'ordonnancement de paquets
    DNS Server Search Order: 212.27.40.240
    DNS Server Search Order: 212.27.40.241

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{C62C7E65-EA76-49AD-9CAC-A4A52A73B5AB}: DhcpNameServer=212.27.40.240 212.27.40.241
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{C62C7E65-EA76-49AD-9CAC-A4A52A73B5AB}: DhcpNameServer=212.27.40.240 212.27.40.241
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{C62C7E65-EA76-49AD-9CAC-A4A52A73B5AB}: DhcpNameServer=212.27.40.240 212.27.40.241
    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

    »»»»»»»»»»»»»»»»»»»»»»»» Fin
    0
    1. un petit soucis quand j allume mon pc en mode sans eches je n ai pas les logiciels nécessaire a cette application suis je obligé de le faire en mode sans échecs ? auparavant j avais eu ce soucis et je n avais pas démarer en mode sans echecs alor que faire ?
      0
      1. ui ui je démare bien en mode sans échecs sur le session administrateur et ui j ai peut étre bocoup d icone car j en ai pas bocoup d afficher par raport a ce que j ai
        0
        1. voila c est fait je redemérra en mode sans échecs
          0
          1. voila c est fait en faite j ai 2 session administrateurs et je prenais la session administrateur a la place de hp administrateur voila pk sa ne marchait pas sinon je fait ce que vous m avait dit de faire voici le rapport

            SmitFraudFix v2.356

            Rapport fait à 14:12:27,32, 02/10/2008
            Executé à partir de C:\Documents and Settings\HP_Administrateur\Bureau\SmitfraudFix
            OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
            Le type du système de fichiers est NTFS
            Fix executé en mode sans echec

            »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            127.0.0.1 localhost

            »»»»»»»»»»»»»»»»»»»»»»»» VACFix

            VACFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

            S!Ri's WS2Fix: LSP not Found.

            »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

            GenericRenosFix by S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

            »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

            IEDFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

            404Fix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

            AntiXPVSTFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» RK

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
            HKLM\SYSTEM\CCS\Services\Tcpip\..\{C62C7E65-EA76-49AD-9CAC-A4A52A73B5AB}: DhcpNameServer=212.27.40.240 212.27.40.241
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{C62C7E65-EA76-49AD-9CAC-A4A52A73B5AB}: DhcpNameServer=212.27.40.240 212.27.40.241
            HKLM\SYSTEM\CS3\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
            HKLM\SYSTEM\CS3\Services\Tcpip\..\{C62C7E65-EA76-49AD-9CAC-A4A52A73B5AB}: DhcpNameServer=212.27.40.240 212.27.40.241
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
            HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241

            »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "System"=""

            »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

            Nettoyage terminé.

            »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» Fin
            0
            1. dsl de l attente mes le logiciel fonctionne encore sa fait un peu peu plus de 40 min qu il inspecte mon pc il a trouvé 82 fichiés infectés je poste le rapport des que finit
              0
              1. ui pas de probléme le tuto est ouvert la j attend juste qu il finit
                0
                1. voila l examen est fini il a trouvé 108 fichié infecté j ai suivi le tuto il me demande de reboot le pc est ce bon ?
                  voila le rapport

                  Malwarebytes' Anti-Malware 1.28
                  Version de la base de données: 1226
                  Windows 5.1.2600 Service Pack 2

                  02/10/2008 15:21:09
                  mbam-log-2008-10-02 (15-21-09).txt

                  Type de recherche: Examen complet (C:\|D:\|)
                  Eléments examinés: 166987
                  Temps écoulé: 49 minute(s), 1 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 3
                  Clé(s) du Registre infectée(s): 20
                  Valeur(s) du Registre infectée(s): 2
                  Elément(s) de données du Registre infecté(s): 2
                  Dossier(s) infecté(s): 2
                  Fichier(s) infecté(s): 77

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  C:\WINDOWS\system32\tuvWnLeC.dll (Trojan.Vundo.H) -> Delete on reboot.
                  C:\WINDOWS\system32\efcATNHA.dll (Trojan.Vundo.H) -> Delete on reboot.
                  C:\WINDOWS\system32\zzagxy.dll (Trojan.Vundo.H) -> Delete on reboot.

