HELP!!!trojan alerté par critical system w...

Résolu
Bonjour,j'ai téléchargé mozilla et "je tourne avec" depuis hier après midi. il arrive souvent qu'a l'ouverture d'une page je sois signalé d'absence de plu gin. ce matin j'ai eu la surprise, après avoir voulu en télécharger un, de voir que des antivirus ce soit télécharger et mis en route sans que je ne demande quoi que ce soit. ceux là me dise que j'ai plusieurs infections par des trojan et spyware. de peur que ce soit ces antivirus qui m'ont infecté j'ai essayé de les supprimé du programme, peut être en vain. maintenant j'ai plusieurs alerte critical système warning" qui pourrait bien confirmer ces infections. aidez moi SVP . j'ai des fenêtre qui s'ouvre de tout les côtés!!!!!!!!!!
Configuration: Windows XP
Firefox 3.0.3

46 réponses

Résumé de la discussion

Des alertes antivirus et des messages indiquant des infections par trojan et spyware apparaissent à l'ouverture des pages, accompagnés de fenêtres qui s'ouvrent et d'un comportement ralenti après l'installation de Mozilla et de plugins. Plusieurs conseils préconisent Malwarebytes Anti-Malware et un scan complet en mode sans échec, puis l'enregistrement des rapports et l'élimination des outils obsolètes, afin d'identifier et de supprimer les composants malveillants. D'autres évoquent l'utilisation de ComboFix et la suppression d'éléments indésirables du démarrage, ainsi que le contrôle des extensions et des composants du navigateur via HijackThis. En cas de persistance, il est recommandé d'exécuter des scans complémentaires et de vérifier les modifications récentes du démarrage et des paramètres du navigateur pour éviter une réinfection.

Bobot (l’IA à votre service)
  1. bonjour.

    telecharge cela:util pour voir ce que peut etre l infection et agir ensuite.

    http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

    installe le normallement comme tout autre programme dans c/programme/...............
    clique sur do a scan and save a logfile, tu obtiens un rapport que tu colles.
    parfois alerte comme quoi, sans la fonction administrateur le rapport ne peut pas etre complet .
    a ce moment relance hijack avec un clique droit sur le raccourci et executer en tant qu administrateur.
    0
    1. Contributeur sécurité
      Salut,

      je te laisse là main ...

      pour suivre .... ;)
      0
  2. Contributeur sécurité
    Salut,

    essayes de faire ceci pour commencer :

    Télécharges et installes le logiciel HijackThis :

    ici : ftp://ftp.commentcamarche.com/download/HJTInstall.exe
    ou ici : http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
    ou ici : https://www.clubic.com/telecharger-fiche17891-hijackthis.html

    1- Cliques sur le setup pour lancer l'installe : laisses toi guider et ne modifies pas les paramètres d'installation .
    A la fin de l'installe , le prg se lance automatiquement : fermes le en cliquant sur la croix rouge .
    Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
    "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .
    Supprimes le raccourcis stp ...

    Important :
    Renommer le prg HijackThis (pour contrer l'infection Vundo):
    Rends toi sur ton PC ici "C:\ program files\Trend Micro\HijackThis\HijackThis.exe"<---cliques droit sur ce dernier et choisis "renommer" : tapes monjack et valides .
    Puis cliques droit sur "monjack.exe" et choisis "envoyer vers" -> le bureau ( créer un raccourci ).

    tuto pour utilisation
    Regardes ici, c'est parfaitement expliqué en images (merci balltrap34) :
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm
    ( Ne fixes encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement )

    2-!! Déconnectes toi et fermes toute tes applications en cours !!

    Cliques sur le raccourci du bureau pour lancer le prg :
    fais un scan "monjack" (ou HijackThis renommé) en cliquant sur : "Do a system scan and save a logfile"

    ---> Postes le rapport généré pour analyse ...

