Encore Savekeeper

Bonjour,

J'ai des pb avec un spyware nommé savekeeper
j'ai lu dans le forum comment erraiquer ce spyware avec malwarebytes

j'ai mis a jour le malwarebytes a jour, je scan, je supprime les fichiers infectés mais j'ai toujours savekeeper sur mon PC.

ESt ce que quelqu'un peut m'aider svp ...
Configuration: Windows XP Internet Explorer 7.0

22 réponses

  1. Félicitation ! :D

    Mais c'est pas fini une toute petite touche ^^

    Ont va se débarrasser des outils qu'ont a utiliser pour la désinfection ,

    ~~~~~~~~ToolsCleaner~~~~~~~~~~

    ◆ Installe sur ton bureaux Toolscleaner depuis le lien du haut
    ◆ Double-clique dessus, puis clique sur Recherche --> Le programme va chercher les utilitaires installés

    ((!)) Il se peut que la fenêtre devienne blanche pendant le scan, c'est normal ! ((!))

    Copie-colle le contenu du rapport qui apparait dans la fenêtre blanche.

    * Lorsque la recherche est terminée ToolsCleaner affiche une liste des différents outils trouvés, clique sur "Suppression" afin de les supprimer.

    ==> Vide ta corbeille
    ==> Quitte le programme

    Et enfin postes le rapport qui se trouve ici >>> C:\TCleaner.txt
    0
    1. laisse c'est bon
      j'ai eu la maj de malwaure d'aujourd'hui et ca m'a viré ce spyware
      plus d emessage savekeeper

      merci pour ton aide, top ce log
      0
      1. Comment sait tu qu'il ya savekeeper dans ton ordinateur ?
        0
        1. rien n'y fait savekeeper toutjours présent sur ma bécane
          rien de detecter lors du scan

          Malwarebytes' Anti-Malware 1.40
          Version de la base de données: 2734
          Windows 5.1.2600 Service Pack 2

          09/09/2009 21:51:42
          mbam-log-2009-09-09 (21-51-42).txt

          Type de recherche: Examen complet (C:\|E:\|)
          Eléments examinés: 181761
          Temps écoulé: 1 hour(s), 14 minute(s), 22 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 0
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 0

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          (Aucun élément nuisible détecté)
          0
          1. Procéde par étapes :

            (!) Faire une mise à jour du logiciel avant de le manipuler (!)

            Installe Malwarbytes sur ton bureaux

            ✿✿ Pour installer Malwarbytes clique ici ✿✿

            Sélectionne "Exécuter un examen complet" puis clique sur le bouton Rechercher pour lancer le scan.
            Clique sur le bouton "Lancer l'examen" pour démarrer le scan.
            Clique sur le bouton "Supprimer la sélection" en bas à gauche.
            Un rapport de scan s'ouvre, sélectionne tout copie le et colle le dans ta prochaine réponse.

            ~~~~~~> Tuto Malwarbytes
            0
            1. Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 20:00:41, on 09/09/2009
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v8.00 (8.00.6001.18702)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\UberIcon\UberIcon Manager.exe
              C:\Windows\System32\VisualTaskTips.exe
              C:\Program Files\styler\Styler.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\WINDOWS\TBPanel.exe
              C:\WINDOWS\system32\RUNDLL32.EXE
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\WINDOWS\Mixer.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\Spyware Doctor\pctsTray.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
              C:\WINDOWS\system32\z4kfcdkx.exe
              C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
              C:\WINDOWS\system32\nvsvc32.exe
              C:\Program Files\Spyware Doctor\pctsAuxs.exe
              C:\Program Files\Spyware Doctor\pctsSvc.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
              C:\WINDOWS\System32\alg.exe
              C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
              C:\Program Files\Outlook Express\msimn.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Documents and Settings\Administrateur\Bureau\HiJackThis.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Ultimate Edition
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
              O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\styler\TB\StylerTB.dll
              O4 - HKLM\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe"
              O4 - HKLM\..\Run: [VisualTaskTips] C:\Windows\System32\VisualTaskTips.exe
              O4 - HKLM\..\Run: [Vistadrv] C:\WINDOWS\system32\Vistadrive\vsdrv.exe
              O4 - HKLM\..\Run: [TransBar] C:\Windows\System32\TransBar.exe /s
              O4 - HKLM\..\Run: [Styler] C:\Program Files\styler\Styler.exe
              O4 - HKLM\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
              O4 - HKLM\..\Run: [Gainward] C:\WINDOWS\TBPanel.exe /A
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
              O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
              O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
              O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
              O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
              O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
              O4 - HKCU\..\Run: [z4kfcdkx.exe] C:\WINDOWS\system32\z4kfcdkx.exe
              O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
              O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
              O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - https://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{B09DEB9C-8B1F-463C-9FBD-376ECE76F418}: NameServer = 212.27.53.252,212.27.54.252
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
              O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
              O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
              O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
              O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
              O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
              0
              1. Refait un rapport Hijackthis pour voir ...
                0
                1. yo m're voila !!

                  j'ai fait la manip en mode sans echec
                  voila le rapport:

                  SmitFraudFix v2.423

                  Rapport fait à 19:35:46,18, 09/09/2009
                  Executé à partir de C:\Documents and Settings\Administrateur\Bureau\SmitfraudFix
                  OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                  Le type du système de fichiers est NTFS
                  Fix executé en mode sans echec

                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                  127.0.0.1 localhost

                  »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                  VACFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                  S!Ri's WS2Fix: LSP not Found.

