[PROBLEME] PROGRAMME SUSPECT ???

Bonjour,

Depuis quelques temps, des programmes et fenetres s'ouvrent sur mon ordinateur de manière intempestive
Un programme nommé "k.exe" apparait à l'écran dans une fentre Vista.
En effet, une fenetre s'ouvre en disant :
"un probleme a fait que le programme a cessé de fonctionner correctement... Fermer le programme"
Ou Alors des fenêtres noires de commande s'ouvrent pendant quelques secondes toute seule...

Plus récemment, en augmentant le niveau de recherche de mon antivirus à chaque fois que mon PC s'allume, antivir m'annonce un virus sur ces fichiers :
C:\Users\Maxime\AppData\Roaming\msnf3\syslpt.exe
et sur ce logiciel :
SPR/PSW.Messen.BH.6

Si quelqu'un pouvait m'aider à nettoyer mon PC ca serait très sympathique : D

PS : J'utilise Antivir, spybot destroy mais également régulièrement Ccleaner

Merci d'avance pour votre aide ; )
Configuration: Windows Vista
Firefox 3.0.11

19 réponses

  1. Voici le rapport :

    SmitFraudFix v2.423

    Scan done at 9:40:27,76, 19/07/2009
    Run from C:\Windows\System32\SmitfraudFix
    OS: Microsoft Windows [version 6.0.6001] - Windows_NT
    The filesystem type is NTFS
    Fix run in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Killing process

    »»»»»»»»»»»»»»»»»»»»»»»» hosts

    ::1 localhost

    127.0.0.1 myomemo.com
    127.0.0.1 www.myomemo.com

    »»»»»»»»»»»»»»»»»»»»»»»» VACFix

    VACFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

    S!Ri's WS2Fix: LSP not Found.

    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

    IEDFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

    Agent.OMZ.Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

    404Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» RK

    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{67B5A412-8B12-4D65-98E9-560BDC88673F}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{67B5A412-8B12-4D65-98E9-560BDC88673F}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS2\Services\Tcpip\..\{67B5A412-8B12-4D65-98E9-560BDC88673F}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, following keys are not inevitably infected!!!

    »»»»»»»»»»»»»»»»»»»»»»»» RK.2

    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

    Registry Cleaning done.

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» End
    0
    1. redémarre le pc sans échec
      Pour démarrer en mode sans échec

      >>1--démarre ou redémarre l’ordinateur. L'affichage affichent la progression du BIOS,
      >>2--A la fin du chargement du BIOS, tapote sur la touche F8 de ton clavier. jusqu'à ce que le menu des options avancées de Windows apparaisse. Si tu appuie sur la touche F8 trop tôt, il est possible que certains ordinateurs affichent le message "erreur clavier". Dans ce cas redémarre l'ordinateur et essaye de nouveau.
      >>4--En utilisant les flèches de ton clavier, sélectionne « Mode sans échec » dans le menu puis appuie sur Entrée.
      Aide ici:

      http://www.commentcamarche.net/faq/sujet 5004 windows demarrage en mode sans echec#demarrer en mode sans echec avec windows xp

      une fois dans le bureau
      redémarre Smitfraud " et fait l'option nettoyage "2"
      Réponds O aux deux questions suivantes: si il les pose
      Voulez-vous nettoyer le registre ?
      Corriger le fichier infecté ?
      Un rapport.txt sera généré et tu le sauve sous ton bureau pour le retrouver plus tard
      et tu redémarre le pc
      enfin tu le postes le rapport
      0
      1. Le post Navilog :

        Fix Navipromo version 4.0.1 commencé le 18/07/2009 10:42:59,96

        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
        !!! Postez ce rapport sur le forum pour le faire analyser !!!