    0
    1. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 14:21:34, on 30/10/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 SP2 (7.00.5730.0011)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Orange\Systray\SystrayApp.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\DNA\btdna.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
      C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\PSIService.exe
      C:\WINDOWS\system32\svchost.exe
      c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Applications\wcs.exe
      C:\Program Files\Applications\iebtm.exe
      C:\Program Files\Applications\wcm.exe
      C:\Program Files\Applications\iebtmm.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\algg.exe
      C:\Program Files\trend micro\monjack\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = https://laptopadviser.com/malware-removal/
      R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = https://laptopadviser.com/malware-removal/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://laptopadviser.com/malware-removal/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://laptopadviser.com/malware-removal/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://laptopadviser.com/malware-removal/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://laptopadviser.com/malware-removal/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://laptopadviser.com/malware-removal/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://laptopadviser.com/malware-removal/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lo.st
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://laptopadviser.com/malware-removal/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://laptopadviser.com/malware-removal/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {3B7AAEB1-9F3D-4491-9C06-C7165CA8D058} - C:\Program Files\Applications\iebt.dll
      O2 - BHO: 512686 helper - {51B15F5A-E98B-4658-B9CB-9307B74773A7} - C:\WINDOWS\system32\512686\512686.dll
      O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
      O2 - BHO: VResLabWarningBHO Class - {B494E7BB-1E33-4922-A947-F74EFF4E714F} - C:\Program Files\VResLab\VResLabWarning.dll (file missing)
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
      O3 - Toolbar: Internet Service - {144A6B24-0EBC-4D89-BF09-A06A718E57B5} - C:\Program Files\Applications\iebr.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [PMCS] "C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe" -host -clearDebug
      O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
      O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
      O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
      O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
      O4 - HKLM\..\Run: [ItsTV] "C:\Program Files\ItsLabel\ItsTV.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [Corel Photo Downloader] "C:\Program Files\Fichiers communs\Corel\Corel PhotoDownloader\Corel PhotoDownloader.exe" -startup
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [ycmcy] "c:\documents and settings\utilisateur\local settings\application data\ycmcy.exe" ycmcy
      O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
      O4 - HKCU\..\Run: [messengerskinner] C:\Program Files\MessengerSkinner\MessengerSkinner.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
      O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
      O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
      O4 - HKCU\..\Run: [VResLab] "C:\Program Files\VResLab\VResLab.exe"
      O4 - HKCU\..\Run: [wblogon] C:\WINDOWS\system32\algg.exe
      O4 - HKLM\..\Policies\Explorer\Run: [smile] C:\Program Files\Applications\wcs.exe
      O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\Applications\iebtm.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Belkin Wireless Client Utility.lnk = C:\Program Files\Belkin\F5D9050\Belkinwcui.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.onlyiesettings.com/redirect.php (file missing)
      O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.onlyiesettings.com/redirect.php (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
      O22 - SharedTaskScheduler: bismuthiferous - {d04bbe06-7ce7-405e-8730-cd56d9531cbb} - C:\WINDOWS\system32\vimhx.dll
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
      0
      1. il y a du boulot pour desinfecter ensuite il faudra enlever des lignes inutils et ensuite mieux protege ton ordi.il ne faut pas cliquer sur n im porte quoi. tu en as plein d infection.

        on va commencer avec celui ci.

        tu télécharge navilog1
        http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

        Laisse-toi guider. Au menu principal, choisis 1 et valides.
        (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
        Patiente jusqu'au message :
        *** Analyse Termine le ..... ***
        Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
        Copie-colle l'intégralité dans une réponse. Referme le blocnote.
        Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
        0
        1. ps:avec le premier outil c est messenger skinner que je retire.
          0
          1. ps: je ne sais pas si je dirai "ne pas cliquer sur n'importe quoi quand on est infecté" mais plutôt "ne pas cliquer quand on n'y connait rien"(lol)
            pour messenger skiner comme pour d'autre choses, je pensais les avoir supprimés mais ils sont revenus après une restauration du système?!?! à voir !!!!
            0
        2. Search Navipromo version 3.6.7 commencé le 30/10/2008 à 14:44:17,39

          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
          !!! Postez ce rapport sur le forum pour le faire analyser !!!
          !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

          Outil exécuté depuis C:\Program Files\navilog1
          Session actuelle : "utilisateur"

          Mise à jour le 22.10.2008 à 20h00 par IL-MAFIOSO

          Microsoft Windows XP [version 5.1.2600]
          Internet Explorer : 6.0.2900.2180
          Système de fichiers : NTFS

          Recherche executé en mode normal

          *** Recherche Programmes installés ***

          Favorit
          MessengerSkinner

          *** Recherche dossiers dans "C:\WINDOWS" ***

          *** Recherche dossiers dans "C:\Program Files" ***

          *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

          *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\utilisateur\applic~1" ***

          *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

          *** Recherche dossiers dans "C:\DOCUME~1\parents\applic~1" ***

          *** Recherche dossiers dans "C:\DOCUME~1\PARENT~1\applic~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\utilisateur\locals~1\applic~1" ***

          *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

          *** Recherche dossiers dans "C:\DOCUME~1\parents\locals~1\applic~1" ***

          *** Recherche dossiers dans "C:\DOCUME~1\PARENT~1\locals~1\applic~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\utilisateur\menudm~1\progra~1" ***

          *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***

          *** Recherche dossiers dans "C:\DOCUME~1\parents\menudm~1\progra~1" ***

          *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
          pour + d'infos : http://www.gmer.net

          *** Recherche avec GenericNaviSearch ***
          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
          !!! A vérifier impérativement avant toute suppression manuelle !!!

