Trojan.w32.looksky

Résolu
Bonjours a tous .Voila je suis infecté par un trojan.w32.looksky,Avast ne le detect pas et j'ai sans arrêt des fenêtres de pub qui s'ouvrent pour que je prenne tel ou tel antivirus.J'ai donc fais une recherche avec navilog1 et voici le rapport .
Pourriez-vous me dire ce que je dois faire s'il vous plaît???? MERCI

Search Navipromo version 3.0.2 commencé le 13/09/2007 à 23:40:21,00

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Poster ce rapport sur le forum pour le faire analyser !!!
!!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

Fix lancé depuis C:\Program Files\navilog1
Mise a jour le 13.09.2007 a 18h00 by IL-MAFIOSO

Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 6.0.2900.2180

*** Recherche Programmes installes ***

*** Recherche dossiers dans C:\WINDOWS ***

*** Recherche dossiers dans C:\Program Files ***

*** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

*** Recherche dossiers dans C:\Documents and Settings\HP_Propri‚taire\Application Data ***

*** Recherche avec BlackLight Engine/F-secure ***
BlackLight Engine est un produit de F-secure, pour + d'infos :
https://www.f-secure.com/en

F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
======================================

Copyright 2005-2006 F-Secure Corporation. All rights reserved.
This is a beta version. It will expire on 1st of October, 2007.
Version information: 2.2.1064.

[+] Started on 09/13/07 at 23:40:23.
[+] Initializing ...
[+] Starting scan, press Ctrl-C to abort.
[+] Scanning for hidden items ............................................................................................
[+] Scan complete.
[+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
[+] Exited on 09/13/07 at 23:50:17 (return code = 0).

*** Recherche avec GenericNaviSearch ***
!!! Tous Ces résultats peuvent révéler des fichiers légitimes !!!
!!! A verifier impérativement avant toute suppression manuelle !!!

* Scan C:\WINDOWS\system32 *

Fichiers trouvés :

hudcvfbwt.exe trouvé !
pozfaszzu.exe trouvé !
xaddanu.exe trouvé !
xbmfsqqsy.exe trouvé !

Fichiers suspects :

Aucun Fichier suspect trouvé !

*** Recherche fichiers ***

*** Recherche cles registre ***

*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche fichiers connus:

2)Recherche Heuristique :

3)Recherche Certificats :

Certificat Egroup absent !

*** Analyse Terminé le 13/09/2007 à 23:50:29,43 ***
Configuration: Windows XP
Internet Explorer 6.0

27 réponses

Résumé de la discussion

Une infection par trojan.w32.looksky provoque des fenêtres publicitaires persistantes et échappe à Avast, poussant à rechercher des rapports et des méthodes de désinfection adaptées. Le rapport Navilog1 et l’analyse avec F-Secure BlackLight affichent peu de menaces cachées mais listent des fichiers suspects dans system32, nécessitant une vérification approfondie et des outils spécialisés. Des réponses suggèrent d’utiliser SmitfraudFix et des procédures de suppression ciblée, avec des avertissements sur les risques de suppression manuelle et l’examen attentif des résultats. En parallèle, des conseils évoquent la désinstallation de Navilog1 et une vérification régulière des protections-browser, tout en reportant la nécessité d’un avis spécialisé avant toute action majeure.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonjour loulou63

    Ce fut avec plaisir, content d avoir pu te filer un coup de main.

    Bon surf.
    0
    1. Je te remerci pour tout.Mais j'ai les mises a jours windows et tout esr rentré dans l'ordre.

      ENCORE MERCI
      0
      1. Contributeur sécurité
        Bonsoir

        Ca y est je suis debout , je suis au taff ;)

        * Cela tombe bien que tu sois repassé , j avais omis de te faire desinstaller Navilog :

        Pour supprimer Navilog1 du PC, 2 choix :

        - Via ajout/suppression des programmes (Navilog1)
        - Via le fichier uninstall présent dals le dossier %programfiles%\navilog1.

        N'oubliez pas après désinfection de supprimer également le dossier Navilog1 présent dans %programfiles%

        * Pour FireFox, quel est le message d erreur exactement, stp..

