Probleme avec smart antivirus

Bonjour,

voila je pense que je suis pas le seul a avoir eu ce probleme mais souvent lorsque je vais sur le web une page s'affiche a la place de celle que j'ai demander en me disant que mon ordinateur n'est pas proteger et me donne un lien pour smart antivirus
donc si quelqu'un sait ce qu'il faut faire ca serai sympa de m'aider
merci d'avance
Configuration: Windows Vista
Internet Explorer 7.0

15 réponses

  1. Contributeur sécurité
    Salut !!

    ▶ Fais un rapport hijackthis pour que je puisse vérifier les infections de ton pc stp

    ▶ Télécharge hijackthis et enregistre le fichier d'installation sur ton bureau.

    ▶ Ensuite double-cliques sur le fichier d'installation puis sur "exécuter".

    ▶ Cliques sur "Install" en vérifiant que le chemin d'installation est bien dans tes programmes et puis sur "I Accept".

    ▶ Cliques sur "Do a system scan and save a logfile".

    ▶ Laisse l'analyse se terminer jusqu'à l'apparition du rapport dans le bloc note.

    ▶ Ensuite fais un copié/collé du rapport dans ta prochaine réponse sur le forum

    Comment copier/coller le rapport :

    Quand tu as le rapport à l écran, tu fais ctrl A pour "sélectionner tout" puis ctrl C pour "copier".

    ensuite tu viens sur le forum pour me répondre et tu fais ctrl V pour "coller" le rapport.
    0
    1. voici le rapport
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 15:34:20, on 10/11/2008
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Windows\System32\hkcmd.exe
      C:\Windows\System32\igfxpers.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\Program Files\Sony\ISB Utility\ISBMgr.exe
      C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
      C:\Program Files\Grisoft\AVG7\avgcc.exe
      C:\Program Files\FlashGet\flashget.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
      C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Logitech\SetPoint\SetPoint.exe
      C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
      C:\Program Files\Grisoft\AVG7\avgw.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Program Files\Internet Explorer\ieuser.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://my.yahoo.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: QXK Olive - {083B32AD-4448-4F60-B38B-BBD1C8197630} - C:\Windows\grfxbanodkx.dll
      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
      O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
      O3 - Toolbar: (no name) - {148BDBE0-051C-4B70-84B3-889274D33E60} - (no file)
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
      O4 - HKLM\..\Run: [NapsterShell] "C:\Program Files\Napster\napster.exe" /systray
      O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
      O4 - HKLM\..\Run: [VAIOSecurity] "C:\Program Files\Sony\VAIO Security Center\VSC.exe" 1
      O4 - HKLM\..\Run: [QuickBooks Simple Start] "C:\Program Files\Intuit\SimpleStartEntice\entice.exe"
      O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire\Corel PhotoDownloader.exe
      O4 - HKLM\..\Run: [VAIOSurvey] "C:\Program Files\Sony\VAIO Survey\Vista VAIO Survey.exe"
      O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
      O4 - HKLM\..\Run: [Flashget] "C:\Program Files\FlashGet\FlashGet.exe" /min
      O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [Skytel] Skytel.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
      O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
      O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKLM\..\Policies\Explorer\Run: [pOdC1VH13x] C:\ProgramData\ozklcxod\uhmpqfaj.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
      O4 - Global Startup: Logitech SetPoint.lnk = Logitech\SetPoint\SetPoint.exe
      O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
      O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
      O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
      O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
      O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
      O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
      O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O13 - Gopher Prefix:
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/VistaMSNPUplden-us.cab
      O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
      O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
      O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
      O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
      O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
      O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Image Converter SCSI Service (ICScsiSV) - Sony Corporation - C:\Program Files\Sony\Image Converter 3\ICScsiSV.exe
      O23 - Service: IcVzMonLauncher - Sony Corporation - C:\Program Files\Sony\Image Converter 3\IcVzMonLauncher.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 3\IcVzMon.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
      O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
      O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
      O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
      O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) - - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
      O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
      O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
      O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
      O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
      O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
      O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
      O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
      O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
      O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
      O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
      O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
      O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
      O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
      O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
      O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
      O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
      O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
      0
      1. Contributeur sécurité
        commence par faire ceci stp :

        Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

        ▶ Va dans démarrer puis panneau de configuration
        ▶ Double Clique sur l'icône "Comptes d'utilisateurs"
        ▶ Clique ensuite sur désactiver et valide.

        ensuite :

        Option 1 - Recherche :

        ▶ télécharge smitfraudfix et enregistre le sur le bureau

        ▶ Ensuite double clique sur smitfraudfix puis exécuter

        ▶ Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.