          * Recherche dans "C:\WINDOWS\system32" *

          * Recherche dans "C:\Documents and Settings\utilisateur\locals~1\applic~1" *

          * Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

          * Recherche dans "C:\DOCUME~1\parents\locals~1\applic~1" *

          * Recherche dans "C:\DOCUME~1\PARENT~1\locals~1\applic~1" *

          *** Recherche fichiers ***

          *** Recherche clés spécifiques dans le Registre ***

          HKEY_CURRENT_USER\Software\Lanconfig trouvé !

          *** Module de Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Recherche nouveaux fichiers Instant Access :

          2)Recherche Heuristique :

          * Dans "C:\WINDOWS\system32" :

          * Dans "C:\Documents and Settings\utilisateur\locals~1\applic~1" :

          * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :

          * Dans "C:\DOCUME~1\parents\locals~1\applic~1" :

          * Dans "C:\DOCUME~1\PARENT~1\locals~1\applic~1" :

          3)Recherche Certificats :

          Certificat Egroup trouvé !
          Certificat Electronic-Group trouvé !
          Certificat Montorgueil absent !
          Certificat OOO-Favorit trouvé !
          Certificat Sunny-Day-Design-Ltd absent !

          4)Recherche fichiers connus :

          *** Analyse terminée le 30/10/2008 à 14:48:03,81 ***
          0
          1. il a trouve une partie de l infection navipromo.fait cela

            Salut,

            Arriver au menu principal, choisir l'option 2 et valider (nettoyage "automatique" ).

            Le fix demandera ensuite de "redémarrer le PC", fermer toutes les fenêtres ouvertes
            et appuyer sur une touche comme demandé.(si le PC ne redémarre pas automatiquement, le faire manuellement)
            Au redémarrage du PC, choisir la session habituelle si nécessaire.

            Patienter jusqu'au message : "Nettoyage Terminé le ..."

            Le bureau revient, puis le bloc-note s'ouvre .
            Sauvegarder ce rapport de manière à le retrouver, puis fermer le bloc-note ...
            (Le rapport sera en outre sauvegardé à la racine du disque "C\:cleannavi.txt")

            Postes ce rapport dans ta nouvelle réponse pour analyse et attends la suite ...

            (PS : Si le bureau ne réapparaît pas, faire CTRL+ALT+SUPPR pour ouvrir le gestionnaire de tâches.
            Choisir l'onglet processus. Cliquer en haut à gauche sur fichiers et choisir exécuter,
            Taper explorer et valider.)
            0
            1. la je t aide mais si ske 69 te dit de faire quelquechose il faudra suivre ces consignes(il s y connait tres bien) .
              0
              1. Clean Navipromo version 3.6.7 commencé le 30/10/2008 à 15:30:04,35

                Outil exécuté depuis C:\Program Files\navilog1
                Session actuelle : "utilisateur"

                Mise à jour le 22.10.2008 à 20h00 par IL-MAFIOSO

                Microsoft Windows XP [version 5.1.2600]
                Internet Explorer : 6.0.2900.2180
                Système de fichiers : NTFS

                Mode suppression automatique
                avec prise en charge résultats Catchme et GNS

                Nettoyage exécuté au redémarrage de l'ordinateur

                *** fsbl1.txt non trouvé ***
                (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                * Suppression dans "C:\WINDOWS\System32" *

                * Suppression dans "C:\Documents and Settings\utilisateur\locals~1\applic~1" *

                * Suppression dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

                * Suppression dans "C:\DOCUME~1\parents\locals~1\applic~1" *

                * Suppression dans "C:\DOCUME~1\PARENT~1\locals~1\applic~1" *

                *** Suppression dossiers dans "C:\WINDOWS" ***

                *** Suppression dossiers dans "C:\Program Files" ***

                *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

                *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

                *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                *** Suppression dossiers dans "C:\Documents and Settings\utilisateur\applic~1" ***