        Outil exécuté depuis C:\Program Files\navilog1

        Mise à jour le 14.07.2009 à 14h00 par IL-MAFIOSO

        Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
        X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz )
        BIOS : BIOS Date: 11/23/07 18:30:01 Ver: 08.00.15
        USER : Maxime ( Administrator )
        BOOT : Normal boot

        C:\ (Local Disk) - NTFS - Total:228 Go (Free:115 Go)
        D:\ (Local Disk) - NTFS - Total:227 Go (Free:81 Go)
        E:\ (CD or DVD)
        F:\ (CD or DVD)
        G:\ (USB)
        H:\ (USB)
        I:\ (USB)
        J:\ (USB)
        K:\ (CD or DVD)

        Recherche executée en mode normal

        [b]Aucune Infection Navipromo/Egdaccess trouvé/b

        *** Scan terminé 18/07/2009 10:54:17,68 ***
        0
        1. Voici le rapport de Toolbar S&D :

          -----------\\ ToolBar S&D 1.2.8 XP/Vista

          Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
          X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz )
          BIOS : BIOS Date: 11/23/07 18:30:01 Ver: 08.00.15
          USER : Maxime ( Administrator )
          BOOT : Normal boot
          C:\ (Local Disk) - NTFS - Total:228 Go (Free:115 Go)
          D:\ (Local Disk) - NTFS - Total:227 Go (Free:81 Go)
          E:\ (CD or DVD)
          F:\ (CD or DVD)
          G:\ (USB)
          H:\ (USB)
          I:\ (USB)
          J:\ (USB)
          K:\ (CD or DVD)

          "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
          Option : [1] ( 18/07/2009|10:36 )

          [ UAC => 0 ]

          -----------\\ Recherche de Fichiers / Dossiers ...

          -----------\\ [..\Internet Explorer\Main]

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
          "Start Page"="https://www.google.fr/?gws_rd=ssl"
          "SEARCH PAGE"="http://fr.rd.yahoo.com/customize/ycomp/defaults/sp/*https://fr.yahoo.com/"
          "Local Page"="C:\\Windows\\system32\\blank.htm"
          "SearchMigratedDefaultURL"="https://search.yahoo.com/web{searchTerms}&ei=utf-8&fr=b1ie7"
          "Url"="https://www.msn.com/fr-fr/actualite/"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
          "Start Page"="https://fr.yahoo.com/"
          "Default_Page_URL"="https://fr.yahoo.com/"
          "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

          --------------------\\ Recherche d'autres infections

          --------------------\\ Cracks & Keygens ..

          C:\Users\Maxime\Desktop\pes2009\Crack
          C:\Users\Maxime\Desktop\pes2009\Crack\pes2009.exe

          [ UAC => 1 ]

          1 - "C:\ToolBar SD\TB_1.txt" - 18/07/2009|10:37 - Option : [1]

          -----------\\ Fin du rapport a 10:37:05,73
          0
          1. Désolé pour le retard mais je n'ai pas eu beaucoup de temps ces temps ci ...

            Voici pour le rapport de SmitFrauFix :

            SmitFraudFix v2.423

            Scan done at 10:30:45,15, 18/07/2009
            Run from C:\Users\Maxime\Desktop\SmitfraudFix
            OS: Microsoft Windows [version 6.0.6001] - Windows_NT
            The filesystem type is NTFS
            Fix run in normal mode

            »»»»»»»»»»»»»»»»»»»»»»»» Process

            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\SLsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\spoolsv.exe
            C:\Program Files\Avira\AntiVir Desktop\sched.exe
            C:\Program Files\Avira\AntiVir Desktop\avguard.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\Dwm.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\Explorer.EXE
            C:\Windows\system32\taskeng.exe
            C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
            C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
            C:\Windows\RtHDVCpl.exe
            C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
            C:\Acer\Empowering Technology\SysMonitor.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\nvraidservice.exe
            C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\TeamViewer3\TeamViewer_Host.exe
            C:\Windows\System32\svchost.exe
            C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe
            C:\Windows\system32\SearchIndexer.exe
            C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
            C:\Program Files\Common Files\Real\Update_OB\realsched.exe
            C:\Windows\System32\rundll32.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
            C:\Windows\system32\WUDFHost.exe
            C:\Windows\system32\wbem\wmiprvse.exe
            C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
            C:\Program Files\Winamp\winampa.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Windows\ehome\ehtray.exe
            C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
            C:\Users\Maxime\AppData\Roaming\tmobd.exe
            C:\Users\Maxime\AppData\Roaming\finalssf\fssf.exe
            C:\Program Files\DAEMON Tools Lite\daemon.exe
            C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\Program Files\OpenOffice.org 3\program\soffice.exe
            C:\Windows\ehome\ehmsas.exe
            C:\Windows\system32\wbem\unsecapp.exe
            C:\Windows\system32\wbem\wmiprvse.exe
            C:\Program Files\OpenOffice.org 3\program\soffice.bin
            C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
            C:\Windows\System32\mobsync.exe
            C:\Users\Maxime\AppData\Roaming\tmobd.exe
            C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
            C:\Windows\system32\SearchProtocolHost.exe
            C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
            C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Windows\system32\wuauclt.exe
            C:\Windows\servicing\TrustedInstaller.exe
            C:\Windows\system32\SearchFilterHost.exe
            C:\Windows\system32\conime.exe
            C:\Users\Maxime\Desktop\SmitfraudFix\Policies.exe
            C:\Windows\system32\cmd.exe