                  Clé(s) du Registre infectée(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{114a72af-007e-461d-89ff-864728c749c5} (Trojan.Vundo.H) -> Delete on reboot.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\efcatnha (Trojan.Vundo.H) -> Delete on reboot.
                  HKEY_CLASSES_ROOT\CLSID\{114a72af-007e-461d-89ff-864728c749c5} (Trojan.Vundo.H) -> Delete on reboot.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{69d483aa-441c-4272-b68d-1b2ba1e8a5a0} (Trojan.Vundo.H) -> Delete on reboot.
                  HKEY_CLASSES_ROOT\CLSID\{69d483aa-441c-4272-b68d-1b2ba1e8a5a0} (Trojan.Vundo.H) -> Delete on reboot.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4443e27-3821-445b-954e-66eea67b113d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{a4443e27-3821-445b-954e-66eea67b113d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\UpMedia (Adware.SmartShopper) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\MediaHoldings (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InternetGameBox.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.

                  Valeur(s) du Registre infectée(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{114a72af-007e-461d-89ff-864728c749c5} (Trojan.Vundo.H) -> Delete on reboot.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bmebeb1525 (Trojan.Agent) -> Delete on reboot.

                  Elément(s) de données du Registre infecté(s):
                  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\tuvwnlec -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\tuvwnlec -> Delete on reboot.

                  Dossier(s) infecté(s):
                  C:\WINDOWS\system32\UpMedia (Adware.SmartShopper) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\wTR02 (Trojan.Agent) -> Quarantined and deleted successfully.

                  Fichier(s) infecté(s):
                  C:\WINDOWS\system32\efcATNHA.dll (Trojan.Vundo.H) -> Delete on reboot.
                  C:\WINDOWS\system32\tuvWnLeC.dll (Trojan.Vundo.H) -> Delete on reboot.
                  C:\WINDOWS\system32\CeLnWvut.ini (Trojan.Vundo.H) -> Delete on reboot.
                  C:\WINDOWS\system32\CeLnWvut.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\zzagxy.dll (Trojan.Vundo.H) -> Delete on reboot.
                  C:\WINDOWS\system32\brmewpsd.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\dspwemrb.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\lqqwohfm.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\mfhowqql.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\ugddgbra.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\arbgddgu.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\upwiwkuv.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\vukwiwpu.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\vtUnkjKc.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\cKjknUtv.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\aeymagq_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\aeymagq_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\aeymagq.dat (Adware.Navipromo.H) -> Delete on reboot.
                  C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\aeymagq.exe (Adware.Navipromo.H) -> Delete on reboot.
                  C:\Documents and Settings\HP_Administrateur\Local Settings\Temporary Internet Files\Content.IE5\GP674DEV\nd82m0[1] (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\HP_Administrateur\Local Settings\Temporary Internet Files\Content.IE5\I2J8KDL1\upd105320[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\HP_Administrateur\Local Settings\Temporary Internet Files\Content.IE5\SXEN456B\upd105320[1] (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\HP_Administrateur\Local Settings\Temporary Internet Files\Content.IE5\WPC5EKGS\nd82m0[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP467\A0140752.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP470\A0141904.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP471\A0144938.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP471\A0145958.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP472\A0150126.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\crhouoht.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\dktfmz.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\jtvjwp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\qkyyqubh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\qqswwcex.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\qxyjcndh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\afwpsamo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\ahyydckb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\atmcmq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\bcqiew.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\cbXponND.VIR (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\cgiberjs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\ckzboe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\dgktox.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\eclvcjoy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\ejompvef.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\glokmrrc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\juypvmdk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\kdjlcaql.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\kjmrsn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\lgqrmbpk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\ljJddEVL.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\mesahw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\mtmbtg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\nglubqjf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\nmmicfte.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\pbsxybas.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\pusdlrbm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\rgtame.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\royyyo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\rqemkmrv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\sjewls.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\skklwl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\uehwbddo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\vtUnmNFx.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\sglxlqjo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\wvUnNdAS.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\yaqpmq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\ymbwuf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\xjbzzj.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\xretny.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\Program Files\WinRAR\Default.SFX (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
                  C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\ovmnwkwj.dll (Trojan.Agent) -> Delete on reboot.
                  C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully.
                  C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\BMebeb1525.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\BMebeb1525.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
                  0
                  1. voici le rapport

                    Search Navipromo version 3.6.6 commencé le 02/10/2008 à 15:32:23,92

                    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                    !!! Postez ce rapport sur le forum pour le faire analyser !!!
                    !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                    Outil exécuté depuis C:\Program Files\navilog1
                    Session actuelle : "HP_Administrateur"