                *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

                *** Suppression dossiers dans "C:\DOCUME~1\parents\applic~1" ***

                *** Suppression dossiers dans "C:\DOCUME~1\PARENT~1\applic~1" ***

                *** Suppression dossiers dans "C:\Documents and Settings\utilisateur\locals~1\applic~1" ***

                *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

                *** Suppression dossiers dans "C:\DOCUME~1\parents\locals~1\applic~1" ***

                *** Suppression dossiers dans "C:\DOCUME~1\PARENT~1\locals~1\applic~1" ***

                *** Suppression dossiers dans "C:\Documents and Settings\utilisateur\menudm~1\progra~1" ***

                *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***

                *** Suppression dossiers dans "C:\DOCUME~1\parents\menudm~1\progra~1" ***

                *** Suppression fichiers ***

                *** Suppression fichiers temporaires ***

                Nettoyage contenu C:\WINDOWS\Temp effectué !
                Nettoyage contenu C:\Documents and Settings\utilisateur\locals~1\Temp effectué !

                *** Traitement Recherche complémentaire ***
                (Recherche fichiers spécifiques)

                1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                2)Recherche, création sauvegardes et suppression Heuristique :

                * Dans "C:\WINDOWS\system32" *

                * Dans "C:\Documents and Settings\utilisateur\locals~1\applic~1" *

                * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

                * Dans "C:\DOCUME~1\parents\locals~1\applic~1" *

                * Dans "C:\DOCUME~1\PARENT~1\locals~1\applic~1" *

                *** Sauvegarde du Registre vers dossier Safebackup ***

                sauvegarde du Registre réalisée avec succès !

                *** Nettoyage Registre ***

                Nettoyage Registre Ok

                *** Certificats ***

                Certificat Egroup supprimé !
                Certificat Electronic-Group supprimé !
                Certificat Montorgueil absent !
                Certificat OOO-Favorit supprimé !
                Certificat Sunny-Day-Design-Ltdt absent !

                *** Nettoyage terminé le 30/10/2008 à 15:32:49,98 ***
                0
                1. ok rien ou quasiment.

                  on va passer autre chose , fais comme indique,donne moi le rapport a la fin de la suppresion.

                  1)Telecharges malwares bytes anti malwares : egalement tres util sur pb de pub mais pas tous malheureusement

                  Malwarebytes Anti-Malware: http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                  Tutoriel Malwarebytes Anti-Malware: https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
                  fais comme indique,mise a jour , scan complet en mode sans echec et les rapports.

                  garde le et lance un scan tout les mois comme indique.

                  si tu as ad aware tu peux desinstalle car il ne reconnait plus grand chose.

                  2)refais un rapport hijack et colle le.
                  0
                  1. Contributeur sécurité
                    là , j'interviens ...^^

                    utiliser en premier les outils spécifiques ! utiliser les outils généralistes après ...

                    là, tu as une infection Zlob flagrante , il faut utiliser Smithfraudfix !

                    je te laisse donc rectifier le tire ... ;)

                    ++
                    0
                2. Télécharge SmitfraudFix
                  Utilitaire de S!Ri: Moe et balltrap34
                  http://siri.urz.free.fr/Fix/SmitfraudFix.php
                  et télécharge SmitfraudFix.exe.

                  Exécute le en choisissant l’option 1,
                  il va générer un rapport
                  Copie/colle le sur le poste stp.
                  0
                  1. SmitFraudFix v2.368

                    Rapport fait à 16:23:50,90, 30/10/2008
                    Executé à partir de C:\Program Files\Mozilla Firefox\SmitfraudFix
                    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                    Le type du système de fichiers est NTFS
                    Fix executé en mode normal

                    »»»»»»»»»»»»»»»»»»»»»»»» Process

                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                    C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
                    C:\WINDOWS\system32\nvsvc32.exe
                    C:\WINDOWS\system32\PSIService.exe
                    C:\WINDOWS\system32\svchost.exe
                    c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
                    C:\Program Files\Applications\wcs.exe
                    C:\Program Files\Applications\iebtm.exe
                    C:\WINDOWS\system32\RUNDLL32.EXE
                    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                    C:\Program Files\Applications\wcm.exe
                    C:\Program Files\Orange\Systray\SystrayApp.exe
                    C:\Program Files\Applications\iebtmm.exe
                    C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                    C:\Program Files\DNA\btdna.exe
                    C:\WINDOWS\system32\algg.exe
                    C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
                    C:\Program Files\Belkin\F5D9050\Belkinwcui.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\WINDOWS\system32\cmd.exe

                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                    C:\WINDOWS\system32\algg.exe PRESENT !