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            »»»»»»»»»»»»»»»»»»»»»»»» C:\

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Maxime

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Maxime\AppData\Local\Temp

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Maxime\Application Data

            »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Maxime\FAVORI~1

            »»»»»»»»»»»»»»»»»»»»»»»» Desktop

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

            »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

            »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

            »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
            !!!Attention, following keys are not inevitably infected!!!

            o4Patch
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
            !!!Attention, following keys are not inevitably infected!!!

            IEDFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
            !!!Attention, following keys are not inevitably infected!!!

            Agent.OMZ.Fix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» VACFix
            !!!Attention, following keys are not inevitably infected!!!

            VACFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
            !!!Attention, following keys are not inevitably infected!!!

            404Fix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, following keys are not inevitably infected!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
            !!!Attention, following keys are not inevitably infected!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLs"=""
            "LoadAppInit_DLLs"=dword:00000000

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
            !!!Attention, following keys are not inevitably infected!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "Userinit"="C:\\Windows\\system32\\userinit.exe,"

            »»»»»»»»»»»»»»»»»»»»»»»» RK

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            Description: NVIDIA nForce Networking Controller
            DNS Server Search Order: 192.168.1.1

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{67B5A412-8B12-4D65-98E9-560BDC88673F}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{67B5A412-8B12-4D65-98E9-560BDC88673F}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS2\Services\Tcpip\..\{67B5A412-8B12-4D65-98E9-560BDC88673F}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

            »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

            »»»»»»»»»»»»»»»»»»»»»»»» End
            0
            1. bon on va chercher dans plusieurs directions
              suit cette procedure , tu en a pour un moment
              --------------------------------------------------------
              1 Désactivez le Contrôle d'Accès Utilisateur VISTA

              Pour cela,
              --> déroulez le menu Vista,
              -->choisirPanneau de configuration,
              -->clique sur Comptes d'utilisateurs et protection des utilisateurs
              -->puis sur Comptes d'utilisateur.
              Clique sur la mention Activer ou désactiver le contrôle des comptes utilisateurs.
              -->Clique une dernière fois sur Continuer pour confirmer.
              -->Décoche Utiliser le contrôle des comptes utilisateurs pour vous aider à protéger votre ordinateur,
              -->clique sur OK puis sur le bouton Redémarrer maintenant.
              --------------------------------------------------------
              2 Télécharge SmitfraudFix : http://siri.urz.free.fr/Fix/SmitfraudFix.exe
              http://siri.urz.free.fr/Fix/SmitfraudFix.php
              - Enregistre-le sur le bureau

              - Double-clique sur SmitfraudFix.exe et choisis l'option 1 puis Entrée , si ca ne fonctionne pas clic droit et demarrer en tant qu' administrateur

              - Un rapport sera généré, poste-le dans ta prochaine réponse stp.
              ----------------------------------------------------------
              3 Toolbar-S&D
              Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
              https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

              * Lance l'installation du programme en exécutant le fichier téléchargé.
              * Double-clique maintenant sur le raccourci de Toolbar-S&D.
              * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
              * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
              * Poste le rapport généré. (C:\TB.txt)
              -------------------------------------------------------------------------

              4 Faire un clic droit sur ce lien : http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
              Enregistrez la cible (du lien) sous... et enregistrez-le sur le bureau.
              Ensuite double cliquer sur navilog1.exe pour lancer l'installation.
              Une fois l'installation terminée, Faire un clic-droit sur le raccourci Navilog1 présent sur le bureau et choisir Exécuter en tant qu'administrateur
              Arriver au menu principal, choisir l'option 1 et valider.
              Patientez jusqu'au message : Analyse Termine le ...
              Appuyer sur une touche, le blocnote s'ouvre, enregistrer le rapport manière à le retrouver.
              Le rapport fixnavi.txt est en outre sauvegardé dans %systemdrive%.
              __________________________________