                    Mise à jour le 29.09.2008 à 17h30 par IL-MAFIOSO

                    Microsoft Windows XP [version 5.1.2600]
                    Internet Explorer : 6.0.2900.2180
                    Système de fichiers : NTFS

                    Recherche executé en mode normal

                    *** Recherche Programmes installés ***

                    InternetGameBox

                    *** Recherche dossiers dans "C:\WINDOWS" ***

                    *** Recherche dossiers dans "C:\Program Files" ***

                    *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

                    *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

                    *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                    *** Recherche dossiers dans "C:\Documents and Settings\HP_Administrateur\applic~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

                    *** Recherche dossiers dans "C:\Documents and Settings\HP_Administrateur\locals~1\applic~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

                    *** Recherche dossiers dans "C:\Documents and Settings\HP_Administrateur\menudm~1\progra~1" ***

                    ...\InternetGameBox trouvé !

                    *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                    pour + d'infos : http://www.gmer.net

                    *** Recherche avec GenericNaviSearch ***
                    !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                    !!! A vérifier impérativement avant toute suppression manuelle !!!

                    * Recherche dans "C:\WINDOWS\system32" *

                    * Recherche dans "C:\Documents and Settings\HP_Administrateur\locals~1\applic~1" *

                    * Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

                    *** Recherche fichiers ***

                    *** Recherche clés spécifiques dans le Registre ***

                    HKEY_CURRENT_USER\Software\Lanconfig trouvé !

                    *** Module de Recherche complémentaire ***
                    (Recherche fichiers spécifiques)

                    1)Recherche nouveaux fichiers Instant Access :

                    2)Recherche Heuristique :

                    * Dans "C:\WINDOWS\system32" :

                    * Dans "C:\Documents and Settings\HP_Administrateur\locals~1\applic~1" :

                    * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :

                    3)Recherche Certificats :

                    Certificat Egroup trouvé !
                    Certificat Electronic-Group trouvé !
                    Certificat Montorgueil absent !
                    Certificat OOO-Favorit trouvé !
                    Certificat Sunny-Day-Design-Ltd absent !

                    4)Recherche fichiers connus :

                    C:\WINDOWS\system32\DNnopXbc.ini2 trouvé ! infection Vundo possible non traitée par cet outil !

                    *** Analyse terminée le 02/10/2008 à 15:42:04,64 ***
                    0
                    1. voici le rapport navilog je fait un scan hitajiks la

                      Clean Navipromo version 3.6.6 commencé le 02/10/2008 à 15:48:21,31

                      Outil exécuté depuis C:\Program Files\navilog1
                      Session actuelle : "HP_Administrateur"

                      Mise à jour le 29.09.2008 à 17h30 par IL-MAFIOSO

                      Microsoft Windows XP [version 5.1.2600]
                      Internet Explorer : 6.0.2900.2180
                      Système de fichiers : NTFS

                      Mode suppression automatique
                      avec prise en charge résultats Catchme et GNS

                      Nettoyage exécuté au redémarrage de l'ordinateur

                      *** fsbl1.txt non trouvé ***
                      (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                      *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                      * Suppression dans "C:\WINDOWS\System32" *

                      * Suppression dans "C:\Documents and Settings\HP_Administrateur\locals~1\applic~1" *

                      * Suppression dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

                      *** Suppression dossiers dans "C:\WINDOWS" ***

                      *** Suppression dossiers dans "C:\Program Files" ***

                      *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

                      *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

                      *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                      *** Suppression dossiers dans "C:\Documents and Settings\HP_Administrateur\applic~1" ***

                      *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

                      *** Suppression dossiers dans "C:\Documents and Settings\HP_Administrateur\locals~1\applic~1" ***

                      *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

                      *** Suppression dossiers dans "C:\Documents and Settings\HP_Administrateur\menudm~1\progra~1" ***

                      ...\InternetGamebox ...suppression...
                      ...\InternetGamebox supprimé !

                      *** Suppression fichiers ***

                      *** Suppression fichiers temporaires ***

                      Nettoyage contenu C:\WINDOWS\Temp effectué !
                      Nettoyage contenu C:\Documents and Settings\HP_Administrateur\locals~1\Temp effectué !

