Probleme avec antivir

Résolu
Bonjour, j'ai un petit probleme avec antivir!
j'ai une fenetre me signalant la detection d'un virus et je n'arrive rien a faire.... je selectionne toutes les options les unes apres les autres mais ca revient a chaque fois!
en plus ca s'embale il y a des jusquq'a 12 fenetres identiques qui s'ouvrent...
j'ai tout essayé:
j'ai lancé unscan complet, redemarré l'ordi...
si quelqu'un a une solution!!!
merci!
Configuration: Windows XP
Internet Explorer 7.0

10 réponses

  1. Contributeur sécurité
    Bonjour,

    Il serait préférable que tu fasses ton message personnel, cela rendra les postes plus compréhensibles et la réponse à ton problème sera plus efficace
    Procèdes comme ceci :
    http://pageperso.aol.fr/balltrap34/demofairesontmessage.htm

    A bientôt
    0
    1. Contributeur sécurité
      Re

      Sans hésitations, antivir.

      Redemarre ton pc et refais un hijackthis + un smitfraudfix

      a+
      0
      1. bon le message a reapparut mais a priori la mise en quarantane a fonctionné!.....
        merci!!!!
        un petit conseil: avast ou antivir?
        0
        1. ça a l air d etre bon
          en une soirée probleme resolu
          BRAVO Regis59

          ET ATTENTION AU SITE X
          L'ABUS D'ALCOOL ET DANGEREUX POUR LA SANTé
          0
          1. dFix v2.234

            Rapport fait à 22:47:55,09, 01/10/2007
            Executé à partir de C:\Documents and Settings\Natalia\Bureau\SmitfraudFix
            OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
            Le type du système de fichiers est NTFS
            Fix executé en mode normal

            »»»»»»»»»»»»»»»»»»»»»»»» Process

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
            C:\WINDOWS\System32\FTRTSVC.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\WINDOWS\system32\WgaTray.exe
            C:\WINDOWS\ehome\ehtray.exe
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
            C:\Program Files\SPYWAREfighter\spftray.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\MSN Messenger\MsnMsgr.Exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
            C:\PROGRA~1\Wanadoo\ComComp.exe
            C:\PROGRA~1\Wanadoo\Toaster.exe
            C:\PROGRA~1\Wanadoo\Inactivity.exe
            C:\PROGRA~1\Wanadoo\PollingModule.exe
            C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
            C:\PROGRA~1\Wanadoo\Watch.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
            C:\WINDOWS\eHome\ehmsas.exe
            C:\WINDOWS\exploeee.exe
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\WINDOWS\system32\HPZipm12.exe
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\WINDOWS\system32\HPZipm12.exe
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\system32\cmd.exe
            C:\WINDOWS\system32\HPZipm12.exe

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            »»»»»»»»»»»»»»»»»»»»»»»» C:\

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

            C:\WINDOWS\system32\hadjajr.ini PRESENT !
            C:\WINDOWS\system32\vtr???.dll PRESENT !

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Natalia

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Natalia\Application Data

            »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

            »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Natalia\Favoris

            »»»»»»»»»»»»»»»»»»»»»»»» Bureau

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

            »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

            »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
            "Source"="About:Home"
            "SubscribedURL"="About:Home"
            "FriendlyName"="Ma page d'accueil"

            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLs"="C:\\WINDOWS\\system32\\hadjajr.ini"

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "System"=""

            »»»»»»»»»»»»»»»»»»»»»»»» Rustock

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            Description: Broadcom 802.11b/g WLAN - Miniport d'ordonnancement de paquets
            DNS Server Search Order: 192.168.1.1
            DNS Server Search Order: 0.0.0.0

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{18BC9557-F9EF-4DD6-93E9-DBACFDBFE888}: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{18BC9557-F9EF-4DD6-93E9-DBACFDBFE888}: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CS2\Services\Tcpip\..\{18BC9557-F9EF-4DD6-93E9-DBACFDBFE888}: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0

            »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

            »»»»»»»»»»»»»»»»»»»»»»»» Fin

            EN MODE SANS ECHECdFix v2.234

            Rapport fait à 23:05:25,43, 01/10/2007
            Executé à partir de C:\Documents and Settings\Natalia\Bureau\SmitfraudFix
            OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
            Le type du système de fichiers est NTFS
            Fix executé en mode sans echec

            »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            127.0.0.1 localhost

            »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

            S!Ri's WS2Fix: LSP not Found.

            »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

            GenericRenosFix by S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

            C:\WINDOWS\system32\vtr???.dll supprimé

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{18BC9557-F9EF-4DD6-93E9-DBACFDBFE888}: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{18BC9557-F9EF-4DD6-93E9-DBACFDBFE888}: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CS2\Services\Tcpip\..\{18BC9557-F9EF-4DD6-93E9-DBACFDBFE888}: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0

            »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "System"=""

            »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

            Nettoyage terminé.