        Sinon, tu peux essayer Opera, c est un navigateur sympa aussi ;)

        * Tu peux faire des verifications regulieres des mises a jours differents softs ici stp https://www.flexera.com/products/operations/software-vulnerability-management.html
        entre autre Acrobate reader est a mettre a jour !

        @+
        0
        1. Quand tu te sera reposer pourrais-tu essayer de repondre a ma question poser si-dessus s'il te plaît.
          JE T'EN REMERCI D'AVANCE
          0
          1. Contributeur sécurité
            Re

            Ce fut avec plaisir ;)

            "ah!!j'allais oublier j'ai bien un pare-feu c'estLOOK'N'STOP" --> Exact,autant pour moi, je fatigue, faut que j aille au pieux, c est en partie un copier/coller un peu rapidos et j ai laissé trainer cette remarque qui ne t etait pas destinée..

            Bon surf, salut.
            0
            1. ah!!j'allais oublier j'ai bien un pare-feu c'estLOOK'N'STOP
              0
              1. Merci encore pour tous. Mais je ne peut pas utiliser firefox .j'avais déja posé la question sur se sîtes et par rapport au message d'erreur que j'avais ont m'avait conseillé de supprimer (KB925902)et de le remplacer par le correctif(KB935448).Ce que j'ai fait a plusieurs reprises ,seulement a chaque fois le PC s'éteint et me retelecharge (KB925902)

                Mais bon!!!!! JE TE REMERCIE ENCORE BEAUCOUP
                0
                1. Contributeur sécurité
                  Re
                  Excuse moi pour cette erreur.

                  Re,
                  on termine ;)

                  -- Lance OTMoveIt et clique sur le bouton CLEANUP (ceci supprime toutes les traces des logiciels que nous avons utilisé qui traitent des infections spécifiques et qui sont mis à jour réguliérement, ainsi que OTMoveIt lui meme)

                  Un redémarrage sera nécessaire.
                  -------------------------------------------------------------------------------------------------------------------------------------------------

                  Maintenant que ton PC n'est plus infecté, désactive ta "Restauration système"
                  afin de créer un point de restauration sain en la reactivant a nouveau.


                  Pour ce faire

                  Comment faire pour ....(lettre A) https://forum.pcastuces.com/sujet.asp?f=25&s=3902

                  =========================================================================

                  Pour améliorer la sécurité de ton PC prend quelques instants pour lire

                  Sécuriser son PC +WIFI (versions "hot" & "light") https://forum.pcastuces.com/default.asp

                  Pense a installer un parefeu

                  =========================================================================

                  Autre conseils :


                  --Comportement a adopter http://assiste.com.free.fr/p/abc/a/safe_cex.html

                  --Essaye le navigateur Firefox plus sur/securisé qu IE
                  Firefox n utilise pas le dangereux protocole ActiveX

                  Ce que sont les activeX : http://assiste.com.free.fr/p/abc/a/activex_dangers.html
                  S'en protéger: http://assiste.com.free.fr/p/abc/c/anti_activex.html

                  ---------------------------------------------------------------------------------------------------------------------------------------------------
                  Remarque :

                  * Sache qu avec Avast, tu n es pas tres bien protégé:

                  Comparatif Avast VS Antivir :

                  http://forum.malekal.com/ftopic3528.php

                  A lire https://forum.pcastuces.com/sujet.asp?f=25&s=31837

                  Si tu te decides a installer Antivir, desinstalle avast d abord et une fois antivir installé parametre le comme indiqué ici :

                  http://speedweb1.free.fr/frames2.php?page=tuto5

                  * L infection SmitFraud peut s attrapper en telechargeant de faux codecs piégés ( comme dans ton cas C:\Program Files\VideoAccessCodec) proposé par des sites de petanques pour soi disant voir les vidéos..donc, fais gaffe ;)

                  Peux tu mettre en resolu stp.

                  Voila, content d avoir pu te filer un coup de main, bon surf.
                  -------------------------------------------------------------------------------------------------------------

                  Si tu veux bien

                  Dénonce ton infection pour faire condamner les auteurs.