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\utilisateur

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\utilisateur\Application Data

                    C:\Documents and Settings\utilisateur\Application Data\Microsoft\Internet Explorer\Quick Launch\VirusResponse Lab 2009 2.1.lnk PRESENT !

                    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                    C:\DOCUME~1\UTILIS~1\MENUDM~1\VirusResponse Lab 2009 2.1.lnk PRESENT !
                    C:\DOCUME~1\UTILIS~1\MENUDM~1\PROGRA~1\VirusResponse Lab 2009 2.1 PRESENT !
                    C:\DOCUME~1\ALLUSE~1\MENUDM~1\Antivirus Scan.url PRESENT !

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\UTILIS~1\Favoris

                    C:\DOCUME~1\UTILIS~1\Favoris\Antivirus Scan.url PRESENT !

                    »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                    C:\DOCUME~1\UTILIS~1\Bureau\VirusResponse Lab 2009 2.1.lnk PRESENT !

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                    C:\Program Files\Applications\ PRESENT !

                    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                    "Source"="About:Home"
                    "SubscribedURL"="About:Home"
                    "FriendlyName"="Ma page d'accueil"

                    »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    o4Patch
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    IEDFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    VACFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    404Fix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri
                    +--------------------------------------------------+
                    [!] Suspicious: 512686.dll
                    BHO: 512686 Class - {51B15F5A-E98B-4658-B9CB-9307B74773A7}
                    BHO CLSID TypeLib: {E63648F7-3933-440E-AAAA-A8584DD7B7EB}
                    Corrected TypeLib: {E63648F7-3933-440E-B4F6-A8584DD7B7EB}
                    Interface: {F7D09218-46D7-4D3D-9B7F-315204CD0836}

                    »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    AntiXPVSTFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                    "{d04bbe06-7ce7-405e-8730-cd56d9531cbb}"="bismuthiferous"

                    [HKEY_CLASSES_ROOT\CLSID\{d04bbe06-7ce7-405e-8730-cd56d9531cbb}\InProcServer32]
                    @="C:\WINDOWS\system32\vimhx.dll"

                    [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{d04bbe06-7ce7-405e-8730-cd56d9531cbb}\InProcServer32]
                    @="C:\WINDOWS\system32\vimhx.dll"

                    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                    "AppInit_DLLs"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                    "System"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» RK

                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                    Description: Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller - Miniport d'ordonnancement de paquets
                    DNS Server Search Order: 192.168.1.1
                    DNS Server Search Order: 192.168.1.1

                    Description: Belkin Wireless G Plus MIMO USB Network Adapter - Miniport d'ordonnancement de paquets
                    DNS Server Search Order: 192.168.1.1

                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{CD908245-0789-4CCA-A914-8BD39B78BCEE}: DhcpNameServer=192.168.1.1 192.168.1.1
                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{E9B32ADF-B4BA-43B4-A795-AA40A54DC0AF}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{CD908245-0789-4CCA-A914-8BD39B78BCEE}: DhcpNameServer=192.168.1.1 192.168.1.1
                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{E9B32ADF-B4BA-43B4-A795-AA40A54DC0AF}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS2\Services\Tcpip\..\{CD908245-0789-4CCA-A914-8BD39B78BCEE}: DhcpNameServer=192.168.1.1 192.168.1.1
                    HKLM\SYSTEM\CS2\Services\Tcpip\..\{E9B32ADF-B4BA-43B4-A795-AA40A54DC0AF}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Fin
                    0
                    1. est ce que je poste le rapport malwarebytes? si oui, où puis-je retrouver ce rapport?
                      0
                      1. 1)pour smitfraud . va en mode sans echec et lance le en option2.tu obtiens un rapport que tu colles.

