J'ai un virus dans mon ordinateur

Bonjour à tous,

J'ai un virus dans mon ordinateur que je n'arrive pas à supprimer. Il s'agit de TrojanDownloader:Win32/Zlob.gen!CD
Comment faire pour le supprimer ??
Merci d'avance pour votre aide, je ne sais plus quoi faire !!!
Configuration: Windows Vista
Internet Explorer 7.0

11 réponses

  1. Contributeur sécurité
    Bonjour,

    ouvre le Bloc-Notes (Démarrer, Tous les programmes, Accessoires)

    Fichier, Ouvrir.

    Cherche C:\Windows/System32\drivers\etc\Hosts

    Ajoute à la fin du fichier ces 3 lignes

    127.0.0.1 64.247.39.247
    127.0.0.1 74.50.107.165
    127.0.0.1 74.50.107.159

    Fichier, Enregistrer.

    Ferme le Bloc-Notes
    ==========

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Lis le contenu de l'écran Disclaimer puis clique sur Continue (si tu acceptes les conditions).

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt
    1
    1. Contributeur sécurité
      Bonsoir,

      ton "virus" n'est pas parti.

      Toutes ces lignes sont des signes de tes infections :

      O2 - BHO: (no name) - {998DAE3E-7D4F-4952-A71F-467D8FE64407} - C:\Windows\system32\pmnkKcbB.dll
      O4 - HKLM\..\Run: [SMrhc71qj0ej5a] C:\Program Files\rhc71qj0ej5a\rhc71qj0ej5a.exe
      O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\pmnkKcbB.dll,#1
      O4 - HKLM\..\Run: [\YUR794A.exe] C:\Windows\system32\YUR794A.exe
      O4 - HKLM\..\Run: [\YUR7AC0.exe] C:\Windows\system32\YUR7AC0.exe
      O4 - HKLM\..\Run: [\YUR7E87.exe] C:\Windows\system32\YUR7E87.exe
      O4 - HKLM\..\Run: [\YUR83E4.exe] C:\Windows\system32\YUR83E4.exe
      O4 - HKLM\..\Run: [\YUR82FB.exe] C:\Windows\system32\YUR82FB.exe
      O4 - HKLM\..\Run: [\YUR856B.exe] C:\Windows\system32\YUR856B.exe
      O4 - HKLM\..\Run: [\YUR8C3E.exe] C:\Windows\system32\YUR8C3E.exe
      O4 - HKLM\..\Run: [\YUR9469.exe] C:\Windows\system32\YUR9469.exe
      O4 - HKLM\..\Run: [\YUR1BA2.exe] C:\Windows\system32\YUR1BA2.exe
      O4 - HKLM\..\Run: [\YUR7863.exe] C:\Windows\system32\YUR7863.exe
      O4 - HKLM\..\Run: [\YUR7CF5.exe] C:\Windows\system32\YUR7CF5.exe
      O4 - HKLM\..\Run: [\YUR854E.exe] C:\Windows\system32\YUR854E.exe
      O4 - HKLM\..\Run: [\YURB7B4.exe] C:\Windows\system32\YURB7B4.exe
      O4 - HKLM\..\Run: [\YUR657F.exe] C:\Windows\system32\YUR657F.exe
      O4 - HKCU\..\Run: [\YUR3A12.exe] C:\Windows\system32\YUR3A12.exe
      O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\AMLIE~1\AppData\Local\Temp\xxywTKAP.dll,#1
      O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\AMLIE~1\AppData\Local\Temp\urqNFuRi.dll,c

      Pour soigner, commence par ça :

      Ouvre ce lien (merci a S!RI pour ce programme). http://siri.urz.free.fr/Fix/SmitfraudFix.php
      et télécharge SmitfraudFix.exe.

      Regarde le tuto
      Exécute le en choisissant l’option 1, il va générer un rapport
      Copie/colle le sur le poste stp.

      ======================

      téquiqui

      celui qui se prétend médecin parce qu'il a guéri sa grippe s'appelle un charlatan.

