Smitfraud à comrendre

Bonjour,

Quelqu'un pourrait-il m'aider à analyser ce rapport de Smitfraud ???

SmitFraudFix v2.228

Rapport fait à 11:33:19,76, 27/09/2007
Executé à partir de C:\Documents and Settings\Audrey FELIX\Bureau\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\SharedComponents\iTechnology\igateway.exe
C:\Program Files\CA\eTrustITM\InoRpc.exe
C:\Program Files\CA\eTrustITM\InoRT.exe
C:\Program Files\CA\eTrustITM\InoTask.exe
C:\WINDOWS\system32\lxcycoms.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\Program Files\CA\eTrustITM\realmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\OpenVPN\bin\openvpn.exe
C:\WINDOWS\system32\mstsc.exe
C:\Program Files\IBM\Sametime Connect\sametime.exe
C:\Program Files\IBM\Sametime Connect\jre\bin\sametime75.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Audrey FELIX\Bureau\iTunes742Setup.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\MsiExec.exe
C:\DOCUME~1\AUDREY~1\LOCALS~1\Temp\IXP417.TMP\iTunesSetupAdmin.exe
C:\WINDOWS\system32\MsiExec.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts

»»»»»»»»»»»»»»»»»»»»»»»» C:\

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Audrey FELIX

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Audrey FELIX\Application Data

»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\AUDREY~1\Favoris

»»»»»»»»»»»»»»»»»»»»»»»» Bureau

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""

»»»»»»»»»»»»»»»»»»»»»»»» Rustock

»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Carte réseau sans fil Mini-PCI 1370 de Dell - Miniport d'ordonnancement de paquets
DNS Server Search Order: 192.168.6.1
DNS Server Search Order: 192.168.6.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{B7622672-D961-47C6-9403-8FFB99075422}: DhcpNameServer=192.168.6.1 192.168.6.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{B7622672-D961-47C6-9403-8FFB99075422}: DhcpNameServer=192.168.6.1 192.168.6.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{B7622672-D961-47C6-9403-8FFB99075422}: DhcpNameServer=192.168.6.1 192.168.6.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.6.1 192.168.6.1

»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

»»»»»»»»»»»»»»»»»»»»»»»» Fin

Merci
Configuration: Windows XP
Firefox 2.0.0.7

7 réponses

  1. Contributeur sécurité
    Re,

    je ne connais pas,

    je vais regarder ça ce soir;

    En attendant, je te proposerai un travail de nettoyage (anti spy et antivirus on line) tout à l'heure.

    @+
    0
    1. Contributeur sécurité
      Re,

      il n'a rien, c'est le fichier initial de Windows.

      Il n'y en avait qu'un quand tu as recherché .
      ?

      C'est quoi ce que tu appellles procees explorer qui le voit en rouge ?

      @+
      0
      1. RE lyonnais 92

        Fichier wmiprvse.exe reçu le 2007.09.27 17:51:47 (CET)
        Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE
        Résultat: 0/32 (0%)
        en train de charger les informations du serveur...
        Votre fichier est dans la file d'attente, en position: 2.
        L'heure estimée de démarrage est entre 43 et 62 secondes.
        Ne fermez pas la fenêtre avant la fin de l'analyse.
        L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
        Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
        Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
        les résultats seront affichés au fur et à mesure de leur génération.
        Formaté Formaté
        Impression des résultats Impression des résultats
        Votre fichier a expiré ou n'existe pas.
        Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

        Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
        Email:

        Antivirus Version Dernière mise à jour Résultat
        AhnLab-V3 2007.9.28.0 2007.09.27 -
        AntiVir 7.6.0.15 2007.09.27 -
        Authentium 4.93.8 2007.09.27 -
        Avast 4.7.1043.0 2007.09.26 -
        AVG 7.5.0.488 2007.09.27 -
        BitDefender 7.2 2007.09.27 -
        CAT-QuickHeal 9.00 2007.09.27 -
        ClamAV 0.91.2 2007.09.26 -
        DrWeb 4.33 2007.09.27 -
        eSafe 7.0.15.0 2007.09.23 -
        eTrust-Vet 31.2.5168 2007.09.27 -
        Ewido 4.0 2007.09.27 -
        FileAdvisor 1 2007.09.27 -
        Fortinet 3.11.0.0 2007.09.27 -
        F-Prot 4.3.2.48 2007.09.26 -
        F-Secure 6.70.13030.0 2007.09.27 -
        Ikarus T3.1.1.12 2007.09.27 -
        Kaspersky 7.0.0.125 2007.09.27 -
        McAfee 5129 2007.09.27 -
        Microsoft 1.2803 2007.09.27 -
        NOD32v2 2554 2007.09.26 -
        Norman 5.80.02 2007.09.27 -
        Panda 9.0.0.4 2007.09.27 -
        Prevx1 V2 2007.09.27 -
        Rising 19.42.32.00 2007.09.27 -
        Sophos 4.21.0 2007.09.27 -
        Sunbelt 2.2.907.0 2007.09.26 -
        Symantec 10 2007.09.27 -
        TheHacker 6.2.6.072 2007.09.27 -
        VBA32 3.12.2.4 2007.09.26 -
        VirusBuster 4.3.26:9 2007.09.27 -
        Webwasher-Gateway 6.0.1 2007.09.27 -
        Information additionnelle
        File size: 218112 bytes
        MD5: db493dd6bc2fa5b38811f2bcdcf03d2b
        SHA1: 95f6f43d2ce1b1ca08371ca1794eb5369726ada1

        Voilà, il n'a rien?

        A+
        0
        1. Contributeur sécurité
          Re,

          1)->Affiche tous les fichiers et dossiers :
          clique sur démarrer/panneau de configuration (en affichage classique)/option des dossiers/affichage

          [Coche] « afficher les dossiers et fichiers cachés »

          [Décoche] la case « Masquer les fichiers protégés du système d'exploitation (recommandé) »

          [Décoche] « masquer les extensions dont le type est connu »

          Puis fais [appliquer] pour valider les changements.

          Et [Ok]

          2) recherche le nom exact de wmiprvse (vérifie, wmiprvse pas wmipruse ?)

          3) pour chacun des noms trouvés, fais ceci :

          Rends toi sur ce site :

          https://www.virustotal.com/gui/

          Clique sur parcourir et cherche ce fichier : XXXXXXXXXXXXXXX (utilise le nom complet du fichier avec son extension)

          Clique sur Send File.

          Un rapport va s'élaborer ligne à ligne.

          Attends la fin. Il doit comprendre la taille du fichier envoyé.

          Sauvegarde le rapport avec le bloc-note.

          Copie le dans ta réponse.

          @+
          0
          1. Bonjour, Lyonnais 92

            Voici le rapport Smitfraud ainsi qu'un rapport de Hijackthis:

            SmitFraudFix v2.231

            Rapport fait à 17:13:22,85, 27/09/2007
            Executé à partir de C:\Documents and Settings\Audrey FELIX\SmitfraudFix
            OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
            Le type du système de fichiers est NTFS
            Fix executé en mode normal

            »»»»»»»»»»»»»»»»»»»»»»»» Process

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            C:\Program Files\CA\SharedComponents\iTechnology\igateway.exe
            C:\Program Files\CA\eTrustITM\InoRpc.exe
            C:\Program Files\CA\eTrustITM\InoRT.exe
            C:\Program Files\CA\eTrustITM\InoTask.exe
            C:\WINDOWS\system32\lxcycoms.exe
            C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
            C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\hkcmd.exe
            C:\WINDOWS\system32\igfxpers.exe
            C:\WINDOWS\stsystra.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\WINDOWS\system32\igfxsrvc.exe
            C:\Program Files\OpenVPN\bin\openvpn-gui.exe
            C:\Program Files\CA\eTrustITM\realmon.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
            C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\OpenVPN\bin\openvpn.exe
            C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
            C:\WINDOWS\system32\mstsc.exe
            C:\WINDOWS\system32\cmd.exe

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            »»»»»»»»»»»»»»»»»»»»»»»» C:\

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Audrey FELIX

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Audrey FELIX\Application Data

            »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

            »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\AUDREY~1\Favoris

            »»»»»»»»»»»»»»»»»»»»»»»» Bureau

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

            »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

            »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
            "Source"="About:Home"
            "SubscribedURL"="About:Home"
            "FriendlyName"="Ma page d'accueil"

            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLs"=""

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "System"=""