                  »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                  GenericRenosFix by S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                  »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                  IEDFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

                  Agent.OMZ.Fix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                  404Fix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» RK

                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{B09DEB9C-8B1F-463C-9FBD-376ECE76F418}: NameServer=212.27.53.252,212.27.54.252
                  HKLM\SYSTEM\CS1\Services\Tcpip\..\{B09DEB9C-8B1F-463C-9FBD-376ECE76F418}: NameServer=212.27.53.252,212.27.54.252
                  HKLM\SYSTEM\CS2\Services\Tcpip\..\{B09DEB9C-8B1F-463C-9FBD-376ECE76F418}: NameServer=212.27.53.252,212.27.54.252

                  »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  "System"=""

                  »»»»»»»»»»»»»»»»»»»»»»»» RK.2

                  »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                  Nettoyage terminé.

                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Fin
                  0
                  1. Ok sans probléme =)
                    0
                    1. je vais dormir j'en peux plus
                      on continu demain stp

                      merci pour ton aide
                      0
                      1. Redémarre en mode sans echec

                        Pour redémarrer en mode sans échec, pour cela, redémarre l'ordinateur, avant le logo Windows, tapote sur la touche F8, un menu va apparaître, choisis Mode sans échec et appuye sur la touche entrée du clavier. Tu dois tapoter sur la touche F8 seulement après le changement du premier écran, si tu le faites trop tôt, t'obtiendras , un "boot menu".

                        Relance Smitfraudix

                        --> Mais cette fois choisit l'option 2 ..

                        Attendre la fin du scan ...

                        * SmitFraudfix peut te demander si tu désire nettoyer le registre, répond oui à la question, pour cela tape sur la touche o puis valide par la touche entrée.

                        Une fois le nettoyage terminé, SmitFraudfix ouvre le rapport de nettoyage sur le bloc-note.

                        (!) La connexion internet ne fonctionne pas en mode sans échec, enregistrez le rapport sur le bureau.(!)

                        Copie le rapport et colle son intégralité dans ta prochaine reponse ...
                        0
                        1. SmitFraudFix v2.423

                          Rapport fait à 2:53:33,39, 09/09/2009
                          Executé à partir de C:\Documents and Settings\Administrateur\Bureau\SmitfraudFix
                          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                          Le type du système de fichiers est NTFS
                          Fix executé en mode normal

                          »»»»»»»»»»»»»»»»»»»»»»»» Process

                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\UberIcon\UberIcon Manager.exe
                          C:\Windows\System32\VisualTaskTips.exe
                          C:\Program Files\styler\Styler.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\WINDOWS\TBPanel.exe
                          C:\WINDOWS\system32\RUNDLL32.EXE
                          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          C:\WINDOWS\Mixer.exe
                          C:\Program Files\Java\jre6\bin\jusched.exe
                          C:\Program Files\Spyware Doctor\pctsTray.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
                          C:\WINDOWS\system32\z4kfcdkx.exe
                          C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Java\jre6\bin\jqs.exe
                          C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
                          C:\WINDOWS\system32\nvsvc32.exe
                          C:\Program Files\Spyware Doctor\pctsAuxs.exe
                          C:\Program Files\Spyware Doctor\pctsSvc.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\WINDOWS\System32\alg.exe
                          C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
                          C:\Program Files\Outlook Express\msimn.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\WINDOWS\system32\cmd.exe
                          C:\WINDOWS\system32\wbem\wmiprvse.exe

                          »»»»»»»»»»»»»»»»»»»»»»»» hosts

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrateur

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrateur\Application Data

                          »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\Favoris

                          »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                          »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                          »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                          "Source"="About:Home"
                          "SubscribedURL"="About:Home"
                          "FriendlyName"="Ma page d'accueil"

                          »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          o4Patch
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          IEDFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          Agent.OMZ.Fix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          VACFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          404Fix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                          "AppInit_DLLs"=""

                          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                          "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

                          »»»»»»»»»»»»»»»»»»»»»»»» RK

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                          "System"=""

                          »»»»»»»»»»»»»»»»»»»»»»»» DNS

                          Description: NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter - Miniport d'ordonnancement de paquets
                          DNS Server Search Order: 212.27.53.252
                          DNS Server Search Order: 212.27.54.252