      1
      1. si tu peux faire un hijackthis fais le et poste le ici.
        http://hijackthis.de/#anl
        il te dira quoi suprimer.

        sinon essaye combofix.
        0
        1. Voici mon rapport HijackThis :

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 11:35:09, on 12/10/2008
          Platform: Windows Vista SP1 (WinNT 6.00.1905)
          MSIE: Internet Explorer v7.00 (7.00.6001.18000)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Windows\system32\taskeng.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\Synaptics\SynTP\SynTPStart.exe
          C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
          C:\Acer\Empowering Technology\eAudio\eAudio.exe
          C:\Program Files\Common Files\Symantec Shared\ccApp.exe
          C:\Windows\RtHDVCpl.exe
          C:\Users\AMLIE~1\AppData\Local\Temp\RtkBtMnt.exe
          C:\Program Files\Launch Manager\QtZgAcer.EXE
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
          C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
          C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
          C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
          C:\Windows\System32\rundll32.exe
          C:\Windows\System32\YUR794A.exe
          C:\Windows\System32\YUR83E4.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
          C:\Windows\System32\YUR8C3E.exe
          C:\Windows\System32\YUR1BA2.exe
          C:\Windows\System32\YUR7CF5.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\DAEMON Tools Lite\daemon.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Windows\System32\rundll32.exe
          C:\Users\Amélie\AppData\Roaming\Adobe\Player.exe
          C:\Windows\System32\rundll32.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Program Files\Acer\Acer VCM\AcerVCM.exe
          C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
          C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
          C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
          C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
          C:\Windows\system32\WerCon.exe
          C:\Program Files\Acer\Acer VCM\acp2HID.exe
          C:\Users\AMLIE~1\AppData\Local\Temp\sft_ver1.1454.0.exe
          C:\Windows\system32\conime.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
          C:\Windows\system32\cmd.exe
          C:\Windows\system32\rundll32.exe
          C:\Windows\system32\SearchFilterHost.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ycomp/defaults/sp/*https://fr.yahoo.com/
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
          O1 - Hosts: ::1 localhost
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: (no name) - {998DAE3E-7D4F-4952-A71F-467D8FE64407} - C:\Windows\system32\pmnkKcbB.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
          O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
          O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [ALaunch] C:\Acer\ALaunch\AlaunchClient.exe
          O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
          O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
          O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
          O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
          O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
          O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\Windows\PLFSet.dll,PLFDefSetting
          O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
          O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
          O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
          O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [SMrhc71qj0ej5a] C:\Program Files\rhc71qj0ej5a\rhc71qj0ej5a.exe
          O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
          O4 - HKLM\..\Run: [Skytel] Skytel.exe
          O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\pmnkKcbB.dll,#1
          O4 - HKLM\..\Run: [\YUR794A.exe] C:\Windows\system32\YUR794A.exe
          O4 - HKLM\..\Run: [\YUR7AC0.exe] C:\Windows\system32\YUR7AC0.exe
          O4 - HKLM\..\Run: [\YUR7E87.exe] C:\Windows\system32\YUR7E87.exe
          O4 - HKLM\..\Run: [\YUR83E4.exe] C:\Windows\system32\YUR83E4.exe
          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
          O4 - HKLM\..\Run: [\YUR82FB.exe] C:\Windows\system32\YUR82FB.exe
          O4 - HKLM\..\Run: [\YUR856B.exe] C:\Windows\system32\YUR856B.exe
          O4 - HKLM\..\Run: [\YUR8C3E.exe] C:\Windows\system32\YUR8C3E.exe
          O4 - HKLM\..\Run: [\YUR9469.exe] C:\Windows\system32\YUR9469.exe
          O4 - HKLM\..\Run: [\YUR1BA2.exe] C:\Windows\system32\YUR1BA2.exe
          O4 - HKLM\..\Run: [\YUR7863.exe] C:\Windows\system32\YUR7863.exe
          O4 - HKLM\..\Run: [\YUR7CF5.exe] C:\Windows\system32\YUR7CF5.exe
          O4 - HKLM\..\Run: [\YUR854E.exe] C:\Windows\system32\YUR854E.exe
          O4 - HKLM\..\Run: [\YURB7B4.exe] C:\Windows\system32\YURB7B4.exe
          O4 - HKLM\..\Run: [\YUR657F.exe] C:\Windows\system32\YUR657F.exe
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
          O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\AMLIE~1\AppData\Local\Temp\fccyvWOI.dll,#1
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKCU\..\Run: [] C:\Users\Amélie\AppData\Roaming\Adobe\Player.exe
          O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\AMLIE~1\AppData\Local\Temp\urqNFuRi.dll,c
          O4 - HKCU\..\Run: [\YUR3A12.exe] C:\Windows\system32\YUR3A12.exe
          O4 - HKCU\..\Run: [\YUR39F3.exe] C:\Windows\system32\YUR39F3.exe
          O4 - HKCU\..\Run: [\YUR3AED.exe] C:\Windows\system32\YUR3AED.exe
          O4 - HKCU\..\Run: [\YUR3C54.exe] C:\Windows\system32\YUR3C54.exe
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Global Startup: Acer VCM.lnk = ?
          O4 - Global Startup: Empowering Technology Launcher.lnk = ?
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O13 - Gopher Prefix:
          O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
          O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
          O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
          O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
          O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
          O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
          O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
          O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
          O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
          O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
          O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          O23 - Service: Raw Socket Service (RS_Service) - Acer Inc. - C:\Program Files\Acer\Acer VCM\RS_Service.exe
          O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
          O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
          O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
          0
          1. Contributeur sécurité
            bonjour,