        (attention : N utilises pas l option 2 si je ne te l ai pas demandé !!)

        ▶ copier/coller le rapport dans la réponse.

        Voici un tutoriel sonore et animé en cas de problème d'utilisation

        (Attention : "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool".
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains,
        cet utilitaire pourrait arrêter des logiciels de sécurité.)
        0
        1. voici le rapport
          SmitFraudFix v2.374

          Scan done at 15:56:07,82, 10/11/2008
          Run from C:\Users\ben\Desktop\SmitfraudFix
          OS: Microsoft Windows [Version 6.0.6001] - Windows_NT
          The filesystem type is NTFS
          Fix run in normal mode

          »»»»»»»»»»»»»»»»»»»»»»»» Process

          C:\Windows\system32\csrss.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\services.exe
          C:\Windows\system32\lsass.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\winlogon.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\SLsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\spoolsv.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Windows\System32\hkcmd.exe
          C:\Windows\System32\igfxpers.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
          C:\Program Files\Sony\ISB Utility\ISBMgr.exe
          C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
          C:\Program Files\Grisoft\AVG7\avgcc.exe
          C:\Program Files\FlashGet\flashget.exe
          C:\Program Files\Adobe\Reader 8.0\Reader\Reader_SL.exe
          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
          C:\Program Files\Sony\VAIO Service Utility\VAIO-SUTOOL.exe
          C:\Windows\system32\igfxsrvc.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Steam\Steam.exe
          C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
          C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
          C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
          C:\Program Files\Logitech\SetPoint\SetPoint.exe
          C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
          C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
          C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
          C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
          C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
          C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
          C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\SearchIndexer.exe
          C:\Windows\system32\DRIVERS\xaudio.exe
          C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
          C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
          C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
          C:\Windows\system32\WUDFHost.exe
          C:\Windows\system32\igfxext.exe
          C:\Windows\system32\igfxsrvc.exe
          C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Windows\System32\alg.exe
          C:\Windows\system32\cmd.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Program Files\Windows Media Player\wmpnetwk.exe
          C:\Windows\system32\wbem\unsecapp.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Program Files\Common Files\Steam\SteamService.exe
          C:\Windows\system32\taskeng.exe

          »»»»»»»»»»»»»»»»»»»»»»»» hosts

          »»»»»»»»»»»»»»»»»»»»»»»» C:\

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\ben

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\ben\AppData\Local\Temp

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\ben\Application Data

          »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\ben\FAVORI~1

          »»»»»»»»»»»»»»»»»»»»»»»» Desktop

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

          C:\Program Files\akl\ FOUND !

          »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

          »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

          »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
          !!!Attention, following keys are not inevitably infected!!!

          o4Patch
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
          !!!Attention, following keys are not inevitably infected!!!

          IEDFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» VACFix
          !!!Attention, following keys are not inevitably infected!!!

          VACFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri
          +--------------------------------------------------+
          [!] Suspicious: grfxbanodkx.dll
          BHO: QXK Olive - {083B32AD-4448-4F60-B38B-BBD1C8197630}
          TypeLib: {E6CB66C9-44FA-4238-BD15-BBD9BE990F42}
          Interface: {D15991D1-517A-41B2-ACD7-8C7B93DD118C}
          Interface: {DB9D2026-3134-4AB2-8FD0-9C4AF287726F}

          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
          !!!Attention, following keys are not inevitably infected!!!