            »»»»»»»»»»»»»»»»»»»»»»»» Rustock

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            Description: Carte réseau sans fil Mini-PCI 1370 de Dell - Miniport d'ordonnancement de paquets
            DNS Server Search Order: 192.168.6.1
            DNS Server Search Order: 192.168.6.1

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{B7622672-D961-47C6-9403-8FFB99075422}: DhcpNameServer=192.168.6.1 192.168.6.1
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{B7622672-D961-47C6-9403-8FFB99075422}: DhcpNameServer=192.168.6.1 192.168.6.1
            HKLM\SYSTEM\CS3\Services\Tcpip\..\{B7622672-D961-47C6-9403-8FFB99075422}: DhcpNameServer=192.168.6.1 192.168.6.1
            HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.6.1 192.168.6.1

            »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

            »»»»»»»»»»»»»»»»»»»»»»»» Fin

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 17:15:07, on 27/09/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            C:\Program Files\CA\SharedComponents\iTechnology\igateway.exe
            C:\Program Files\CA\eTrustITM\InoRpc.exe
            C:\Program Files\CA\eTrustITM\InoRT.exe
            C:\Program Files\CA\eTrustITM\InoTask.exe
            C:\WINDOWS\system32\lxcycoms.exe
            C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
            C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\hkcmd.exe
            C:\WINDOWS\system32\igfxpers.exe
            C:\WINDOWS\stsystra.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\WINDOWS\system32\igfxsrvc.exe
            C:\Program Files\OpenVPN\bin\openvpn-gui.exe
            C:\Program Files\CA\eTrustITM\realmon.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
            C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\OpenVPN\bin\openvpn.exe
            C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
            C:\WINDOWS\system32\mstsc.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.dell.com/fr-fr?c=fr&l=fr&s=gen&redirect=1
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.dell.com/fr-fr?c=fr&l=fr&s=gen&redirect=1
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
            O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
            O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
            O4 - HKLM\..\Run: [Realtime Monitor] "C:\Program Files\CA\eTrustITM\realmon.exe" -s
            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
            O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
            O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?99c9719ad9474a3c8a00938e948c8c44
            O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?99c9719ad9474a3c8a00938e948c8c44
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
            O23 - Service: iTechnology iGateway 4.0 (iGateway) - Computer Associates International, Inc. - C:\Program Files\CA\SharedComponents\iTechnology\igateway.exe
            O23 - Service: Service RPC eTrust ITM (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrustITM\InoRpc.exe
            O23 - Service: Service en temps réel eTrust ITM (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrustITM\InoRT.exe
            O23 - Service: Service des jobs eTrust ITM (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrustITM\InoTask.exe
            O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: lxcy_device - - C:\WINDOWS\system32\lxcycoms.exe
            O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
            O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
            O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
            O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
            O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
            0
            1. Contributeur sécurité
              Bonjour,

              il n'y a rien dans ce rapport, sauf que ta version n'est pas à jour, ce qui peut suffire à la rendre inefficace.

              Supprime tout ce que tu as de SmitfraudFix et fais ça :

              Ouvre ce lien (merci a S!RI pour ce programme). http://siri.urz.free.fr/Fix/SmitfraudFix.php
              et télécharge SmitfraudFix.exe.

              Regarde le tuto
              Exécute le en choisissant l’option 1, il va générer un rapport
              Copie/colle le sur le poste stp.

              Je suppose que tu as des raisons de scanner avec cet outil.

              Dis nous quels sont tes soucis et fais ausiz ça :

              Clique sur ce lien
              http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
              pour télécharger le fichier d'installation d'HijackThis.

              Enregistre HJTInstall.exe sur ton bureau.

              Double-clique sur HJTInstall.exe pour lancer le programme

              Par défaut, il s'installera là :
              C:\Program Files\Trend Micro\HijackThis

              Accepte la license en cliquant sur le bouton "I Accept"

              Choisis l'option "Do a system scan and save a log file"

              Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note

              Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

              Colle le rapport que tu viens de copier sur ce forum

              Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement

              Tutoriaux : http://pageperso.aol.fr/balltrap34/demohijack.htm (ne fixe rien pour le moment !!)
              http://cybersecurite.xooit.com/t138-HijackThis-2-0-2.htm

              @+
              0