                        2)pour malwarebyte,(scan en mode sans echec j espere),le rapport se trouve dans l onglet rapport.lol
                        0
                        1. malheureusement oublié le mode sans échec :-), j'en refait un autre!
                          0
                          1. Malwarebytes' Anti-Malware 1.30
                            Version de la base de données: 1306
                            Windows 5.1.2600 Service Pack 2

                            30/10/2008 17:48:18
                            mbam-log-2008-10-30 (16-12-02).txt

                            Type de recherche: Examen complet (C:\|)
                            Eléments examinés: 124153
                            Temps écoulé: 27 minute(s), 28 second(s)

                            Processus mémoire infecté(s): 0
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 17
                            Valeur(s) du Registre infectée(s): 7
                            Elément(s) de données du Registre infecté(s): 14
                            Dossier(s) infecté(s): 0
                            Fichier(s) infecté(s): 3

                            Processus mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            HKEY_CLASSES_ROOT\Interface\{967a494a-6aec-4555-9caf-fa6eb00acf91} (Rogue.PestPatrol) -> No action taken.
                            HKEY_CLASSES_ROOT\Interface\{9692be2f-eb8f-49d9-a11c-c24c1ef734d5} (Rogue.PestPatrol) -> No action taken.
                            HKEY_CLASSES_ROOT\Interface\{f7d09218-46d7-4d3d-9b7f-315204cd0836} (Trojan.BHO) -> No action taken.
                            HKEY_CLASSES_ROOT\CLSID\{F5734812-E6A1-8833-ECA9-949B5B8A88BF} (Trojan.Zlob) -> No action taken.
                            HKEY_CLASSES_ROOT\CLSID\{144a6b24-0ebc-4d89-bf09-a06a718e57b5} (Trojan.Zlob) -> No action taken.
                            HKEY_CLASSES_ROOT\Typelib\{a8954909-1f0f-41a5-a7fa-3b376d69e226} (Rogue.PestPatrol) -> No action taken.
                            HKEY_CLASSES_ROOT\Typelib\{e63648f7-3933-440e-b4f6-a8584dd7b7eb} (Trojan.BHO) -> No action taken.
                            HKEY_CLASSES_ROOT\CLSID\{51b15f5a-e98b-4658-b9cb-9307b74773a7} (Trojan.BHO) -> No action taken.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51b15f5a-e98b-4658-b9cb-9307b74773a7} (Trojan.BHO) -> No action taken.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijack) -> No action taken.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> No action taken.
                            HKEY_CLASSES_ROOT\CLSID\e405.e405mgr (Trojan.Zlob) -> No action taken.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\System Alert Popup (Trojan.Zlob) -> No action taken.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEBrowse Tool (Trojan.Zlob) -> No action taken.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IExplorer Bar (Trojan.Zlob) -> No action taken.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Warning Center (Trojan.Zlob) -> No action taken.
                            HKEY_CLASSES_ROOT\multimediaControls.chl (Trojan.Zlob) -> No action taken.

                            Valeur(s) du Registre infectée(s):
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{144a6b24-0ebc-4d89-bf09-a06a718e57b5} (Trojan.Zlob) -> No action taken.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securewebinfo.com (Trojan.Zlob) -> No action taken.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.safetyincludes.com (Trojan.Zlob) -> No action taken.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securemanaging.com (Trojan.Zlob) -> No action taken.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wblogon (Trojan.Zlob) -> No action taken.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\start (Trojan.Zlob) -> No action taken.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\smile (Trojan.Zlob) -> No action taken.

                            Elément(s) de données du Registre infecté(s):
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (https://www.google.com/?gws_rd=ssl -> No action taken.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (https://www.google.com/?gws_rd=ssl -> No action taken.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (https://www.google.com/?gws_rd=ssl -> No action taken.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (https://www.google.com/?gws_rd=ssl -> No action taken.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (https://www.google.com/?gws_rd=ssl -> No action taken.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (https://www.google.com/?gws_rd=ssl -> No action taken.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.Search) -> Bad: (https://laptopadviser.com/malware-removal/ Good: (https://www.google.com/?gws_rd=ssl -> No action taken.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.Search) -> Bad: (https://laptopadviser.com/malware-removal/ Good: (https://www.google.com/?gws_rd=ssl -> No action taken.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (https://laptopadviser.com/malware-removal/{searchTerms}) Good: (https://www.google.com/?gws_rd=ssl -> No action taken.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (https://laptopadviser.com/malware-removal/{searchTerms}) Good: (https://www.google.com/?gws_rd=ssl -> No action taken.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (https://www.google.com/?gws_rd=ssl -> No action taken.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (https://www.google.com/?gws_rd=ssl -> No action taken.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) -> Bad: (http://windiwsfsearch.com/search?q=%s) Good: (https://www.google.com/?gws_rd=ssl -> No action taken.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) -> Bad: (http://windiwsfsearch.com/search?q=%s) Good: (https://www.google.com/?gws_rd=ssl -> No action taken.

