Problème Antirus 2009 virus

Bonjour,
voila je me suis laisser avoir par un soi disant antivirus "antivirus 2009" mais qui est en fait un virus d'apres ce que j'en ai vue sur la toile.
Ce virus donc m'ouvre des fenêtre intampestives qui disent "You have a security probleme" et m'ouvres des page internet avec des probablement fauses infection sur mon ordinateur ainsi que des pubs .
Je n'arrive bien sur pas a le désinstaler.

J'espere que vous pourrez m'aider, Merci du temps porté a mon sujet et merci a l'avance de votre aide :)

Svsp.
Configuration: Windows Vista
Internet Explorer 7.0

17 réponses

  1. Hello, alors la j'ai eu le même problème que toi va sur panneau de configuration ajout supprimé programme si non
    Ctrl Alt Delete processus términé le processus norton
    0
    1. Salut,

      Ca ne marche pas et je pense avoir plusieur infections. C'est pour que je preferai qu'une personne du "taff" m'aide si possble :)

      En tout cas merci pour l'attention porté a mon sujet :)
      0
      1. Salut et merci ,

        alors voila :

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 14:50:11, on 07/12/2008
        Platform: Windows Vista SP1 (WinNT 6.00.1905)
        MSIE: Internet Explorer v7.00 (7.00.6001.18000)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Adobe\Reader 8.0\Reader\Reader_SL.exe
        C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
        C:\Windows\WindowsMobile\wmdSync.exe
        C:\Windows\System32\regsvr32.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
        C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Users\Fab\AppData\Local\wioecuq.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Users\Fab\AppData\Local\Temp\a.exe
        C:\Program Files\Antivirus 2009\av2009.exe
        C:\Users\Fab\AppData\Local\Temp\~tmpb.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\Users\Fab\AppData\Local\Temp\~tmpc.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
        C:\Windows\System32\mobsync.exe
        C:\Program Files\HP\HP Software Update\HPWUCli.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        O1 - Hosts: ::1 localhost
        O2 - BHO: (no name) - {037C7B8A-151A-49E6-BAED-CC05FCB50328} - C:\Windows\System32\winsrc.dll
        O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: mxlivemedia browser enhancer - {2596C3B3-DDC9-73B0-0E26-78733DF944B2} - C:\Windows\system32\pwwljgsuvinxe.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
        O2 - BHO: searchersmart search enhancer - {7DCF015E-9C98-A46F-C12C-2B8B791F6C7B} - C:\Windows\system32\xcykikhnacjyquo.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
        O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
        O4 - HKLM\..\Run: [SysVContoller32] C:\Windows\System32\svcl32\svcl32.exe
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [WebcamMaxMoniter] "C:\Program Files\WebcamMax\wcmmon.exe" /a
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
        O4 - HKLM\..\Run: [ugciwzcgsmo] C:\Windows\System32\regsvr32.exe /s "C:\Windows\system32\pwwljgsuvinxe.dll"
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [WinButler] C:\Users\Fab\AppData\Roaming\WinButler\WinButler.exe
        O4 - HKCU\..\Run: [SfKg6wIPu] C:\Users\Fab\AppData\Roaming\Microsoft\Windows\fxqtbb.exe
        O4 - HKCU\..\Run: [IMC] C:\Program Files\FriendFinder\FriendFinder Messenger 4\imc.exe
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKCU\..\Run: [wioecuq] "c:\users\fab\appdata\local\wioecuq.exe" wioecuq
        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        O4 - HKCU\..\Run: [Cognac] C:\Users\Fab\AppData\Local\Temp\~tmpb.exe
        O4 - HKCU\..\Run: [MSFox] C:\Users\Fab\AppData\Local\Temp\a.exe
        O4 - HKCU\..\Run: [95732580372545994757110194745893] C:\Program Files\Antivirus 2009\av2009.exe
        O4 - HKCU\..\Run: [ieupdate] "C:\Windows\system32\explorer32.exe"
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
        O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
        O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
        O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
        O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
        O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
        O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
        O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
        O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O13 - Gopher Prefix:
        O15 - Trusted Zone: https://www.seafight.com/
        O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
        O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} - http://h30155.www3.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab
        O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
        O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
        O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
        O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\MSCSPTISRV.exe
        O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AvLib\PACSPTISVR.exe
        O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\SsBeSvc.exe
        O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\SPTISRV.exe
        O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\SSScsiSV.exe
        O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
        O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
        O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\sony\VAIO Event Service\VESMgr.exe
        O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\VMISrv.exe
        O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
        O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
        O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\VmGateway.exe
        O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\UCLS.exe
        O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
        O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
        O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
        O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
        O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
        O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
        0
        1. il capte deja que dal tu met quoi comme bordel sur se bon site
          0
          1. Re,