          404Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
          !!!Attention, following keys are not inevitably infected!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
          !!!Attention, following keys are not inevitably infected!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLs"=""
          "LoadAppInit_DLLs"=dword:00000000

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
          !!!Attention, following keys are not inevitably infected!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "Userinit"="C:\\Windows\\system32\\userinit.exe,"

          »»»»»»»»»»»»»»»»»»»»»»»» RK

          »»»»»»»»»»»»»»»»»»»»»»»» DNS

          Description: Intel(R) Wireless WiFi Link 4965AGN
          DNS Server Search Order: 212.27.40.240
          DNS Server Search Order: 212.27.40.241

          HKLM\SYSTEM\CCS\Services\Tcpip\..\{D83D5627-FB49-437C-B3E7-C61C85550B27}: DhcpNameServer=212.27.40.240 212.27.40.241
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{D83D5627-FB49-437C-B3E7-C61C85550B27}: DhcpNameServer=212.27.40.240 212.27.40.241
          HKLM\SYSTEM\CS2\Services\Tcpip\..\{D83D5627-FB49-437C-B3E7-C61C85550B27}: DhcpNameServer=212.27.40.240 212.27.40.241
          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
          HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241

          »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

          »»»»»»»»»»»»»»»»»»»»»»»» End
          0
          1. Contributeur sécurité
            ok maintenant :

            Option 2 - Nettoyage :

            redémarre le PC en mode sans échec

            ▶ Double cliquer sur smitfraudfix

            ▶ Sélectionner 2 pour supprimer les fichiers responsables de l'infection.

            ▶ A la question Voulez-vous nettoyer le registre ? répondre O (oui) afin de débloquer le fond d'écran et supprimer les clés de démarrage automatique de l'infection.

            Le fix déterminera si le fichier wininet.dll est infecté. A la question Corriger le fichier infecté ? répondre O (oui) pour remplacer le fichier corrompu.

            ▶ Enregistre le rapport sur ton bureau

            ▶ Redémarrer en mode normal et poster le rapport.
            0
            1. SmitFraudFix v2.374

              Scan done at 16:07:10,43, 10/11/2008
              Run from C:\Users\ben\Desktop\SmitfraudFix
              OS: Microsoft Windows [Version 6.0.6001] - Windows_NT
              The filesystem type is NTFS
              Fix run in safe mode

              »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
              !!!Attention, following keys are not inevitably infected!!!

              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll

              »»»»»»»»»»»»»»»»»»»»»»»» Killing process

              »»»»»»»»»»»»»»»»»»»»»»»» hosts

              127.0.0.1 localhost
              ::1 localhost

              »»»»»»»»»»»»»»»»»»»»»»»» VACFix

              VACFix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri
              C:\Windows\grfxbanodkx.dll deleted.

              »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

              S!Ri's WS2Fix: LSP not Found.

              »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

              GenericRenosFix by S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

              C:\Program Files\akl\ Deleted

              »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

              IEDFix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

              404Fix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» RK

              »»»»»»»»»»»»»»»»»»»»»»»» DNS

              HKLM\SYSTEM\CCS\Services\Tcpip\..\{D83D5627-FB49-437C-B3E7-C61C85550B27}: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CS1\Services\Tcpip\..\{D83D5627-FB49-437C-B3E7-C61C85550B27}: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CS2\Services\Tcpip\..\{D83D5627-FB49-437C-B3E7-C61C85550B27}: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241

              »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
              !!!Attention, following keys are not inevitably infected!!!

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

              »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

              Registry Cleaning done.

              »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
              !!!Attention, following keys are not inevitably infected!!!

              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll

              »»»»»»»»»»»»»»»»»»»»»»»» End
              0
              1. Contributeur sécurité
                ok maintenant fais ceci stp :

                ▶ Télécharge malwarebyte's anti-malware

                ▶ Voici un tutoriel pour t'aider à l'utiliser.

                ▶ Fais la mise à jour du logiciel (elle se fait normalement à l'installation)

                ▶ Lance une analyse complète en cliquant sur "Exécuter un examen complet"

                ▶ Sélectionnes les disques que tu veux analyser et cliques sur "Lancer l'examen"

                ▶ L'analyse peut durer un bon moment.....