                            Dossier(s) infecté(s):
                            (Aucun élément nuisible détecté)

                            Fichier(s) infecté(s):
                            C:\WINDOWS\system32\512686\512686.dll (Trojan.BHO) -> No action taken.
                            C:\RECYCLER\S-1-5-21-343818398-484061587-839522115-1004\Dc291\uninst.exe (Rogue.Installer) -> No action taken.
                            C:\RECYCLER\S-1-5-21-343818398-484061587-839522115-1004\Dc291\VResLab.exe (Rogue.VirusHeat) -> No action taken.
                            0
                            1. SmitFraudFix v2.368

                              Rapport fait à 17:49:01,57, 30/10/2008
                              Executé à partir de C:\Documents and Settings\utilisateur\Bureau\SmitfraudFix
                              OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                              Le type du système de fichiers est NTFS
                              Fix executé en mode sans echec

                              »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                              SrchSTS.exe by S!Ri
                              Search SharedTaskScheduler's .dll

                              »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                              »»»»»»»»»»»»»»»»»»»»»»»» hosts

                              127.0.0.1 localhost

                              »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                              VACFix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                              S!Ri's WS2Fix: LSP not Found.

                              »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                              GenericRenosFix by S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                              »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                              IEDFix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                              404Fix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri
                              C:\WINDOWS\system32\512686\512686.dll deleted.
                              C:\WINDOWS\system32\512686\ deleted.

                              »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

                              AntiXPVSTFix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» RK

                              »»»»»»»»»»»»»»»»»»»»»»»» DNS

                              HKLM\SYSTEM\CCS\Services\Tcpip\..\{CD908245-0789-4CCA-A914-8BD39B78BCEE}: DhcpNameServer=192.168.1.1 192.168.1.1
                              HKLM\SYSTEM\CCS\Services\Tcpip\..\{E9B32ADF-B4BA-43B4-A795-AA40A54DC0AF}: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS1\Services\Tcpip\..\{CD908245-0789-4CCA-A914-8BD39B78BCEE}: DhcpNameServer=192.168.1.1 192.168.1.1
                              HKLM\SYSTEM\CS1\Services\Tcpip\..\{E9B32ADF-B4BA-43B4-A795-AA40A54DC0AF}: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS2\Services\Tcpip\..\{CD908245-0789-4CCA-A914-8BD39B78BCEE}: DhcpNameServer=192.168.1.1 192.168.1.1
                              HKLM\SYSTEM\CS2\Services\Tcpip\..\{E9B32ADF-B4BA-43B4-A795-AA40A54DC0AF}: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                              »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                              <ital>pour le nettoyage j'ai tapé non. j'éspère que j'ai bien fait!!
                              </ital>


                              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                              "System"=""

                              »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                              Nettoyage du registre non souhaité.

                              »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                              SrchSTS.exe by S!Ri
                              Search SharedTaskScheduler's .dll

                              »»»»»»»»»»»»»»»»»»»»»»»» Fin
                              0
                              1. Contributeur sécurité
                                Pour avancer ...

                                pour le nettoyage j'ai tapé non. j'éspère que j'ai bien fait!!
                                -> Et non , il fallais répondre OUI à tout .... -_-

                                reprends extament ainsi :

                                Impératif : Démarrer en mode sans echec .

                                /!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

                                Comment aller en Mode sans échec :
                                1) Redémarres ton ordi .
                                2) Tapotes la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip" .
                                3) Tu tapotes jusqu' à l'apparition de l'écran avec les options de démarrage .
                                4) Choisis la première option : Sans Échec , et valides en tapant sur [Entrée] .
                                5) Choisis ton compte habituel ( et pas Administrateur ).
                                attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...

                                * Double-cliques sur SmitfraudFix.exe

                                * Sélectionnes 2 et presses "Entrée" dans le menu pour supprimer les fichiers responsables de l'infection.

                                --> Si besion :

                                * A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et presser Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection.

                                ( Le correctif déterminera si le fichier wininet.dll est infecté.)

                                * A la question: "Corriger le fichier infecté ?" répondre O (oui) et presser Entrée
                                pour remplacer le fichier corrompu.

                                * Un redémarrage sera peut être nécessaire pour terminer la procédure de nettoyage ( sinon fais le manuellement )

                                Le rapport se trouve à la racine de C\:
                                (dans le fichier "rapport.txt")

                                Postes moi ce dernier rapport accompagné, dans la même réponse, d'un nouveau rapport
                                hijackthis ( fais en mode normal ) et attends les instructions ...