                      *** Traitement Recherche complémentaire ***
                      (Recherche fichiers spécifiques)

                      1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                      2)Recherche, création sauvegardes et suppression Heuristique :

                      * Dans "C:\WINDOWS\system32" *

                      * Dans "C:\Documents and Settings\HP_Administrateur\locals~1\applic~1" *

                      * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

                      *** Sauvegarde du Registre vers dossier Safebackup ***

                      sauvegarde du Registre réalisée avec succès !

                      *** Nettoyage Registre ***

                      Nettoyage Registre Ok

                      *** Certificats ***

                      Certificat Egroup supprimé !
                      Certificat Electronic-Group supprimé !
                      Certificat Montorgueil absent !
                      Certificat OOO-Favorit supprimé !
                      Certificat Sunny-Day-Design-Ltdt absent !

                      *** Nettoyage terminé le 02/10/2008 à 15:52:15,26 ***
                      0
                      1. voila l autre rapport

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 15:53:52, on 02/10/2008
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        C:\WINDOWS\arservice.exe
                        C:\WINDOWS\eHome\ehRecvr.exe
                        C:\WINDOWS\eHome\ehSched.exe
                        C:\WINDOWS\system32\ezNTSvc.exe
                        C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                        C:\WINDOWS\system32\nvsvc32.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\dllhost.exe
                        C:\WINDOWS\system32\wscntfy.exe
                        C:\WINDOWS\NOTEPAD.EXE
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                        C:\Program Files\Internet Explorer\IEXPLORE.EXE
                        C:\Documents and Settings\HP_Administrateur\Bureau\HiJackThis.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
                        O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
                        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O2 - BHO: (no name) - {68B627A7-20FF-46BB-AD7E-171F62B60595} - C:\WINDOWS\system32\cbXponND.dll (file missing)
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                        O4 - HKCU\..\Run: [aeymagq] "c:\documents and settings\hp_administrateur\local settings\application data\aeymagq.exe" aeymagq
                        O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                        O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
                        O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                        O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                        O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                        O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
                        O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                        O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\WINDOWS\system32\ezNTSvc.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                        0
                        1. Contributeur sécurité
                          - relance navilog

                          - choisi cette fois ci l option 4 "désinfection manuelle"

                          - tape ceci : aeymagq

                          - lance la désinfection et poste le rapport qui sera généré à la fin stp

                          ensuite refais un nouveau rapport hijackthis stp
                          0
                          1. voila le rapport navilog

                            Clean Navipromo version 3.6.6 commencé le 02/10/2008 à 16:00:20,31

                            Outil exécuté depuis C:\Program Files\navilog1
                            Session actuelle : "HP_Administrateur"

                            Mise à jour le 29.09.2008 à 17h30 par IL-MAFIOSO

                            Microsoft Windows XP [version 5.1.2600]
                            Internet Explorer : 6.0.2900.2180
                            Système de fichiers : NTFS

                            Mode suppression par méthode manuelle

                            Nom du fichier saisi : aeymagq

                            Nettoyage exécuté au redémarrage de l'ordinateur

                            *** Recherche, création sauvegardes et suppression ***

                            * Suppression dans "C:\WINDOWS\system32" *

                            C:\WINDOWS\prefetch\aeymagq*.pf trouvé !
                            Copie C:\WINDOWS\prefetch\aeymagq*.pf réalisée avec succès !
                            C:\WINDOWS\prefetch\aeymagq*.pf supprimé !

                            * Suppression dans "C:\Documents and Settings\HP_Administrateur\locals~1\applic~1" *

                            * Suppression dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

                            *** Suppression dossiers dans "C:\WINDOWS" ***

                            *** Suppression dossiers dans "C:\Program Files" ***

                            *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

                            *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

                            *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                            *** Suppression dossiers dans "C:\Documents and Settings\HP_Administrateur\applic~1" ***

                            *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

                            *** Suppression dossiers dans "C:\Documents and Settings\HP_Administrateur\locals~1\applic~1" ***

                            *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

                            *** Suppression dossiers dans "C:\Documents and Settings\HP_Administrateur\menudm~1\progra~1" ***

                            *** Suppression fichiers ***

                            *** Suppression fichiers temporaires ***

                            Nettoyage contenu C:\WINDOWS\Temp effectué !
                            Nettoyage contenu C:\Documents and Settings\HP_Administrateur\locals~1\Temp effectué !