                ▶ Une fois l'analyse terminée, cliques sur "OK" puis sur "Afficher les résultats"

                ▶ Vérifies que tout est bien coché et cliques sur "Supprimer la sélection" => et ensuite sur "OK"

                ▶ Un rapport va s'ouvrir dans le bloc note... Fais un copié/collé du rapport dans ta prochaine réponse sur le forum

                * Il se pourrait que certains fichiers devront être supprimés au redémarrage du PC... Faites le en cliquant sur "oui" à la question posée

                Et ensuite refais un nouveau rapport hijackthis stp
                0
                1. Malwarebytes' Anti-Malware 1.30
                  Version de la base de données: 1380
                  Windows 6.0.6001 Service Pack 1

                  10/11/2008 21:59:03
                  mbam-log-2008-11-10 (21-59-03).txt

                  Type de recherche: Examen complet (C:\|)
                  Eléments examinés: 164481
                  Temps écoulé: 2 hour(s), 10 minute(s), 7 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 28
                  Valeur(s) du Registre infectée(s): 3
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 3
                  Fichier(s) infecté(s): 61

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  HKEY_CLASSES_ROOT\CLSID\{0656a137-b161-cadd-9777-e37a75727e78} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{0b682cc1-fb40-4006-a5dd-99edd3c9095d} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{0e1230f8-ea50-42a9-983c-d22abc2eeb4c} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{54645654-2225-4455-44a1-9f4543d34545} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{5c7f15e1-f31a-44fd-aa1a-2ec63aaffd3a} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\dpcproxy (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\typelib (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\HOL5_VXIEWER.FULL.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Classes\hol5_vxiewer.full.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Classes\applications\accessdiver.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\fwbd (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\HolLol (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Invictus (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\iTunesMusic (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\rdriv (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\mwc (Malware.Trace) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\rosqxvmn.bnml (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\rosqxvmn.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.

                  Valeur(s) du Registre infectée(s):
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{0e1230f8-ea50-42a9-983c-d22abc2eeb4c} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{0656a137-b161-cadd-9777-e37a75727e78} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SystemCheck2 (Trojan.Agent) -> Quarantined and deleted successfully.

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  C:\Windows\mslagent (Adware.EGDAccess) -> Quarantined and deleted successfully.
                  C:\Program Files\Inet Delivery (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\Windows\System32\smp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.

                  Fichier(s) infecté(s):
                  C:\Windows\mslagent\2_mslagent.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
                  C:\Windows\mslagent\mslagent.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
                  C:\Windows\mslagent\uninstall.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
                  C:\Program Files\Inet Delivery\inetdl.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\Program Files\Inet Delivery\intdel.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\Windows\System32\smp\msrc.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\Windows\a.bat (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\Windows\base64.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\Windows\FVProtect.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\Windows\userconfig9x.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\Windows\winsystem.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\Windows\zip1.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\Windows\zip2.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\Windows\zip3.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\Windows\zipped.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\Windows\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\iTunesMusic.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\akttzn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\anticipator.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\awtoolb.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\bsva-egihsg52.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\dpcproxy.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\emesx.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\h@tkeysh@@k.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\hoproxy.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\hxiwlgpm.dat (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\hxiwlgpm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\medup012.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\medup020.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\msgp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\msnbho.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\msvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\mtr2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\mwin32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\netode.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\newsd32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\ps1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\psof1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\psoft1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\regc64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\regm64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\Rundl1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\sncntr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\ssurf022.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\ssvchost.com (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\ssvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\sysreq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\taack.dat (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\taack.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\temp#01.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\thun.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\thun32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\VBIEWER.OCX (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\vcatchpi.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\winlogonpc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\winsystem.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\WINWGPX.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Windows\System32\vbsys2.dll (Trojan.Clicker) -> Quarantined and deleted successfully.
                  0
                  1. Contributeur sécurité
                    ok maintenant fais ceci stp :

                    ▶ Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                    * Va dans démarrer puis panneau de configuration
                    * Double Clique sur l'icône "Comptes d'utilisateurs"
                    * Clique ensuite sur désactiver et valide.

                    http://www.laboratoire-microsoft.org/tips-23933-desactiver-uac-vista.html

                    ▶ Télécharge sur le bureau Navilog1

                    *Si ton antivirus s'affole , le désactiver
                    sous vista : Clic-droit sur le raccourci Navilog1 présent sur le bureau et choisis "Exécuter en tant qu'administrateur
                    sous XP : double-clic dessus pour l'installer et le lancer

                    ▶ Quand installé
                    ▶ taper F
                    ▶ Appuyer sur une touche jusqu' arriver aux options
                    ▶ Choisir Recherche ( = taper 1 )

                    ▶ne pas utiliser les autres sans avis , il peut y avoir des processus légitimes

                    ▶un rapport : fixnavi.txt dans ==> C:

                    ▶le copier et le coller dans la réponse
                    0
                    1. Search Navipromo version 3.6.9 commencé le 10/11/2008 à 22:10:43,85

                      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                      !!! Postez ce rapport sur le forum pour le faire analyser !!!
                      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                      Outil exécuté depuis C:\Program Files\navilog1
                      Session actuelle : "ben"

                      Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO

                      Microsoft Windows Vista 6.0.6001
                      Internet Explorer : 7.0.6001.18000
                      Système de fichiers : NTFS

                      Recherche executé en mode normal

                      *** Recherche Programmes installés ***

                      *** Recherche dossiers dans "C:\Windows" ***

                      *** Recherche dossiers dans "C:\Program Files" ***

                      *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                      *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

                      *** Recherche dossiers dans "C:\ProgramData" ***

                      *** Recherche dossiers dans "c:\users\ben\appdata\roaming\micros~1\windows\startm~1\programs" ***

                      *** Recherche dossiers dans "C:\Users\ben\AppData\Local\virtualstore\Program Files" ***

                      *** Recherche dossiers dans "C:\Users\ben\AppData\Roaming" ***

                      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                      pour + d'infos : http://www.gmer.net

                      *** Recherche avec GenericNaviSearch ***
                      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                      !!! A vérifier impérativement avant toute suppression manuelle !!!

                      * Recherche dans "C:\Windows\system32" *

                      * Recherche dans "C:\Users\ben\AppData\Local\Microsoft" *

                      * Recherche dans "C:\Users\ben\AppData\Local\virtualstore\windows\system32" *

                      * Recherche dans "C:\Users\ben\AppData\Local" *

                      *** Recherche fichiers ***

                      *** Recherche clés spécifiques dans le Registre ***

                      *** Module de Recherche complémentaire ***
                      (Recherche fichiers spécifiques)

                      1)Recherche nouveaux fichiers Instant Access :

                      2)Recherche Heuristique :

                      * Dans "C:\Windows\system32" :

                      * Dans "C:\Users\ben\AppData\Local\Microsoft" :

                      * Dans "C:\Users\ben\AppData\Local\virtualstore\windows\system32" :

                      * Dans "C:\Users\ben\AppData\Local" :

                      3)Recherche Certificats :

                      Certificat Egroup absent !
                      Certificat Electronic-Group absent !
                      Certificat Montorgueil absent !
                      Certificat OOO-Favorit absent !
                      Certificat Sunny-Day-Design-Ltd absent !

                      4)Recherche fichiers connus :

                      *** Analyse terminée le 10/11/2008 à 22:26:10,14 ***
                      0
                      1. Contributeur sécurité
                        ok il n a rien trouvé ;-)

                        refais un nouveau rapport hijackthis stp
                        0
                        1. Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 22:36:41, on 10/11/2008
                          Platform: Windows Vista SP1 (WinNT 6.00.1905)
                          MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                          Boot mode: Normal