                                ensuite , je re laisse la place à totobetourne bien sûr ... ;)

                                0
                                1. 1)fait smitfraud fix comme te la indique ske 69.

                                  2)pour malwarebyte tu me montres le mauvais rapport,il faut me montrer celui avec quarantined and deleted successfully.
                                  vide la quarantaine.

                                  3)refais moi un hijack et colle le rapport.
                                  0
                                  1. SmitFraudFix v2.368

                                    Rapport fait à 21:49:32,34, 30/10/2008
                                    Executé à partir de C:\Documents and Settings\utilisateur\Bureau\SmitfraudFix
                                    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                                    Le type du système de fichiers est NTFS
                                    Fix executé en mode sans echec

                                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                    SrchSTS.exe by S!Ri
                                    Search SharedTaskScheduler's .dll

                                    »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                    127.0.0.1 localhost

                                    »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                                    VACFix
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                                    S!Ri's WS2Fix: LSP not Found.

                                    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                                    GenericRenosFix by S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                                    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                                    IEDFix
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                                    404Fix
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

                                    AntiXPVSTFix
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» RK

                                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{CD908245-0789-4CCA-A914-8BD39B78BCEE}: DhcpNameServer=192.168.1.1 192.168.1.1
                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{E9B32ADF-B4BA-43B4-A795-AA40A54DC0AF}: DhcpNameServer=192.168.1.1
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{CD908245-0789-4CCA-A914-8BD39B78BCEE}: DhcpNameServer=192.168.1.1 192.168.1.1
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{E9B32ADF-B4BA-43B4-A795-AA40A54DC0AF}: DhcpNameServer=192.168.1.1
                                    HKLM\SYSTEM\CS2\Services\Tcpip\..\{CD908245-0789-4CCA-A914-8BD39B78BCEE}: DhcpNameServer=192.168.1.1 192.168.1.1
                                    HKLM\SYSTEM\CS2\Services\Tcpip\..\{E9B32ADF-B4BA-43B4-A795-AA40A54DC0AF}: DhcpNameServer=192.168.1.1
                                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                                    »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                    "System"=""

                                    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                                    Nettoyage terminé.

                                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                    SrchSTS.exe by S!Ri
                                    Search SharedTaskScheduler's .dll

                                    »»»»»»»»»»»»»»»»»»»»»»»» Fin

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 22:04:27, on 30/10/2008
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v7.00 SP2 (7.00.5730.0011)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\WINDOWS\system32\RUNDLL32.EXE
                                    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    C:\Program Files\Orange\Systray\SystrayApp.exe
                                    C:\Program Files\DNA\btdna.exe
                                    C:\Program Files\Belkin\F5D9050\Belkinwcui.exe
                                    C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                                    C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                                    C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
                                    C:\WINDOWS\system32\nvsvc32.exe
                                    C:\WINDOWS\system32\PSIService.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
                                    C:\WINDOWS\system32\wscntfy.exe
                                    C:\Program Files\Mozilla Firefox\firefox.exe
                                    C:\Program Files\trend micro\monjack\HijackThis.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
                                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: (no name) - {3B7AAEB1-9F3D-4491-9C06-C7165CA8D058} - C:\Program Files\Applications\iebt.dll (file missing)
                                    O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
                                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
                                    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
                                    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
                                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                    O4 - HKLM\..\Run: [PMCS] "C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe" -host -clearDebug
                                    O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
                                    O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
                                    O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
                                    O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
                                    O4 - HKLM\..\Run: [ItsTV] "C:\Program Files\ItsLabel\ItsTV.exe"
                                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    O4 - HKLM\..\Run: [Corel Photo Downloader] "C:\Program Files\Fichiers communs\Corel\Corel PhotoDownloader\Corel PhotoDownloader.exe" -startup
                                    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
                                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                    O4 - HKCU\..\Run: [ycmcy] "c:\documents and settings\utilisateur\local settings\application data\ycmcy.exe" ycmcy
                                    O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
                                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                    O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                                    O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
                                    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
                                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                    O4 - Global Startup: Belkin Wireless Client Utility.lnk = C:\Program Files\Belkin\F5D9050\Belkinwcui.exe
                                    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
                                    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                    O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
                                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                    O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
                                    0
                                    • 1
                                    • 2
                                    • 3