            ▶ Installe - Télécharge SmitfraudFix (de de S!Ri, balltrap34 et moe31)

            Option:1 => Recherche:

            Double cliquer sur SmitfraudFix.exe

            Sélectionner 1 et pressez =>Entrée dans le menu pour créer

            ▶ un rapport des fichiers responsables de l'infection. Le rapport se trouve à la racine du disque

            système

            C:\rapport.txt

            ==>et colle le rapport génèrer sur le forum.

            *=>Ne pas faire l'option 2 sans un avis d'une personne compétente*<=

            ==>Tutoriel Smitfraudix
            0
            1. Re , :)

              alors voila le scan :

              SmitFraudFix v2.381

              Scan done at 15:05:15,86, 07/12/2008
              Run from C:\Users\Fab\Desktop\SmitfraudFix
              OS: Microsoft Windows [version 6.0.6001] - Windows_NT
              The filesystem type is NTFS
              Fix run in normal mode

              »»»»»»»»»»»»»»»»»»»»»»»» Process

              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\Ati2evxx.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\Ati2evxx.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Windows\System32\spoolsv.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
              C:\Program Files\Adobe\Reader 8.0\Reader\Reader_SL.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              C:\Program Files\Alwil Software\Avast4\ashDisp.exe
              C:\Windows\WindowsMobile\wmdSync.exe
              C:\Windows\System32\regsvr32.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
              C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
              C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              C:\Windows\ehome\ehtray.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Windows\ehome\ehmsas.exe
              C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
              C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
              C:\Program Files\sony\VAIO Event Service\VESMgr.exe
              C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
              C:\Users\Fab\AppData\Local\wioecuq.exe
              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\Program Files\sony\VAIO Event Service\VESMgrSub.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\SearchIndexer.exe
              C:\Users\Fab\AppData\Local\Temp\~tmpb.exe
              C:\Users\Fab\AppData\Local\Temp\a.exe
              C:\Windows\system32\WUDFHost.exe
              C:\Windows\system32\DRIVERS\xaudio.exe
              C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
              C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
              C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
              C:\Program Files\Antivirus 2009\av2009.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
              C:\Users\Fab\AppData\Local\Temp\~tmpc.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Windows\System32\mobsync.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
              C:\Program Files\Windows Media Player\wmpnscfg.exe
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Windows\System32\alg.exe
              C:\Program Files\Windows Media Player\wmpnetwk.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
              C:\Windows\system32\cmd.exe
              C:\Windows\system32\conime.exe
              C:\Windows\system32\SearchProtocolHost.exe
              C:\Windows\system32\SearchFilterHost.exe

              »»»»»»»»»»»»»»»»»»»»»»»» hosts

              »»»»»»»»»»»»»»»»»»»»»»»» C:\

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

              C:\Windows\system32\ieupdates.exe FOUND !
              C:\Windows\system32\msxml71.dll FOUND !
              C:\Windows\system32\winsrc.dll FOUND !

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Fab

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Fab\AppData\Local\Temp

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Fab\Application Data

              C:\Users\Fab\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk FOUND !

              »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Fab\FAVORI~1

              »»»»»»»»»»»»»»»»»»»»»»»» Desktop

              C:\Users\Fab\Desktop\Antivirus 2009.lnk FOUND !

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

              C:\Program Files\Google\googletoolbar1.dll FOUND !

              »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

              »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

              »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
              !!!Attention, following keys are not inevitably infected!!!

              o4Patch
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
              !!!Attention, following keys are not inevitably infected!!!

              IEDFix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» VACFix
              !!!Attention, following keys are not inevitably infected!!!

              VACFix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
              !!!Attention, following keys are not inevitably infected!!!

              404Fix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
              !!!Attention, following keys are not inevitably infected!!!