                  Crée un message pour faire avancer les choses sur Malware-Complaints, nous devons être les plus nombreux possibles, alors rends compte de ton infection :

                  - Voir les règles du forum : https://malwarecomplaints.info/
                  - Après t'être enregistré à l'aide du bouton en haut se nommant "Register"
                  Si tu as plus de 13 ans, choisir : "I Agree to these terms and am over or exactly 13 years of age"
                  Si tu as moins, clique sur : "I Agree to these terms and am under 13 years of age"

                  Tu as alors sous forme de liste un sujet par type d'infection (Look2Me, Smitfraud, SpywareQuake etc..).
                  La tienne = Smitfraud

                  ---> https://malwarecomplaints.info/

                  Si le malware que tu as eu n'apparaît pas dans la liste, ou si tu ne sais pas par quoi tu étais infecté(e), crée un message dans le sujet Autres infections
                  conforme au règle du forum (age, ville, département etc..)

                  Indique aussi le nom du Forum qui t'a aidé CCM
                  0
                  1. C'est bon je l'est réinstallé (nickel) je te remerci beaucoup
                    0
                    1. Contributeur sécurité
                      Re

                      "Par contre j'ai mon accord parental (NAOMI)qui a disparut???? "

                      Mer....damned !! j ai fait une erreur :

                      Je crois que c est l etape 1) et 3) qui ont fait "sauter" Naomi :( :(

                      Peux tu essayer de le reinstaller et dis moi s il refonctionne.

                      Désolé :(

                      Si c est bien le cas, on aura juste a conclure par plusieurs conseils importants de securité a appliquer ;)

                      @+
                      0
                      1. Voila!!! Par contre j'ai mon accord parental (NAOMI)qui a disparut????

                        File move failed. C:\program files\rnamfler\naomf.exe scheduled to be moved on reboot.

                        Created on 09/15/2007 09:29:24

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 12:07:13, on 15/09/2007
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Ahead\InCD\InCDsrv.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                        C:\windows\system\hpsysdrv.exe
                        C:\WINDOWS\system32\hphmon06.exe
                        C:\WINDOWS\AGRSMMSG.exe
                        C:\WINDOWS\ALCXMNTR.EXE
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\WINDOWS\system32\rundll32.exe
                        C:\Program Files\Soft4Ever\looknstop\looknstop.exe
                        C:\Program Files\Ahead\InCD\InCD.exe
                        C:\HP\KBD\KBD.EXE
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        C:\Program Files\Logitech\SetPoint\KEM.exe
                        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        C:\WINDOWS\system32\nvsvc32.exe
                        C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\Rar$EX00.937\HijackThis.exe

                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                        O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                        O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
                        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
                        O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                        O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                        O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
                        O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [Look 'n' Stop] C:\Program Files\Soft4Ever\looknstop\looknstop.exe -auto
                        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                        O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
                        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        O4 - Startup: FreeBot.lnk = C:\Program Files\FreeBot\freebot.exe
                        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
                        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                        O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?55dc050494ea4cc4bd9ef2bd8dbeda2f
                        O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?55dc050494ea4cc4bd9ef2bd8dbeda2f
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                        O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                        O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                        O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
                        O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://www.msnjeux.com/online2/MSN_INTL_FRANCE/shapo/shapo.cab
                        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
                        O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                        0
                        1. Contributeur sécurité
                          Re

                          C est moi qui est oublié l espace entre sc et stop ;(

                          c est

                          sc stop RdnaoFlSvc

                          Désolé

                          @+
                          0
                          1. (quand je vais dans executer:scstop rdnaoflsve)
                            voila se que me repond le PC:::Windows ne trouve pas scstop verifiez que vous avez entré le nom correctement et recommancer a nouveau.
                            J'ai reéssayé plusieurs fois sans changement
                            0
                            1. Contributeur sécurité
                              Re

                              Et et le nouvel HijackThis, stp...

                              @ suivre, car il reste des conseils de securité a appliquer...
                              0
                              1. File move failed. C:\program files\rnamfler\naomf.exe scheduled to be moved on reboot.

                                Created on 09/15/2007 09:29:24
                                0
                                1. Contributeur sécurité
                                  Bonjour loulou 63

                                  Ce n est pas fini...!!