            Ouvre Spybot search and destroy.

            clique sur mode, choisis advanced mode;

            dans la colonne de gauche clique sur le + devant tools.

            clique sur résident (colonne de gauche)

            dans la fenêtre de droite décoche la case devant "resident tea-timer"

            ==============

            Puis fais ce qui est dit au post 2.

            =================

            puis

            Ouvre ce lien (merci a S!RI pour ce programme). http://siri.urz.free.fr/Fix/SmitfraudFix.php
            et télécharge SmitfraudFix.exe.

            Regarde le tuto
            Exécute le en choisissant l’option 1, il va générer un rapport
            Copie/colle le sur le poste stp.
            0
            1. Bonjour,
              J'essaie de poster des msg depuis 2 jours mais impossible... j'espère qu'aujourd'hui ça va marcher...
              Après plusieurs nettoyages avec plusieurs logiciels, mon virus semble être parti, mais j'aimerais en être sûre...
              Je poste ici mon rapport HijackThis, si qqn pouvait me dire si c'est bon ou pas ce serait sympa...
              En tous cas un grand merci à tous ceux qui m'ont aidés sur ce forum, merci à vous de prendre de votre temps pour aider des personnes comme moi qui ne s'y connaissent pas... sans votre aide je n'aurais jamais sû comment me débarrasser de ce fichu virus ... Merci bcp !!!!!

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 14:33:10, on 12/10/2008
              Platform: Windows Vista SP1 (WinNT 6.00.1905)
              MSIE: Internet Explorer v7.00 (7.00.6001.18000)
              Boot mode: Safe mode