              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll

              »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
              !!!Attention, following keys are not inevitably infected!!!

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
              "AppInit_DLLs"=""
              "LoadAppInit_DLLs"=dword:00000001

              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
              !!!Attention, following keys are not inevitably infected!!!

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
              "Userinit"="C:\\Windows\\system32\\userinit.exe,"

              »»»»»»»»»»»»»»»»»»»»»»»» RK

              »»»»»»»»»»»»»»»»»»»»»»»» DNS

              Description: Intel(R) PRO/Wireless 3945ABG Network Connection
              DNS Server Search Order: 192.168.1.1

              HKLM\SYSTEM\CCS\Services\Tcpip\..\{1A9096E0-833B-4EAB-88D9-5858FB7D6E6B}: DhcpNameServer=192.168.1.1
              HKLM\SYSTEM\CS1\Services\Tcpip\..\{1A9096E0-833B-4EAB-88D9-5858FB7D6E6B}: DhcpNameServer=192.168.1.1
              HKLM\SYSTEM\CS2\Services\Tcpip\..\{1A9096E0-833B-4EAB-88D9-5858FB7D6E6B}: DhcpNameServer=192.168.1.1
              HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
              HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
              HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

              »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

              »»»»»»»»»»»»»»»»»»»»»»»» End
              0
              1. Re,

                Maintenant fait ceci:

                2) Nettoyage:

                Redemarrer l'ordinateur en mode sans échec:

                Double cliquer sur smitfraudix:

                ▶ Sélectionner 2 et pressez Entrée dans le menu pour supprimer les fichiers responsables de l'infection.

                ▶ A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et pressez Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection:.

                ▶ Le fix déterminera si le fichier wininet.dll est infecté. A la question: Corriger le fichier infecté ? répondre O (oui) et pressez Entrée pour remplacer le fichier corrompu:.

                ▶ Un redemarrage sera peut être necessaire pour terminer la procedure de nettoyage. Le rapport se trouve à la racine du disque système C:\rapport.txt:

                Option::

                * Pour effacer la liste des sites de confiance et sensibles, sélectionner 3 et pressez Entrée dans le menu.

                A la question: Réinitialiser la liste des sites de confiance et sensibles ? répondre O (oui) et pressez Entrée afin de restaurer les zones de confiances et sensibles:.

                :FAUX POSITIF::

                process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                Refait un log hijackthis.

                @+
                0
                1. Ree et merci :)

                  alors voila :

                  SmitFraudFix v2.381

                  Scan done at 15:13:58,71, 07/12/2008
                  Run from C:\Users\Fab\Desktop\SmitfraudFix
                  OS: Microsoft Windows [version 6.0.6001] - Windows_NT
                  The filesystem type is NTFS
                  Fix run in safe mode

                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                  !!!Attention, following keys are not inevitably infected!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                  127.0.0.1 localhost
                  ::1 localhost

                  »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                  VACFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                  S!Ri's WS2Fix: LSP not Found.

                  »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                  GenericRenosFix by S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                  C:\Windows\system32\ieupdates.exe Deleted
                  C:\Windows\system32\msxml71.dll Deleted
                  C:\Windows\system32\winsrc.dll Deleted
                  C:\Users\Fab\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk Deleted
                  C:\Users\Fab\Desktop\Antivirus 2009.lnk Deleted
                  C:\Program Files\Google\googletoolbar1.dll Deleted

                  »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                  IEDFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                  404Fix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» RK

                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{1A9096E0-833B-4EAB-88D9-5858FB7D6E6B}: DhcpNameServer=192.168.1.1
                  HKLM\SYSTEM\CS1\Services\Tcpip\..\{1A9096E0-833B-4EAB-88D9-5858FB7D6E6B}: DhcpNameServer=192.168.1.1
                  HKLM\SYSTEM\CS2\Services\Tcpip\..\{1A9096E0-833B-4EAB-88D9-5858FB7D6E6B}: DhcpNameServer=192.168.1.1
                  HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                  HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                  HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                  »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                  !!!Attention, following keys are not inevitably infected!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                  »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                  Registry Cleaning done.

                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                  !!!Attention, following keys are not inevitably infected!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» End
                  0
                  1. Re,

                    fait un nouvelle hijackthis.STP.