                                  SmitFraudFix a bien bossé, mais il reste du boulot ;)

                                  Je te conseille d'enregistrer la page en sélectionnant toutes les lignes puis de copier cette sélection dans un fichier texte sur ton PC pour pouvoir appliquer la procedure correctement.
                                  Il faut exécuter toutes les étapes, sans interruption, dans l'ordre exact indiqué ci-dessous.
                                  Si un élément te paraît obscur, demande des explications avant de commencer la désinfection


                                  1) Télécharge OTMoveIt (de Old_Timer)

                                  sur ton Bureau.
                                  http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

                                  clic double sur OTMoveIt.exe pour le lancer.
                                  copie la liste qui se trouve en citation ci-dessous,
                                  et colle-la dans le cadre de gauche de OTMoveIt :
                                  Paste List of Files/Folders to be moved.

                                  C:\Program Files\rnamfler\naomf.exe

                                  clique sur MoveIt! pour lancer la suppression.
                                  le résultat apparaitra dans le cadre Results.
                                  clique sur Exit pour fermer.
                                  poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                                  il te sera peut-être demander de redémarrer le pc pour achever la suppression.
                                  si c'est le cas accepte par Yes.


                                  2) Lance HijackThis.


                                  Ferme toutes les autres fenetres.Pas de connection internet.
                                  Clique sur Scan et coche les lignes suivantes, Clique sur Fix Checked.

                                  O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
                                  O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                                  O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                                  O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
                                  O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
                                  O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
                                  O4 - HKLM\..\Run: [wrna3ls] C:\Program Files\rnamfler\naomf.exe
                                  O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
                                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                  O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
                                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                  O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                  O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
                                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                  O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
                                  O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
                                  O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                                  O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                                  O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://msnfr.oberon-media.com/online2/MSN_INTL_FRANCE/chainz_2/mjolauncher.cab
                                  O16 - DPF: {E1342154-4889-42B5-BEF6-19237577048F} (OberongamesLoader Object) - http://msnfr.oberon-media.com/online2/MSN_INTL_FRANCE/zuma/oberongamesloader.cab


                                  Confirme la suppression par ok, puis ferme HijackThis.

                                  3) Suppression service RdnaoFlSvc

                                  Demarrer / executer puis tapes

                                  scstop RdnaoFlSvc
                                  Puis valide par ok

                                  Meme chose puis tapes

                                  sc delete RdnaoFlSvc

                                  Puis valide par ok

                                  4) Rapports

                                  Redemarre ton pc et poste le rapport d OTMoveIt (situé dans C:\_OTMoveIt\MovedFiles) et un nouvel HijackThis.

                                  @ suivre, car il reste des conseils de securité a appliquer...
                                  0
                                  1. ah!!! j'oublié (FINI LA PETANQUE )
                                    0
                                    1. MERCI pour tout .Je pense que mon pc et revenu a la normal .
                                      0
                                      1. VOILA c'est fait.il faut que j'aille bosser je te direr ce soir si tout va bien MERCI

                                        SmitFraudFix v2.223

                                        Rapport fait à 12:35:18,93, 14/09/2007
                                        Executé à partir de C:\Documents and Settings\HP_Propri‚taire\Bureau\SmitfraudFix
                                        OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                                        Le type du système de fichiers est NTFS
                                        Fix executé en mode normal

                                        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                        SrchSTS.exe by S!Ri
                                        Search SharedTaskScheduler's .dll

                                        »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                                        »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                        127.0.0.1 localhost #***Inserted By STOPzilla***

