Protection bar

Résolu
Bonjour,
Je suis nouveau sur ce forum et j'espere que quelqu'un pourra m'aider, j'ai la protection bar sur le net et je n'arrive pas a mon débarrasser. Que faire ?

Mon anti virus est Kaspersky.
Le rapport d'analyse est :

C:\Program Files\Video ActiveX Object\iesplugin.dll/PE_Patch, découvert : cheval de Troie Trojan-Downloader.Win32.Zlob.bdi

Merci pour votre aide.
Configuration: Windows XP
Internet Explorer 7.0

13 réponses

  1. Grand fou :$ ... pa d'vant tout l'monde j'suis timide ^^

    Bises (k)
    0
    1. Green t'es un super bon pote, j'voulais encore te le dire :P
      0
      1. Oupsss...
        désolé et merci pour ton aide.
        0
        1. Modérateur
          re

          c'est pas il, c'est elle ;-))

          fais le 1/ et 2/ de ce lien stp

          virus methode preliminaire de desinfection version fr

          @+
          0
          1. Logfile of HijackThis v1.99.1
            Scan saved at 22:09:39, on 06/01/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.5730.0011)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
            C:\WINDOWS\system32\pctspk.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\RunDll32.exe
            C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\Program Files\Lexmark 4300 Series\lxcemon.exe
            C:\Program Files\Lexmark 4300 Series\ezprint.exe
            C:\WINDOWS\system32\LVCOMSX.EXE
            C:\Program Files\Logitech\Video\LogiTray.exe
            C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
            C:\Program Files\DAEMON Tools\daemon.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\ATI Multimedia\main\launchpd.exe
            C:\Program Files\MSN Messenger\MsnMsgr.Exe
            C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
            C:\Program Files\Logitech\Video\FxSvr2.exe
            C:\WINDOWS\system32\lxcecoms.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\WinRAR\WinRAR.exe
            C:\DOCUME~1\Fabrice\LOCALS~1\Temp\Rar$EX00.984\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
            O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
            O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16
            O4 - HKLM\..\Run: [lxcemon.exe] "C:\Program Files\Lexmark 4300 Series\lxcemon.exe"
            O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 4300 Series\ezprint.exe"
            O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
            O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
            O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
            O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
            O4 - HKLM\..\Run: [WhenUSearchWHSE] "C:\Program Files\WhenUSearch\whse.exe"
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
            O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
            O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
            O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
            O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?a5f64f605fe74a658fe510461535bd9e
            O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?a5f64f605fe74a658fe510461535bd9e
            O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O11 - Options group: [INTERNATIONAL] International*
            O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
            O17 - HKLM\System\CCS\Services\Tcpip\..\{EF6565C1-AD06-4A5C-8B7F-475797B3D940}: NameServer = 213.36.80.1 213.36.80.1
            O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
            O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
            O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
            O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
            O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe

            Merci pour ton aide t'es un AS.
            0
            1. SmitFraudFix v2.132

              Rapport fait à 21:58:02,81, 06/01/2007
              Executé à partir de C:\Documents and Settings\Fabrice\Bureau\SmitfraudFix
              OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
              Le type du système de fichiers est NTFS
              Fix executé en mode sans echec

              »»»»»»»»»»»»»»»»»»»»»»»» Avant SmitFraudFix
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
              "{951a98d0-dad6-4a77-8280-a494279a884b}"="beeper"

              [HKEY_CLASSES_ROOT\CLSID\{951a98d0-dad6-4a77-8280-a494279a884b}\InProcServer32]
              @="C:\WINDOWS\system32\vwfps.dll"

              [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{951a98d0-dad6-4a77-8280-a494279a884b}\InProcServer32]
              @="C:\WINDOWS\system32\vwfps.dll"

              »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

              »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

              GenericRenosFix by S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

              C:\DOCUME~1\ALLUSE~1\MENUDM~1\Online Security Guide.url supprimé
              C:\DOCUME~1\ALLUSE~1\MENUDM~1\Security Troubleshooting.url supprimé
              C:\Program Files\Video ActiveX Object\ supprimé

              »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
              "System"=""

              »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

              Nettoyage terminé.

              »»»»»»»»»»»»»»»»»»»»»»»» Après SmitFraudFix
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll

              »»»»»»»»»»»»»»»»»»»»»»»» Fin
              0
              1. Modérateur
                Merci :-)

                # Démarre en mode sans échec :
                Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                (Si F8 ne marche pas utilise la touche F5).
                ----------------------------------------------------------------------------
                # Relance le programme Smitfraud :
                Cette fois choisit l’option 2, répond oui a tous ;
                Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

                ensuite :

                Télécharge ceci sur ton bureau :

                Lien : hijackthis

                Démo : http://pageperso.aol.fr/balltrap34/demohijack.htm

                Choisir l'option "do a scan and a logfile", et faire un copier/coller du rapport ainsi générer sur le forum.

                @+
                0
                1. SmitFraudFix v2.132

                  Rapport fait à 21:21:07,31, 06/01/2007
                  Executé à partir de C:\Documents and Settings\Fabrice\Bureau\SmitfraudFix
                  OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                  Le type du système de fichiers est NTFS
                  Fix executé en mode normal

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Fabrice

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Fabrice\Application Data

                  »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                  C:\DOCUME~1\ALLUSE~1\MENUDM~1\Online Security Guide.url PRESENT !
                  C:\DOCUME~1\ALLUSE~1\MENUDM~1\Security Troubleshooting.url PRESENT !

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Fabrice\Favoris

                  »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                  C:\Program Files\Video ActiveX Object\ PRESENT !

                  »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                  »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                  "Source"="About:Home"
                  "SubscribedURL"="About:Home"
                  "FriendlyName"="Ma page d'accueil"

                  »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                  "{951a98d0-dad6-4a77-8280-a494279a884b}"="beeper"

                  [HKEY_CLASSES_ROOT\CLSID\{951a98d0-dad6-4a77-8280-a494279a884b}\InProcServer32]
                  @="C:\WINDOWS\system32\vwfps.dll"

                  [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{951a98d0-dad6-4a77-8280-a494279a884b}\InProcServer32]
                  @="C:\WINDOWS\system32\vwfps.dll"

                  »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                  "AppInit_DLLs"=""

                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                  "System"=""

                  »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Fin
                  0
                  1. Modérateur
                    re

                    ton rappprt est incomplé !

                    poste en un autre stp

                    ++
                    0
                    1. SmitFraudFix v2.132

                      Rapport fait à 21:21:07,31, 06/01/2007
                      Executé à partir de C:\Documents and Settings\Fabrice\Bureau\SmitfraudFix
                      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                      Le type du système de fichiers est NTFS
                      Fix executé en mode normal

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Fabrice

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Fabrice\Application Data

                      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
                      0
                      1. Modérateur
                        Salut

                        # Télécharge ceci: (merci a S!RI pour ce petit programme).

                        http://siri.urz.free.fr/Fix/SmitfraudFix.zip

                        Exécute le, Double click sur Smitfraudfix.cmd choisit l’option 1,
                        voila a quoi cela ressemble : http://siri.urz.free.fr/Fix/SmitfraudFix.php
                        il va générer un rapport : copie/colle le sur le poste stp.

                        ++
                        0