                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{B09DEB9C-8B1F-463C-9FBD-376ECE76F418}: NameServer=212.27.53.252,212.27.54.252
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{B09DEB9C-8B1F-463C-9FBD-376ECE76F418}: NameServer=212.27.53.252,212.27.54.252
                          HKLM\SYSTEM\CS2\Services\Tcpip\..\{B09DEB9C-8B1F-463C-9FBD-376ECE76F418}: NameServer=212.27.53.252,212.27.54.252

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                          »»»»»»»»»»»»»»»»»»»»»»»» Fin
                          0
                          1. ► Installe sur ton bureaux Smitfraudix

                            Clique ici pour installer Smitfraudix

                            ● Fais un clic droit puis Extraire tout sur le fichier SmitfraudFix.zip
                            ● Ouvre le dossier SmitfraudFix double clic surSmitfraudFix.cmd
                            ● Choisis l'option 1 (Recherche) et appuie sur Entrée
                            ● Réponds (Oui) aux deux questions suivantes si elles sont posées
                            Un rapport sera généré copie/colle le contenu du rapport ici

                            # Tuto
                            0
                            1. j'ai toujours ce foutu de savekeeper sur mon PC

                              ci joint le log
                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 02:41:39, on 09/09/2009
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\csrss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\UberIcon\UberIcon Manager.exe
                              C:\Windows\System32\VisualTaskTips.exe
                              C:\Program Files\styler\Styler.exe
                              C:\Program Files\Windows Sidebar\sidebar.exe
                              C:\WINDOWS\TBPanel.exe
                              C:\WINDOWS\system32\RUNDLL32.EXE
                              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              C:\WINDOWS\Mixer.exe
                              C:\Program Files\Java\jre6\bin\jusched.exe
                              C:\Program Files\Spyware Doctor\pctsTray.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
                              C:\WINDOWS\system32\z4kfcdkx.exe
                              C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
                              C:\Program Files\Windows Sidebar\sidebar.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Java\jre6\bin\jqs.exe
                              C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
                              C:\WINDOWS\system32\nvsvc32.exe
                              C:\Program Files\Spyware Doctor\pctsAuxs.exe
                              C:\Program Files\Spyware Doctor\pctsSvc.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
                              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              C:\WINDOWS\System32\alg.exe
                              C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
                              C:\Program Files\Outlook Express\msimn.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\WINDOWS\system32\NOTEPAD.EXE
                              C:\Documents and Settings\Administrateur\Bureau\HiJackThis.exe
                              C:\WINDOWS\system32\wbem\wmiprvse.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr/keyword/%s
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/toolbar/ie8/sidebar.html
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/toolbar/ie8/sidebar.html
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Ultimate Edition
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                              O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\styler\TB\StylerTB.dll
                              O4 - HKLM\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe"
                              O4 - HKLM\..\Run: [VisualTaskTips] C:\Windows\System32\VisualTaskTips.exe
                              O4 - HKLM\..\Run: [Vistadrv] C:\WINDOWS\system32\Vistadrive\vsdrv.exe
                              O4 - HKLM\..\Run: [TransBar] C:\Windows\System32\TransBar.exe /s
                              O4 - HKLM\..\Run: [Styler] C:\Program Files\styler\Styler.exe
                              O4 - HKLM\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                              O4 - HKLM\..\Run: [Gainward] C:\WINDOWS\TBPanel.exe /A
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                              O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
                              O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                              O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
                              O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                              O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                              O4 - HKCU\..\Run: [z4kfcdkx.exe] C:\WINDOWS\system32\z4kfcdkx.exe
                              O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
                              O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
                              O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - https://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
                              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                              O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                              O17 - HKLM\System\CCS\Services\Tcpip\..\{B09DEB9C-8B1F-463C-9FBD-376ECE76F418}: NameServer = 212.27.53.252,212.27.54.252
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                              O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
                              O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                              O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                              O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                              O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
                              0
                              1. Ok ,

                                Tu peux me faire un rapport Hijackthis? pour m'assurer ^^'
                                0
                                1. il ya eu 2 trojans de détecté lors du sacn avec spyware doctor
                                  ils ont été supprimés
                                  pas de save keeper détectés
                                  0
                                  1. Ta supprimer Savekeeper ?

                                    Si oui refait un rapport Hijackthis ..
                                    0
                                    1. Tu as supprimé les infections oui ou non ?
                                      0
                                      1. c'est bon j'ai tout supprimé avec spydoctor
                                        0
                                    2. ton lien, c'est pas savekeeper mais spyware doctor
                                      j'ai quand meme installer mais pour supprimer, il faut s'enregistrer...
                                      0
                                      1. ✿ Installe Savekeeper Clique ici pour installer SaveKeeper

                                        ✿ Lance un scan et supprime les infections trouvé ..
                                        0
                                        • 1
                                        • 2