                            *** Traitement Recherche complémentaire ***
                            (Recherche fichiers spécifiques)

                            1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                            2)Recherche, création sauvegardes et suppression Heuristique :

                            * Dans "C:\WINDOWS\system32" *

                            * Dans "C:\Documents and Settings\HP_Administrateur\locals~1\applic~1" *

                            * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

                            *** Sauvegarde du Registre vers dossier Safebackup ***

                            sauvegarde du Registre réalisée avec succès !

                            *** Nettoyage Registre ***

                            Nettoyage Registre Ok

                            *** Certificats ***

                            Certificat Egroup absent !
                            Certificat Electronic-Group absent !
                            Certificat Montorgueil absent !
                            Certificat OOO-Favorit absent !
                            Certificat Sunny-Day-Design-Ltdt absent !

                            *** Nettoyage terminé le 02/10/2008 à 16:03:45,57 ***
                            0
                            1. voici le rapport hijackthis

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 16:05:17, on 02/10/2008
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                              C:\WINDOWS\arservice.exe
                              C:\WINDOWS\eHome\ehRecvr.exe
                              C:\WINDOWS\eHome\ehSched.exe
                              C:\WINDOWS\system32\ezNTSvc.exe
                              C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                              C:\WINDOWS\system32\nvsvc32.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\dllhost.exe
                              C:\WINDOWS\system32\wscntfy.exe
                              C:\WINDOWS\NOTEPAD.EXE
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                              C:\Program Files\Internet Explorer\IEXPLORE.EXE
                              C:\Documents and Settings\HP_Administrateur\Bureau\HiJackThis.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
                              O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
                              O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O2 - BHO: (no name) - {68B627A7-20FF-46BB-AD7E-171F62B60595} - (no file)
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                              O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                              O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
                              O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                              O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                              O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                              O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
                              O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                              O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                              O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\WINDOWS\system32\ezNTSvc.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                              0
                              1. voici le rapport hijackthis

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 16:05:17, on 02/10/2008
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                Boot mode: Normal

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                C:\WINDOWS\arservice.exe
                                C:\WINDOWS\eHome\ehRecvr.exe
                                C:\WINDOWS\eHome\ehSched.exe
                                C:\WINDOWS\system32\ezNTSvc.exe
                                C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                C:\WINDOWS\system32\nvsvc32.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\dllhost.exe
                                C:\WINDOWS\system32\wscntfy.exe
                                C:\WINDOWS\NOTEPAD.EXE
                                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                C:\Documents and Settings\HP_Administrateur\Bureau\HiJackThis.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
                                O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
                                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O2 - BHO: (no name) - {68B627A7-20FF-46BB-AD7E-171F62B60595} - (no file)
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
                                O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                                O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                                O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                                O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
                                O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\WINDOWS\system32\ezNTSvc.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                0
                                1. Contributeur sécurité
                                  ca a l air bon je ne vois plus d infection ;-)

                                  relance hijackthis en cliquant sur scan only et coches ces lignes stp :

                                  O2 - BHO: (no name) - {68B627A7-20FF-46BB-AD7E-171F62B60595} - (no file)
                                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

                                  puis tu cliques sur fix checked.

                                  ensuite :

                                  ▶ Télécharge JavaRa.zip

                                  ▶ Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)

                                  ▶ Double-clique sur le répertoire JavaRa obtenu.

                                  ▶ Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)

                                  ▶ Clique sur Search For Updates.

                                  ▶ Sélectionne Update Using jucheck.exe puis clique sur Search.

                                  ▶ Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.

                                  ▶ Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.

                                  ▶ Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.

                                  ▶ Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.

                                  * Note : le rapport se trouve aussi là : ( C:\JavaRa.log )

                                  ▶ Ferme l'application et dis moi si tu as encore des problèmes.

                                  et est ce que tu as le logiciel Ad-aware ??
                                  0
                                  1. non je n ai pas le logiciel ad aware et quand je clique sur search rien ne se fait que dois je faire
                                    0
                                    1. Contributeur sécurité
                                      tu dois attendre...ca recherche

                                      Tu peux télécharger Ad-aware sur mon site web à cette adresse :

                                      https://www.androidworld.fr/

                                      et faire une mise à jour et analyse une fois par semaine (comme spybot)
                                      0
                                      1. voila j ai télécharger et mise a jour ad aware par contre javara1.11 ne fait tjoujour rien il reste sur la méme page sauf que j ai du DL une mise a jour java je c est pas si sa a un rapport sinon mon pc est il ok ?
                                        0
                                        • 1
                                        • 2