              Running processes:
              C:\Windows\Explorer.EXE
              E:\RSIT.exe
              C:\Program Files\Trend Micro\HijackThis\Amélie.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ycomp/defaults/sp/*https://fr.yahoo.com/
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
              O1 - Hosts: ::1 localhost
              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: (no name) - {998DAE3E-7D4F-4952-A71F-467D8FE64407} - C:\Windows\system32\pmnkKcbB.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
              O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
              O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              O4 - HKLM\..\Run: [ALaunch] C:\Acer\ALaunch\AlaunchClient.exe
              O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
              O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
              O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
              O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
              O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
              O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
              O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
              O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\Windows\PLFSet.dll,PLFDefSetting
              O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
              O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
              O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
              O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [SMrhc71qj0ej5a] C:\Program Files\rhc71qj0ej5a\rhc71qj0ej5a.exe
              O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
              O4 - HKLM\..\Run: [Skytel] Skytel.exe
              O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\pmnkKcbB.dll,#1
              O4 - HKLM\..\Run: [\YUR794A.exe] C:\Windows\system32\YUR794A.exe
              O4 - HKLM\..\Run: [\YUR7AC0.exe] C:\Windows\system32\YUR7AC0.exe
              O4 - HKLM\..\Run: [\YUR7E87.exe] C:\Windows\system32\YUR7E87.exe
              O4 - HKLM\..\Run: [\YUR83E4.exe] C:\Windows\system32\YUR83E4.exe
              O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
              O4 - HKLM\..\Run: [\YUR82FB.exe] C:\Windows\system32\YUR82FB.exe
              O4 - HKLM\..\Run: [\YUR856B.exe] C:\Windows\system32\YUR856B.exe
              O4 - HKLM\..\Run: [\YUR8C3E.exe] C:\Windows\system32\YUR8C3E.exe
              O4 - HKLM\..\Run: [\YUR9469.exe] C:\Windows\system32\YUR9469.exe
              O4 - HKLM\..\Run: [\YUR1BA2.exe] C:\Windows\system32\YUR1BA2.exe
              O4 - HKLM\..\Run: [\YUR7863.exe] C:\Windows\system32\YUR7863.exe
              O4 - HKLM\..\Run: [\YUR7CF5.exe] C:\Windows\system32\YUR7CF5.exe
              O4 - HKLM\..\Run: [\YUR854E.exe] C:\Windows\system32\YUR854E.exe
              O4 - HKLM\..\Run: [\YURB7B4.exe] C:\Windows\system32\YURB7B4.exe
              O4 - HKLM\..\Run: [\YUR657F.exe] C:\Windows\system32\YUR657F.exe
              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
              O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKCU\..\Run: [] C:\Users\Amélie\AppData\Roaming\Adobe\Player.exe
              O4 - HKCU\..\Run: [\YUR3A12.exe] C:\Windows\system32\YUR3A12.exe
              O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\AMLIE~1\AppData\Local\Temp\xxywTKAP.dll,#1
              O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\AMLIE~1\AppData\Local\Temp\urqNFuRi.dll,c
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
              O4 - Global Startup: Acer VCM.lnk = ?
              O4 - Global Startup: Empowering Technology Launcher.lnk = ?
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
              O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
              O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O13 - Gopher Prefix:
              O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
              O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
              O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
              O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
              O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
              O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
              O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
              O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
              O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
              O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
              O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
              O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
              O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
              O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
              O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
              O23 - Service: Raw Socket Service (RS_Service) - Acer Inc. - C:\Program Files\Acer\Acer VCM\RS_Service.exe
              O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
              O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
              O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
              O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
              0
              1. http://hijackthis.de/#anl
                poste le là et click sur evaluer.
                il semble qu'il y est des chose a supprimer.
                un certain nasty???
                poste et regarde par toi même ceux que tu dois supprimer sur hijackthis.
                0
                1. Contributeur sécurité
                  Salut,

                  téquiqui

                  tu n'y connais rien.

                  Tu ne sais pas que ce robot génére des erreurs (dans les 2 sens, il marque comme dangereux des choses qui ne le sont pas et ne signale pas des choses dangereuses).

                  De plus, fixer les lignes ne suffit pp à résoudre un grand nombrre dd'infections et le rapport Hijackthis lui même ne permet plus de voir de nombreuses infections.

                  Ta bonne volonté et ton envie d'aider ne suffisent pas, il faut que tu apprennes avant de pouvoir intervenir.
                  0
              2. Tu ne sais pas que ce robot génére des erreurs (dans les 2 sens, il marque comme dangereux des choses qui ne le sont pas et ne signale pas des choses dangereuses).

                merci pour l'imformation que tu viens de me donner mais je suis au courant.je n'ai pas dis que j'étais une pro. je m'excuse de t'irriter.mais je t'interdit de dire que je ni connais rien. j'ai eu parfois des virus et la derniere fois il était balaise et j'ai reussi à chaque fois à m'en sortir.même si là j'ai mis 2 jours. ,car plus rien ne fontionner.
                Et du coup je fais le chasseur de virus sur beaucoup d'ordis. Et jusqu'à present j'ai reussi à les debarrasser du virus qu'ils avaient chopé. mon telephone sonne une fois par semaine.
                Comment je fais? j'en sais rien mais ca aussi à ma maniere.

                Il faut que chacun de nous par sa volonté se fasse meilleur et plus fort qu'il n'est par nature.
                -1
                1. Bonjour,

                  C'est vrai que je n'y comprenais pas grand chose sur le site de HijackThis et que ça n'a pas l'air très fiable... merci quand même d'avoir voulu m'aider Téquiqui.

                  Lyonnais92, voici mon rapport smitfraudfix. Merci pour ton aide précieuse.