              Tutoriel ici pour t'aider : http://www.malekal.com//tutorial_SmitFraudfix.php
              0
              1. Non en réalité, rien à changer ...
                J'ai toujours l'alerte Syslpt.exe qui a chaque fois ouvre deux fenetres exactement identique... (ce que je ne comprends pas)
                Sinon J'ai également cette alerte pour un autre programme qui s'ouvre :
                https://www.imagup.com
                Elle s'ouvre généralement 3 fois...
                0
                1. Non il n me semble pas ...
                  Mais j'en ai de nouvelles maintenant
                  0
                  1. a tu toujour une alerte virus sur syslpt.exe?
                    0
                    1. Malwarebytes' Anti-Malware 1.38
                      Version de la base de données: 2358
                      Windows 6.0.6001 Service Pack 1

                      01/07/2009 21:15:46
                      mbam-log-2009-07-01 (21-15-46).txt

                      Type de recherche: Examen rapide
                      Eléments examinés: 82125
                      Temps écoulé: 3 minute(s), 15 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 1
                      Clé(s) du Registre infectée(s): 0
                      Valeur(s) du Registre infectée(s): 0
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 2

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      C:\Users\Maxime\AppData\Roaming\python25.dll (Trojan.Agent) -> Delete on reboot.

                      Clé(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Valeur(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      c:\Users\Maxime\AppData\Roaming\pf.exe (Password.Stealer) -> Quarantined and deleted successfully.
                      c:\Users\Maxime\AppData\Roaming\python25.dll (Trojan.Agent) -> Delete on reboot.
                      0
                      1. Trojan.DNSChanger-Codec ?
                        humm
                        télécharge Malwarebyte's ici http://www.malwarebytes.org/mbam/program/mbam-setup.exe
                        le programme va se mettre automatiquement a jour.
                        S'il manque le fichier COMCTL32.OCX, vous pourrez le télécharger ici
                        https://www.malekal.com/tutorial-aboutbuster/
                        Une fois a jour, le programme va se lancer; click sur l´onglet paramètre, et coche la case : "Arrêter internet explorer pendant la suppression".

                        Click maintenant sur l´onglet recherche et coche la case : "executer un examen rapide".

                        Puis click sur "rechercher".

                        Laisse le scanner le pc...

                        Si des éléments on été trouvés > click sur supprimer la sélection.

                        si il t´es demandé de redémarrer > click sur "yes".

                        A la fin un rapport va s´ouvrir; sauvegarde le de manière a le retrouver en vu de le poster sur le forum.

                        Copie et colle le rapport stp.

                        PS : les rapport sont aussi rangé dans l onglet rapport/log
                        0
                        1. SUPERAntiSpyware Scan Log
                          https://www.superantispyware.com/

                          Generated 07/01/2009 at 12:32 PM

                          Application Version : 4.26.1006

                          Core Rules Database Version : 3964
                          Trace Rules Database Version: 1905

                          Scan type : Complete Scan
                          Total Scan Time : 00:34:38

                          Memory items scanned : 851
                          Memory threats detected : 0
                          Registry items scanned : 8859
                          Registry threats detected : 1
                          File items scanned : 31671
                          File threats detected : 10

                          Adware.Tracking Cookie
                          C:\Users\Maxime\AppData\Roaming\Microsoft\Windows\Cookies\maxime@bs.serving-sys[3].txt
                          C:\Users\Maxime\AppData\Roaming\Microsoft\Windows\Cookies\maxime@smartadserver[2].txt
                          C:\Users\Maxime\AppData\Roaming\Microsoft\Windows\Cookies\maxime@serving-sys[3].txt
                          C:\Users\Maxime\AppData\Roaming\Microsoft\Windows\Cookies\maxime@yourmedia[1].txt
                          C:\Users\Maxime\AppData\Roaming\Microsoft\Windows\Cookies\Low\maxime@bs.serving-sys[2].txt
                          C:\Users\Maxime\AppData\Roaming\Microsoft\Windows\Cookies\Low\maxime@yourmedia[1].txt
                          C:\Users\Maxime\AppData\Roaming\Microsoft\Windows\Cookies\Low\maxime@serving-sys[2].txt
                          C:\Users\Maxime\AppData\Roaming\Microsoft\Windows\Cookies\Low\maxime@xiti[1].txt
                          C:\Users\Maxime\AppData\Roaming\Microsoft\Windows\Cookies\maxime@bs.serving-sys[1].txt
                          C:\Users\Maxime\AppData\Roaming\Microsoft\Windows\Cookies\maxime@serving-sys[1].txt