                    @+
                    0
                    1. Re,

                      Voila :

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 15:29:29, on 07/12/2008
                      Platform: Windows Vista SP1 (WinNT 6.00.1905)
                      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                      Boot mode: Normal

                      Running processes:
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                      C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                      C:\Windows\WindowsMobile\wmdSync.exe
                      C:\Windows\System32\regsvr32.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                      C:\Windows\ehome\ehtray.exe
                      C:\Users\Fab\AppData\Local\wioecuq.exe
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Program Files\Antivirus 2009\av2009.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\ehome\ehmsas.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
                      C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
                      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\Windows\System32\mobsync.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                      O1 - Hosts: ::1 localhost
                      O2 - BHO: (no name) - {037C7B8A-151A-49E6-BAED-CC05FCB50328} - C:\Windows\System32\winsrc.dll
                      O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                      O2 - BHO: mxlivemedia browser enhancer - {2596C3B3-DDC9-73B0-0E26-78733DF944B2} - C:\Windows\system32\pwwljgsuvinxe.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                      O2 - BHO: searchersmart search enhancer - {7DCF015E-9C98-A46F-C12C-2B8B791F6C7B} - C:\Windows\system32\xcykikhnacjyquo.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
                      O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
                      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
                      O4 - HKLM\..\Run: [SysVContoller32] C:\Windows\System32\svcl32\svcl32.exe
                      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [WebcamMaxMoniter] "C:\Program Files\WebcamMax\wcmmon.exe" /a
                      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                      O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
                      O4 - HKLM\..\Run: [ugciwzcgsmo] C:\Windows\System32\regsvr32.exe /s "C:\Windows\system32\pwwljgsuvinxe.dll"
                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                      O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                      O4 - HKCU\..\Run: [WinButler] C:\Users\Fab\AppData\Roaming\WinButler\WinButler.exe
                      O4 - HKCU\..\Run: [SfKg6wIPu] C:\Users\Fab\AppData\Roaming\Microsoft\Windows\fxqtbb.exe
                      O4 - HKCU\..\Run: [IMC] C:\Program Files\FriendFinder\FriendFinder Messenger 4\imc.exe
                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                      O4 - HKCU\..\Run: [wioecuq] "c:\users\fab\appdata\local\wioecuq.exe" wioecuq
                      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                      O4 - HKCU\..\Run: [95732580372545994757110194745893] C:\Program Files\Antivirus 2009\av2009.exe
                      O4 - HKCU\..\Run: [ieupdate] "C:\Windows\system32\explorer32.exe"
                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                      O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                      O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                      O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                      O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                      O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                      O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                      O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                      O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
                      O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
                      O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                      O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                      O13 - Gopher Prefix:
                      O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} - http://h30155.www3.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                      O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                      O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\MSCSPTISRV.exe
                      O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AvLib\PACSPTISVR.exe
                      O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\SsBeSvc.exe
                      O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\SPTISRV.exe
                      O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\SSScsiSV.exe
                      O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
                      O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                      O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\sony\VAIO Event Service\VESMgr.exe
                      O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\VMISrv.exe
                      O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                      O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                      O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                      O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\UCLS.exe
                      O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                      O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                      O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                      O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                      O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                      0
                      1. Re,

                        Télécharge et installe MalwareByte's Anti-Malware
                        Malwarebyte

                        Mets le à jour

                        ▶ Double clique sur le raccourci de MalwareByte's Anti-Malware qui est sur le bureau.

                        ▶ Sélectionne Exécuter un examen complet si ce n'est pas déjà fait

                        ▶ clique sur Rechercher

                        ▶ Une fois le scan terminé, une fenêtre s'ouvre, clique sur sur Ok

                        Si MalwareByte's n'a rien détecté, clique sur Ok Un rapport va apparaître ferme-le.

                        Si MalwareByte's a détecté des infections, clique sur Afficher les résultats ensuite sur Supprimer la sélection

                        Enregistre le rapport sur ton Bureau comme cela il sera plus facile à retrouver, poste ensuite ce rapport.