                                        127.0.0.1 0websearch.com # ***Inserted By STOPzilla***
                                        127.0.0.1 2005-search.com # ***Inserted By STOPzilla***
                                        127.0.0.1 600pics.com # ***Inserted By STOPzilla***
                                        127.0.0.1 a1.interclick.com # ***Inserted By STOPzilla***
                                        127.0.0.1 absolutepics.net # ***Inserted By STOPzilla***
                                        127.0.0.1 ad.yieldmanager.com # ***Inserted By STOPzilla***
                                        127.0.0.1 alex.fileburst.com # ***Inserted By STOPzilla***
                                        127.0.0.1 all-tgp.org # ***Inserted By STOPzilla***
                                        127.0.0.1 all-websearch.com # ***Inserted By STOPzilla***
                                        127.0.0.1 apps.deskwizz.com # ***Inserted By STOPzilla***
                                        127.0.0.1 awmdabest.com # ***Inserted By STOPzilla***
                                        127.0.0.1 bailefunk.com # ***Inserted By STOPzilla***
                                        127.0.0.1 barteros.net # ***Inserted By STOPzilla***
                                        127.0.0.1 best4all.net # ***Inserted By STOPzilla***
                                        127.0.0.1 besthardcore.net # ***Inserted By STOPzilla***
                                        127.0.0.1 best-targeted-traffic.com # ***Inserted By STOPzilla***
                                        127.0.0.1 bins.elitemediagroup.net # ***Inserted By STOPzilla***
                                        127.0.0.1 bn.i-ru.net # ***Inserted By STOPzilla***
                                        127.0.0.1 brazauskas.info # ***Inserted By STOPzilla***
                                        127.0.0.1 bundleware.com # ***Inserted By STOPzilla***
                                        127.0.0.1 burnsrecyclinginc.com # ***Inserted By STOPzilla***
                                        127.0.0.1 campaigns.interclick.com # ***Inserted By STOPzilla***
                                        127.0.0.1 centralgate.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 clickfast.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 code.jcash.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 code.trasferimento.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 command.adservs.com # ***Inserted By STOPzilla***
                                        127.0.0.1 content.dollarrevenue.com # ***Inserted By STOPzilla***
                                        127.0.0.1 content.exetraffic.com # ***Inserted By STOPzilla***
                                        127.0.0.1 content2.dollarrevenue.com # ***Inserted By STOPzilla***
                                        127.0.0.1 coolwebsearch.com # ***Inserted By STOPzilla***
                                        127.0.0.1 cumhereteens.com # ***Inserted By STOPzilla***
                                        127.0.0.1 cyber-search.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 ddh24.com # ***Inserted By STOPzilla***
                                        127.0.0.1 dedmazai.com # ***Inserted By STOPzilla***
                                        127.0.0.1 dnv-counter.com # ***Inserted By STOPzilla***
                                        127.0.0.1 download.abetterinternet.com # ***Inserted By STOPzilla***
                                        127.0.0.1 download.accessmedia.tv # ***Inserted By STOPzilla***
                                        127.0.0.1 download.jupitersatellites.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 exeloads.info # ***Inserted By STOPzilla***
                                        127.0.0.1 faccesborrate.com # ***Inserted By STOPzilla***
                                        127.0.0.1 flavinha.com # ***Inserted By STOPzilla***
                                        127.0.0.1 forlink.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 freevideo24.com # ***Inserted By STOPzilla***
                                        127.0.0.1 fullbizzone.com # ***Inserted By STOPzilla***
                                        127.0.0.1 game4all.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 get-access.host.sk # ***Inserted By STOPzilla***
                                        127.0.0.1 go-pic.com # ***Inserted By STOPzilla***
                                        127.0.0.1 granjerascachondas.com # ***Inserted By STOPzilla***
                                        127.0.0.1 greatgoodsex.com # ***Inserted By STOPzilla***
                                        127.0.0.1 heretofind.com # ***Inserted By STOPzilla***
                                        127.0.0.1 hqthumbz.com # ***Inserted By STOPzilla***
                                        127.0.0.1 it.online-more.com # ***Inserted By STOPzilla***
                                        127.0.0.1 its.justcount.net # ***Inserted By STOPzilla***
                                        127.0.0.1 krovalidajop.com # ***Inserted By STOPzilla***
                                        127.0.0.1 l.mezzicodec.net # ***Inserted By STOPzilla***
                                        127.0.0.1 lust-mature.com # ***Inserted By STOPzilla***
                                        127.0.0.1 mikos.paraisoasiatico.com # ***Inserted By STOPzilla***
                                        127.0.0.1 mmm.elitemediagroup.net # ***Inserted By STOPzilla***
                                        127.0.0.1 more-pages.com # ***Inserted By STOPzilla***
                                        127.0.0.1 morteen.net # ***Inserted By STOPzilla***
                                        127.0.0.1 moviecsodecs.com # ***Inserted By STOPzilla***
                                        127.0.0.1 ms-counter.com # ***Inserted By STOPzilla***
                                        127.0.0.1 msmn.com # ***Inserted By STOPzilla***
                                        127.0.0.1 musah.info # ***Inserted By STOPzilla***
                                        127.0.0.1 netincap.com # ***Inserted By STOPzilla***
                                        127.0.0.1 newsh.com # ***Inserted By STOPzilla***
                                        127.0.0.1 niuqennaois.com # ***Inserted By STOPzilla***
                                        127.0.0.1 nude-teen-bodies.com # ***Inserted By STOPzilla***
                                        127.0.0.1 onlyhotlinks.com # ***Inserted By STOPzilla***
                                        127.0.0.1 on-search.com # ***Inserted By STOPzilla***