                          Trojan.DNSChanger-Codec
                          HKU\S-1-5-21-101066567-1177660795-1296244435-1000\Software\fcn
                          0
                          1. rien de precis , des trucs comme fssf.exe ? , normalement c'est fsecure, et tu a avira

                            0
                            1. En cours ...
                              Merci de votre aide ; )

                              Des choses suspectes dans le 1e rapport ? Si oui lesquelles ?
                              0
                              1. Voici le Log :

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 11:29:14, on 01/07/2009
                                Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                MSIE: Internet Explorer v7.00 (7.00.6001.18248)
                                Boot mode: Normal

                                Running processes:
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\Explorer.EXE
                                C:\Program Files\Windows Defender\MSASCui.exe
                                C:\Windows\RtHDVCpl.exe
                                C:\Acer\Empowering Technology\SysMonitor.exe
                                C:\Windows\System32\nvraidservice.exe
                                C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe
                                C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
                                C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                C:\Windows\System32\rundll32.exe
                                C:\Windows\System32\rundll32.exe
                                C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                                C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
                                C:\Program Files\Winamp\winampa.exe
                                C:\Program Files\iTunes\iTunesHelper.exe
                                C:\Program Files\Java\jre6\bin\jusched.exe
                                C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                                C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                C:\Program Files\Windows Sidebar\sidebar.exe
                                C:\Windows\ehome\ehtray.exe
                                C:\Users\Maxime\AppData\Roaming\tmobd.exe
                                C:\Users\Maxime\AppData\Roaming\finalssf\fssf.exe
                                C:\Program Files\DAEMON Tools Lite\daemon.exe
                                C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
                                C:\Windows\ehome\ehmsas.exe
                                C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                C:\Program Files\OpenOffice.org 3\program\soffice.exe
                                C:\Program Files\OpenOffice.org 3\program\soffice.bin
                                C:\Users\Maxime\AppData\Roaming\tmobd.exe
                                C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                                C:\Windows\System32\mobsync.exe
                                C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
                                C:\Windows\system32\wbem\unsecapp.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
                                C:\Program Files\Mozilla Firefox\firefox.exe
                                C:\Windows\system32\wuauclt.exe
                                C:\Windows\system32\conime.exe
                                C:\Users\Maxime\AppData\Roaming\msnf3\ms.exe
                                C:\Windows\system32\SearchFilterHost.exe
                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ycomp/defaults/sp/*https://fr.yahoo.com/
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
                                O1 - Hosts: ::1 localhost
                                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
                                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                                O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
                                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
                                O4 - HKLM\..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
                                O4 - HKLM\..\Run: [Apanel] C:\ACERSW\config\NewSetApanel.cmd
                                O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
                                O4 - HKLM\..\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
                                O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                                O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe"
                                O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
                                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                                O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                O4 - HKLM\..\Run: [Blubster] C:\Program Files\Blubster\Blubster.exe SILENT
                                O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                                O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
                                O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                                O4 - HKLM\..\Run: [pdfw] C:\Program Files\Amic Utilities\PDF Writer Pro\pdfwload.exe
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                O4 - HKCU\..\Run: [tmobd] C:\Users\Maxime\AppData\Roaming\tmobd.exe
                                O4 - HKCU\..\Run: [ssf] C:\Users\Maxime\AppData\Roaming\finalssf\fssf.exe
                                O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                                O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
                                O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
                                O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                                O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O13 - Gopher Prefix:
                                O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
                                O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                                O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
                                O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/DigWXMSN.cab
                                O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                                O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
                                O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                                O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
                                O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                                O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                                O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                                O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                                O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Host.exe
                                0
                                1. télécharge hijackthis http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
                                  >> enregistre la cible sous .... "le bureau" renomme HJTInstall.exe en par exemple HJT.exe

                                  >> Fais un double-clic sur "HJT.exe" afin de lancer l'installation

                                  >> Clique sur Install ensuite sur "I Accept"

                                  >> Clique sur" Do a scan system and save log file"

                                  >> Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse

                                  http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
                                  0