                        Note : Si MalwareByte's a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok

                        Tutoriel pour MalwareByte's
                        0
                        1. Re désolé le scan a été long ,

                          Alors voila

                          Search Navipromo version 3.6.9 commencé le 07/12/2008 à 15:37:32,50

                          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                          !!! Postez ce rapport sur le forum pour le faire analyser !!!
                          !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                          Outil exécuté depuis C:\Program Files\navilog1
                          Session actuelle : "Fab"

                          Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO

                          Microsoft Windows Vista 6.0.6001
                          Internet Explorer : 7.0.6001.18000
                          Système de fichiers : NTFS

                          Recherche executé en mode normal

                          *** Recherche Programmes installés ***

                          *** Recherche dossiers dans "C:\Windows" ***

                          *** Recherche dossiers dans "C:\Program Files" ***

                          ...\MessengerSkinner trouvé !

                          *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                          ...\MessengerSkinner trouvé !

                          *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

                          *** Recherche dossiers dans "C:\ProgramData" ***

                          *** Recherche dossiers dans "c:\users\fab\appdata\roaming\micros~1\windows\startm~1\programs" ***

                          *** Recherche dossiers dans "C:\Users\Fab\AppData\Local\virtualstore\Program Files" ***

                          *** Recherche dossiers dans "C:\Users\Fab\AppData\Roaming" ***

                          ...\MessengerSkinner trouvé !

                          *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                          pour + d'infos : http://www.gmer.net

                          *** Recherche avec GenericNaviSearch ***
                          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                          !!! A vérifier impérativement avant toute suppression manuelle !!!

                          * Recherche dans "C:\Windows\system32" *

                          * Recherche dans "C:\Users\Fab\AppData\Local\Microsoft" *

                          * Recherche dans "C:\Users\Fab\AppData\Local\virtualstore\windows\system32" *

                          * Recherche dans "C:\Users\Fab\AppData\Local" *

                          *** Recherche fichiers ***

                          *** Recherche clés spécifiques dans le Registre ***

                          HKEY_CURRENT_USER\Software\Lanconfig trouvé !

                          *** Module de Recherche complémentaire ***
                          (Recherche fichiers spécifiques)

                          1)Recherche nouveaux fichiers Instant Access :

                          2)Recherche Heuristique :

                          * Dans "C:\Windows\system32" :

                          * Dans "C:\Users\Fab\AppData\Local\Microsoft" :

                          * Dans "C:\Users\Fab\AppData\Local\virtualstore\windows\system32" :

                          * Dans "C:\Users\Fab\AppData\Local" :

                          wioecuq.exe trouvé !
                          wioecuq.dat trouvé !
                          wioecuq_nav.dat trouvé !
                          wioecuq_navps.dat trouvé !

                          3)Recherche Certificats :

                          Certificat Egroup trouvé !
                          Certificat Electronic-Group trouvé !
                          Certificat Montorgueil absent !
                          Certificat OOO-Favorit trouvé !
                          Certificat Sunny-Day-Design-Ltd absent !

                          4)Recherche fichiers connus :

                          *** Analyse terminée le 07/12/2008 à 15:50:02,95 ***
                          0
                          1. Mince désole j'ai pas suprimé , maintenant je re fait un scan fait ce que tu as dit plus haut ?
                            0
                            1. Et voila le scan apres reboot :)

                              Malwarebytes' Anti-Malware 1.31
                              Version de la base de données: 1470
                              Windows 6.0.6001 Service Pack 1

                              07/12/2008 17:52:53
                              mbam-log-2008-12-07 (17-52-37).txt

                              Type de recherche: Examen complet (C:\|D:\|E:\|F:\|)
                              Eléments examinés: 154428
                              Temps écoulé: 1 hour(s), 34 minute(s), 27 second(s)

                              Processus mémoire infecté(s): 1
                              Module(s) mémoire infecté(s): 0
                              Clé(s) du Registre infectée(s): 10
                              Valeur(s) du Registre infectée(s): 3
                              Elément(s) de données du Registre infecté(s): 0
                              Dossier(s) infecté(s): 4
                              Fichier(s) infecté(s): 28

                              Processus mémoire infecté(s):
                              C:\Program Files\Antivirus 2009\av2009.exe (Rogue.Antivirus 2009) -> No action taken.