                          Running processes:
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\Explorer.EXE
                          C:\Program Files\Sony\VAIO Service Utility\VAIO-SUTOOL.exe
                          C:\Program Files\Windows Defender\MSASCui.exe
                          C:\Windows\System32\hkcmd.exe
                          C:\Windows\System32\igfxpers.exe
                          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          C:\Windows\system32\igfxsrvc.exe
                          C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                          C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                          C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
                          C:\Program Files\Grisoft\AVG7\avgcc.exe
                          C:\Program Files\FlashGet\flashget.exe
                          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                          C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
                          C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
                          C:\Program Files\iTunes\iTunesHelper.exe
                          C:\Program Files\Steam\Steam.exe
                          C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
                          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                          C:\Program Files\Logitech\SetPoint\SetPoint.exe
                          C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\Windows\system32\SearchFilterHost.exe
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                          O1 - Hosts: ::1 localhost
                          O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                          O2 - BHO: (no name) - {083B32AD-4448-4F60-B38B-BBD1C8197630} - (no file)
                          O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                          O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
                          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
                          O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
                          O3 - Toolbar: (no name) - {148BDBE0-051C-4B70-84B3-889274D33E60} - (no file)
                          O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                          O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                          O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                          O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                          O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
                          O4 - HKLM\..\Run: [NapsterShell] "C:\Program Files\Napster\napster.exe" /systray
                          O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
                          O4 - HKLM\..\Run: [VAIOSecurity] "C:\Program Files\Sony\VAIO Security Center\VSC.exe" 1
                          O4 - HKLM\..\Run: [QuickBooks Simple Start] "C:\Program Files\Intuit\SimpleStartEntice\entice.exe"
                          O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire\Corel PhotoDownloader.exe
                          O4 - HKLM\..\Run: [VAIOSurvey] "C:\Program Files\Sony\VAIO Survey\Vista VAIO Survey.exe"
                          O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
                          O4 - HKLM\..\Run: [Flashget] "C:\Program Files\FlashGet\FlashGet.exe" /min
                          O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                          O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                          O4 - HKLM\..\Run: [Skytel] Skytel.exe
                          O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                          O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
                          O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
                          O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
                          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                          O4 - HKLM\..\Policies\Explorer\Run: [pOdC1VH13x] C:\ProgramData\ozklcxod\uhmpqfaj.exe
                          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                          O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
                          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                          O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
                          O4 - Global Startup: Logitech SetPoint.lnk = Logitech\SetPoint\SetPoint.exe
                          O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
                          O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
                          O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                          O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                          O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                          O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                          O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                          O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                          O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                          O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
                          O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
                          O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
                          O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
                          O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
                          O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
                          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                          O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                          O13 - Gopher Prefix:
                          O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                          O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
                          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                          O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                          O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
                          O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                          O23 - Service: Image Converter SCSI Service (ICScsiSV) - Sony Corporation - C:\Program Files\Sony\Image Converter 3\ICScsiSV.exe
                          O23 - Service: IcVzMonLauncher - Sony Corporation - C:\Program Files\Sony\Image Converter 3\IcVzMonLauncher.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                          O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 3\IcVzMon.exe
                          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
                          O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
                          O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                          O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                          O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) - - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
                          O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
                          O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
                          O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                          O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
                          O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                          O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                          O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                          O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                          O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                          O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                          O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                          O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
                          O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                          O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                          O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                          O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                          O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                          0
                          1. Contributeur sécurité
                            Ok... Relance hijackthis en cliquant sur scan only et coches ces lignes stp :

                            O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                            O2 - BHO: (no name) - {083B32AD-4448-4F60-B38B-BBD1C8197630} - (no file)
                            O3 - Toolbar: (no name) - {148BDBE0-051C-4B70-84B3-889274D33E60} - (no file)
                            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

                            puis tu cliques sur fix checked.

                            ensuite fais la mise à jour de java à cette adresse stp : https://www.java.com/fr/download/manual.jsp

                            et ensuite désinstalle la version antérieure de java (version 6 update 7)

                            est ce que tu as encore des problèmes ??
                            0
                            1. ben tout a l'air de marcher je te remercie pour tout et te tient au courant si le probleme revient
                              merci bocoup et bonne soiree a toi
                              0
                              1. Contributeur sécurité
                                Mais de rien, je t ai aidé avec plaisir ;-)

                                Si tu n as plus de problèmes tu peux faire ceci pour terminer stp :

                                Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                                ▶ Va dans démarrer puis panneau de configuration
                                ▶ Double Clique sur l'icône "Comptes d'utilisateurs"
                                ▶ Clique ensuite sur désactiver et valide.

                                Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques :

                                ▶ Télécharge Toolscleaner sur ton Bureau

                                ▶ Double-clique sur ToolsCleaner2.exe et laisse le travailler
                                ▶ Clique sur Recherche et laisse le scan se terminer.
                                ▶ Clique sur Suppression pour finaliser.
                                ▶ Tu peux, si tu le souhaites, te servir des Options facultatives.
                                ▶ Clique sur Quitter, pour que le rapport puisse se créer.
                                ▶ Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse

                                Désactive et réactive la Restauration du système :

                                Le fait de faire cette manipulation va supprimer tous les virus qui auraient pu se loger dans les
                                points de restauration que tu avais créé auparavant.. Il est donc recommandé de la faire :

                                Voici un tutoriel qui t expliquera comment désactiver et réactiver la restauration du système.

                                Tu peux mettre ton problème résolu !! Comment mettre résolu ??
                                0