                                        127.0.0.1 picshunter.us # ***Inserted By STOPzilla***
                                        127.0.0.1 picslab.com # ***Inserted By STOPzilla***
                                        127.0.0.1 prevedtraf.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 promo.dollarrevenue.com # ***Inserted By STOPzilla***
                                        127.0.0.1 redirect.msupdate.net # ***Inserted By STOPzilla***
                                        127.0.0.1 rogalik.net # ***Inserted By STOPzilla***
                                        127.0.0.1 search4www.com # ***Inserted By STOPzilla***
                                        127.0.0.1 search-biz.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 searchforit.com # ***Inserted By STOPzilla***
                                        127.0.0.1 searchx.cc # ***Inserted By STOPzilla***
                                        127.0.0.1 sex-pics.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 sexyfaceplace.com # ***Inserted By STOPzilla***
                                        127.0.0.1 snow410.info # ***Inserted By STOPzilla***
                                        127.0.0.1 software.topinstalls.com # ***Inserted By STOPzilla***
                                        127.0.0.1 sp2admin.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 surubanet.com # ***Inserted By STOPzilla***
                                        127.0.0.1 teadis.net # ***Inserted By STOPzilla***
                                        127.0.0.1 teen-biz.com # ***Inserted By STOPzilla***
                                        127.0.0.1 teen-fantazi.com # ***Inserted By STOPzilla***
                                        127.0.0.1 teenygirlshome.com # ***Inserted By STOPzilla***
                                        127.0.0.1 traff5all.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 traffbest.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 traffbucks.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 traffmoney.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 ukstories.net # ***Inserted By STOPzilla***
                                        127.0.0.1 ultra-search.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 uniq-soft.com # ***Inserted By STOPzilla***
                                        127.0.0.1 vivisexy.com # ***Inserted By STOPzilla***
                                        127.0.0.1 wearehosters.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.0websearch.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.600pics.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.abetterstart.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.all-tgp.org # ***Inserted By STOPzilla***
                                        127.0.0.1 www.all-websearch.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.axmediaproject.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.bailefunk.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.best4all.net # ***Inserted By STOPzilla***
                                        127.0.0.1 www.besthardcore.net # ***Inserted By STOPzilla***
                                        127.0.0.1 www.bundleware.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.burnsrecyclinginc.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.coolwebsearch.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.dedmazai.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.flavinha.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.granjerascachondas.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.heretofind.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.hqthumbz.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.jtreeproperties.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.lattefresco.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 www.lust-mature.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.mikos.paraisoasiatico.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.more-pages.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.msmn.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.msnwm.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.newsh.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.nude-teens-bodies.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.onli-ne.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.onlyhotlinks.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.on-search.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.picshunter.us # ***Inserted By STOPzilla***
                                        127.0.0.1 www.picslab.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.procounter.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 www.search4www.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.searchforit.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.searchx.cc # ***Inserted By STOPzilla***
                                        127.0.0.1 www.sex-pics.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 www.sp2admin.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 www.spamcatchero.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 www.surubanet.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.teen-biz.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.teen-fantazi.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.teenygirlshome.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.traff4ppc.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 www.vivisexy.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.voghp.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.wearehosters.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.ysbweb.com # ***Inserted By STOPzilla***
                                        127.0.0.1 www.zgallery.us # ***Inserted By STOPzilla***
                                        127.0.0.1 www.zonebest.com # ***Inserted By STOPzilla***
                                        127.0.0.1 ybbwxlxytz.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 yepjnddqpq.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 yhvoo.eseconsult.info # ***Inserted By STOPzilla***
                                        127.0.0.1 yougoodheer.com # ***Inserted By STOPzilla***
                                        127.0.0.1 ysbweb.com # ***Inserted By STOPzilla***
                                        127.0.0.1 z-advertise.com # ***Inserted By STOPzilla***
                                        127.0.0.1 zchxsikpgz.biz # ***Inserted By STOPzilla***
                                        127.0.0.1 zgallery.us # ***Inserted By STOPzilla***
                                        127.0.0.1 zonebest.com # ***Inserted By STOPzilla***