                  SmitFraudFix v2.361

                  Scan done at 12:32:59,72, 15/10/2008
                  Run from C:\Users\Amélie\SmitfraudFix
                  OS: Microsoft Windows [version 6.0.6001] - Windows_NT
                  The filesystem type is NTFS
                  Fix run in normal mode

                  »»»»»»»»»»»»»»»»»»»»»»»» Process

                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\wininit.exe
                  C:\Windows\system32\services.exe
                  C:\Windows\system32\lsass.exe
                  C:\Windows\system32\lsm.exe
                  C:\Windows\system32\winlogon.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\SLsvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\System32\spoolsv.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                  C:\Windows\system32\svchost.exe
                  C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
                  C:\Acer\Empowering Technology\eAudio\eAudio.exe
                  C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                  C:\Windows\RtHDVCpl.exe
                  C:\Acer\ALaunch\ALaunchSvc.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                  C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                  C:\Acer\Empowering Technology\eNet\eNet Service.exe
                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                  C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  C:\Acer\Mobility Center\MobilityService.exe
                  C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  C:\Users\AMLIE~1\AppData\Local\Temp\RtkBtMnt.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                  C:\Program Files\Acer\Acer VCM\RS_Service.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\SearchIndexer.exe
                  C:\Windows\system32\DRIVERS\xaudio.exe
                  C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                  C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                  C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Windows\system32\wbem\unsecapp.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Program Files\Launch Manager\QtZgAcer.EXE
                  C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                  C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\DAEMON Tools Lite\daemon.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Program Files\Acer\Acer VCM\AcerVCM.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
                  C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
                  C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                  C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                  C:\Program Files\Windows Media Player\wmpnetwk.exe
                  C:\Program Files\Acer\Acer VCM\acp2HID.exe
                  C:\Program Files\Internet Explorer\ieuser.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Windows\system32\conime.exe
                  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                  C:\Program Files\Windows Live\Messenger\usnsvc.exe
                  C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
                  C:\Windows\system32\WUDFHost.exe
                  C:\Users\Amélie\SmitfraudFix\Policies.exe
                  C:\Windows\system32\SearchProtocolHost.exe
                  C:\Windows\system32\cmd.exe
                  C:\Windows\system32\SearchFilterHost.exe

                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Amélie

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Amélie\Application Data

                  »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\AMLIE~1\FAVORI~1

                  »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                  »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                  »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                  »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                  !!!Attention, following keys are not inevitably infected!!!

                  o4Patch
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                  !!!Attention, following keys are not inevitably infected!!!

                  IEDFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                  !!!Attention, following keys are not inevitably infected!!!

                  VACFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                  !!!Attention, following keys are not inevitably infected!!!

                  404Fix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
                  !!!Attention, following keys are not inevitably infected!!!

                  »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                  !!!Attention, following keys are not inevitably infected!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                  !!!Attention, following keys are not inevitably infected!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                  "AppInit_DLLs"=""
                  "LoadAppInit_DLLs"=dword:00000000

                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                  !!!Attention, following keys are not inevitably infected!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                  "Userinit"="C:\\Windows\\system32\\userinit.exe,"

                  »»»»»»»»»»»»»»»»»»»»»»»» RK

                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                  Description: Intel(R) PRO/Wireless 3945ABG Network Connection
                  DNS Server Search Order: 86.64.145.147
                  DNS Server Search Order: 84.103.237.147

                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{2C04170D-2E9D-44F6-B608-EB1BD89306D9}: DhcpNameServer=86.64.145.147 84.103.237.147
                  HKLM\SYSTEM\CS1\Services\Tcpip\..\{2C04170D-2E9D-44F6-B608-EB1BD89306D9}: DhcpNameServer=86.64.145.147 84.103.237.147
                  HKLM\SYSTEM\CS2\Services\Tcpip\..\{2C04170D-2E9D-44F6-B608-EB1BD89306D9}: DhcpNameServer=84.103.237.144 86.64.145.144
                  HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=86.64.145.147 84.103.237.147
                  HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=86.64.145.147 84.103.237.147
                  HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=84.103.237.144 86.64.145.144

                  »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                  »»»»»»»»»»»»»»»»»»»»»»»» End
                  0
                  1. Contributeur sécurité
                    Re,

                    Démarre en mode sans échec :
                    Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
                    Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                    Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                    (Si F8 ne marche pas utilise la touche F5).
                    ----------------------------------------------------------------------------
                    Relance le programme Smitfraud,
                    Cette fois choisit l’option 2, répond oui a tous ;
                    Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

                    Remets un nouveau rapport Hijackthis.
                    0