                              Module(s) mémoire infecté(s):
                              (Aucun élément nuisible détecté)

                              Clé(s) du Registre infectée(s):
                              HKEY_CLASSES_ROOT\CLSID\{037c7b8a-151a-49e6-baed-cc05fcb50328} (Trojan.BHO) -> No action taken.
                              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{037c7b8a-151a-49e6-baed-cc05fcb50328} (Trojan.BHO) -> No action taken.
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{037c7b8a-151a-49e6-baed-cc05fcb50328} (Trojan.BHO) -> No action taken.
                              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\messengerskinner (Rogue.MessengerSkinner) -> No action taken.
                              HKEY_CURRENT_USER\SOFTWARE\Solt Lake Software (Rogue.ProAntispyware2009) -> No action taken.
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2596c3b3-ddc9-73b0-0e26-78733df944b2} (Adware.BHO) -> No action taken.
                              HKEY_CLASSES_ROOT\CLSID\{2596c3b3-ddc9-73b0-0e26-78733df944b2} (Adware.BHO) -> No action taken.
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7dcf015e-9c98-a46f-c12c-2b8b791f6c7b} (Adware.BHO) -> No action taken.
                              HKEY_CLASSES_ROOT\CLSID\{7dcf015e-9c98-a46f-c12c-2b8b791f6c7b} (Adware.BHO) -> No action taken.

                              Valeur(s) du Registre infectée(s):
                              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\95732580372545994757110194745893 (Rogue.Antivirus 2009) -> No action taken.
                              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\IEUpdate (Trojan.Agent) -> No action taken.
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ugciwzcgsmo (Trojan.Agent) -> No action taken.

                              Elément(s) de données du Registre infecté(s):
                              (Aucun élément nuisible détecté)

                              Dossier(s) infecté(s):
                              C:\Program Files\Antivirus 2009 (Rogue.Antivirus 2009) -> No action taken.
                              C:\Program Files\MessengerSkinner (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\download (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\resources (Rogue.MessengerSkinner) -> No action taken.

                              Fichier(s) infecté(s):
                              C:\Users\Fab\Local Settings\Application Data\wioecuq_navps.dat (Adware.Navipromo.H) -> No action taken.
                              C:\Users\Fab\Local Settings\Application Data\wioecuq_nav.dat (Adware.Navipromo.H) -> No action taken.
                              C:\Users\Fab\Local Settings\Application Data\wioecuq.dat (Adware.Navipromo.H) -> No action taken.
                              C:\Users\Fab\Local Settings\Application Data\wioecuq.exe (Adware.Navipromo.H) -> No action taken.
                              C:\Windows\System32\winsrc.dll (Trojan.BHO) -> No action taken.
                              C:\Program Files\MessengerSkinner\MessengerSkinnerDll.dll (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\Antivirus 2009\av2009.exe (Rogue.Antivirus 2009) -> No action taken.
                              C:\Program Files\MessengerSkinner\uninst.exe (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\download\defaultPack.cab (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\resources\appconfig.xml (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\resources\btn.rgn (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\resources\btnBnr.rgn (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\resources\btnIn.rgn (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\resources\btnInNormal.bmp (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\resources\btnInOver.bmp (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\resources\btnNormal.bmp (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\resources\btnNormal.gif (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\resources\btnNormalBnr.bmp (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\resources\btnNormalBnr.gif (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\resources\btnOver.bmp (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\resources\btnOver.gif (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\resources\btnOverBnr.bmp (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\resources\btnOverBnr.gif (Rogue.MessengerSkinner) -> No action taken.
                              C:\Program Files\MessengerSkinner\resources\languages_v2.xml (Rogue.MessengerSkinner) -> No action taken.
                              C:\Windows\System32\explorer32.exe (Trojan.Agent) -> No action taken.
                              C:\Windows\System32\pwwljgsuvinxe.dll (Trojan.Agent) -> No action taken.
                              C:\Windows\System32\ieupdates.exe (Trojan.Agent) -> No action taken.
                              C:\Windows\System32\xcykikhnacjyquo.dll (Adware.BHO) -> No action taken.
                              0
                              1. Re,
                                cette dernier analyse ma enfin enlever mon virus ou du moin il apparait plus :D
                                0
                                1. Houla

                                  bon plusieurs chose , et la première c'est que je vais prendre le relais

                                  relance navilog et fait loption 2, et post le rapport

                                  et ave cmalwarebyte , tu n'a srien supprimé , fait le .
                                  et poste egalement le rapport

                                  0