                                        »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                                        »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                                        C:\WINDOWS\main_uninstaller.exe supprimé
                                        C:\WINDOWS\msmdev.dll supprimé
                                        C:\WINDOWS\msmhost.dll supprimé
                                        C:\WINDOWS\nsduo.dll supprimé
                                        C:\WINDOWS\privacy_danger\ supprimé
                                        C:\DOCUME~1\HP_PRO~1\Favoris\Error Cleaner.url supprimé
                                        C:\DOCUME~1\HP_PRO~1\Favoris\Privacy Protector.url supprimé
                                        C:\Program Files\VideoAccessCodec\ supprimé

                                        »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                        Description: Carte réseau virtuelle FreeBox USB - Miniport d'ordonnancement de paquets
                                        DNS Server Search Order: 212.27.54.252
                                        DNS Server Search Order: 212.27.53.252

                                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{2AEF8DB6-DAE6-45D3-87E6-C89053B8CE58}: DhcpNameServer=212.27.54.252 212.27.53.252
                                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{2AEF8DB6-DAE6-45D3-87E6-C89053B8CE58}: DhcpNameServer=212.27.54.252 212.27.53.252
                                        HKLM\SYSTEM\CS3\Services\Tcpip\..\{2AEF8DB6-DAE6-45D3-87E6-C89053B8CE58}: DhcpNameServer=212.27.54.252 212.27.53.252
                                        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.54.252 212.27.53.252
                                        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.54.252 212.27.53.252
                                        HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=212.27.54.252 212.27.53.252

                                        »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                                        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                                        »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                                        Nettoyage terminé.

                                        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                        SrchSTS.exe by S!Ri
                                        Search SharedTaskScheduler's .dll

                                        »»»»»»»»»»»»»»»»»»»»»»»» Fin
                                        Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 12:41:02, on 14/09/2007
                                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\WINDOWS\System32\smss.exe
                                        C:\WINDOWS\system32\csrss.exe
                                        C:\WINDOWS\system32\winlogon.exe
                                        C:\WINDOWS\system32\services.exe
                                        C:\WINDOWS\system32\lsass.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\Program Files\Ahead\InCD\InCDsrv.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                        C:\WINDOWS\system32\spoolsv.exe
                                        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                        C:\WINDOWS\system32\nvsvc32.exe
                                        C:\Program Files\rnamfler\naofsvc.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                                        C:\windows\system\hpsysdrv.exe
                                        C:\WINDOWS\system32\hphmon06.exe
                                        C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                                        C:\WINDOWS\AGRSMMSG.exe
                                        C:\WINDOWS\system32\rundll32.exe
                                        C:\WINDOWS\ALCXMNTR.EXE
                                        C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                                        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                        C:\Program Files\Soft4Ever\looknstop\looknstop.exe
                                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                        C:\WINDOWS\System32\alg.exe
                                        C:\Program Files\rnamfler\naomf.exe
                                        C:\Program Files\Ahead\InCD\InCD.exe
                                        C:\HP\KBD\KBD.EXE
                                        C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
                                        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                        C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
                                        C:\Program Files\iTunes\iTunesHelper.exe
                                        C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                                        c:\program files\rnamfler\radprcmp.exe
                                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                        C:\Program Files\MSN Messenger\msnmsgr.exe
                                        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                        C:\Program Files\Logitech\SetPoint\KEM.exe
                                        C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
                                        C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
                                        C:\Program Files\iPod\bin\iPodService.exe
                                        C:\WINDOWS\system32\cmd.exe
                                        C:\WINDOWS\system32\wbem\wmiprvse.exe
                                        C:\WINDOWS\explorer.exe
                                        C:\WINDOWS\notepad.exe
                                        C:\WINDOWS\system32\wuauclt.exe
                                        C:\Program Files\WinRAR\WinRAR.exe
                                        C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\Rar$EX00.453\HijackThis.exe
                                        C:\WINDOWS\system32\wbem\wmiprvse.exe

                                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                                        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                        O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
                                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                                        O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                                        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                                        O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
                                        O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
                                        O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                                        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                                        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
                                        O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                                        O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                                        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                                        O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
                                        O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
                                        O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
                                        O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
                                        O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
                                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                        O4 - HKLM\..\Run: [Look 'n' Stop] C:\Program Files\Soft4Ever\looknstop\looknstop.exe -auto
                                        O4 - HKLM\..\Run: [wrna3ls] C:\Program Files\rnamfler\naomf.exe
                                        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                        O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
                                        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                                        O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
                                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                        O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
                                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                                        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                        O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
                                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                        O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
                                        O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
                                        O4 - Startup: FreeBot.lnk = C:\Program Files\FreeBot\freebot.exe
                                        O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                                        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                        O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
                                        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                                        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                        O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?55dc050494ea4cc4bd9ef2bd8dbeda2f
                                        O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?55dc050494ea4cc4bd9ef2bd8dbeda2f
                                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                                        O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                                        O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
                                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                                        O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://msnfr.oberon-media.com/online2/MSN_INTL_FRANCE/chainz_2/mjolauncher.cab
                                        O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
                                        O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://www.msnjeux.com/online2/MSN_INTL_FRANCE/shapo/shapo.cab
                                        O16 - DPF: {E1342154-4889-42B5-BEF6-19237577048F} (OberongamesLoader Object) - http://msnfr.oberon-media.com/online2/MSN_INTL_FRANCE/zuma/oberongamesloader.cab
                                        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                        O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
                                        O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                        O23 - Service: RdnaoFlSvc - Unknown owner - C:\Program Files\rnamfler\naofsvc.exe
                                        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                                        0
                                        1. Contributeur sécurité
                                          Re

                                          On continu,

                                          C est bien une infection SmitFraud qui s attrappe en telechargeant de faux codecs sur les sites de petanques ou en visitant ces derniers ou/et sites de crack... a bon entendeur..salut ;)

                                          Je te conseille d'enregistrer la page en sélectionnant toutes les lignes puis de copier cette sélection dans un fichier texte sur ton PC pour pouvoir appliquer la procedure correctement.
                                          Il faut exécuter toutes les étapes, sans interruption, dans l'ordre exact indiqué ci-dessous.
                                          (Note: tu n'auras pas accès à Internet à partir du moment ou tu redemarreras en mode sans echec)
                                          Si un élément te paraît obscure, demande des explications avant de commencer la désinfection



                                          1) Redemarre en mode sans echec


                                          Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuyer sur la touche [F8] ou [F5] jusqu'à l'affichage du menu des options avancées de Windows.
                                          Sélectionner "Mode sans échec" et appuyer sur [Entrée]
                                          Regarde si besoin a C) ici --> https://forum.pcastuces.com/sujet.asp?f=25&s=3902


                                          2) SmitFraudFix option 2


                                          Double cliquer sur smitfraudfix.cmd

                                          Sélectionner 2
                                          pour supprimer les fichiers responsables de l'infection.
                                          A la question Voulez-vous nettoyer le registre ? répondre O (oui) afin de débloquer le fond d'écran et supprimer les clés de démarrage automatique de l'infection.
                                          Le fix déterminera si le fichier wininet.dll est infecté. A la question Corriger le fichier infecté ? répondre O (oui) pour remplacer le fichier corrompu.

                                          N.B.: Cette étape élimine les fichiers infectieux détectés à l'étape #1
                                          Attention que l'option 2 de l'outil supprime le fond d'écran !

                                          process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                                          3) Rapports


                                          Redémarre en mode normal et poste ce nouveau rapport de SmitfraudFix ainsi qu un nouvel HijackThis sur le forum en precisant si cela va mieux.

                                          Je regarderais, ces 2 nouveaux rapports plutard, je vais "siesté", je bosse de nuit ;)

                                          @ suivre
                                          0
                                          • 1
                                          • 2