            »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» Fin
            0
            1. Contributeur sécurité
              Je viens de comprendre lol
              Attention aux sites X.

              Télécharge ceci: (merci a S!RI pour ce programme).
              http://siri.urz.free.fr/Fix/SmitfraudFix.exe
              Exécute le Smitfraudfix.exe et choisit l’option 1, il va générer un rapport
              Copie/colle le sur le poste stp.
              ----------------------------------------------------------------------------
              Démarre en mode sans échec :
              Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
              Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
              Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
              (Si F8 ne marche pas utilise la touche F5).
              ----------------------------------------------------------------------------
              Relance le programme Smitfraud,
              Cette fois choisit l’option 2, répond oui a tous ;
              Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum
              0
              1. Bonjour,
                c'est encore nat 26!!!!
                c'est la merde ca a recommencé....
                j'ai refait la meme manip mais je pense que c'est pas bien normal!
                j'ai mis les 2 rapport sur le forum si tu a l'occas de jeter un coup d'oeil!
                merci!
                0
              2. Bonjour,
                SmitFraudFix v2.237

                Rapport fait à 17:16:23,67, 05/10/2007
                Executé à partir de C:\Documents and Settings\Victor\SmitfraudFix
                OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                Le type du système de fichiers est NTFS
                Fix executé en mode normal

                »»»»»»»»»»»»»»»»»»»»»»»» Process

                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\csrss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                C:\WINDOWS\system32\cisvc.exe
                C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                C:\Program Files\Spyware Doctor\svcntaux.exe
                C:\Program Files\Spyware Doctor\swdsvc.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                C:\WINDOWS\wanmpsvc.exe
                C:\Program Files\VirusBuster\Bin\VBSNTW.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\WINDOWS\System32\alg.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\cidaemon.exe
                C:\WINDOWS\system32\wscntfy.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
                C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe
                C:\WINDOWS\tsnpstd3.exe
                C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
                C:\WINDOWS\SOUNDMAN.EXE
                C:\WINDOWS\vsnpstd3.exe
                C:\Program Files\QuickTime\qttask.exe
                C:\WINDOWS\system32\igfxtray.exe
                C:\WINDOWS\system32\hkcmd.exe
                C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
                C:\Program Files\Hotbar\bin\10.0.342.0\OEAddOn.exe
                C:\Program Files\Hotbar\bin\10.0.342.0\HotbarSA.exe
                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                C:\Program Files\Spyware Doctor\SDTrayApp.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Messenger\msmsgs.exe
                C:\Program Files\Fichiers communs\AOL\1167939182\ee\aolsoftware.exe
                C:\Program Files\WinZip\WZQKPICK.EXE
                C:\PROGRA~1\Mozilla Firefox\firefox.exe
                C:\Program Files\MSN Messenger\usnsvc.exe
                C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
                C:\WINDOWS\system32\regmod.exe
                C:\WINDOWS\system32\cmd.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe

                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                Fichier hosts corrompu !

                127.0.0.1 legal-at-spybot.info
                127.0.0.1 www.legal-at-spybot.info

                »»»»»»»»»»»»»»»»»»»»»»»» C:\

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                C:\WINDOWS\system32\ieffse32.dll PRESENT !
                C:\WINDOWS\system32\regmod.exe PRESENT !
                C:\WINDOWS\system32\vzfhprk.dll PRESENT !

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Victor

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Victor\Application Data

                »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                C:\DOCUME~1\ALLUSE~1\MENUDM~1\Online Security Guide.url PRESENT !
                C:\DOCUME~1\ALLUSE~1\MENUDM~1\Security Troubleshooting.url PRESENT !

                »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Victor\Favoris

                »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                C:\Program Files\Online Video Add-on\ PRESENT !

                »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                "Source"="About:Home"
                "SubscribedURL"="About:Home"
                "FriendlyName"="Ma page d'accueil"

                »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                SrchSTS.exe by S!Ri
                Search SharedTaskScheduler's .dll

                »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~3\\GOEC62~1.DLL"
                "LoadAppInit_DLLs"=dword:00000001

                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                "System"=""

                »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                »»»»»»»»»»»»»»»»»»»»»»»» DNS

                Description: Intel(R) PRO/100 VE Network Connection - Miniport d'ordonnancement de paquets
                DNS Server Search Order: 192.168.1.2

                Description: AOLbox - Miniport d'ordonnancement de paquets
                DNS Server Search Order: 192.168.1.1

                HKLM\SYSTEM\CCS\Services\Tcpip\..\{5D9B9945-C887-4F4E-9972-38216B68036D}: NameServer=192.168.1.2
                HKLM\SYSTEM\CCS\Services\Tcpip\..\{71B4C5EC-6F49-41FF-921C-B1C9D1EDB07F}: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CCS\Services\Tcpip\..\{FF0F230D-72E2-4E75-9C9B-4EFE8136A3CD}: NameServer=192.168.1.1
                HKLM\SYSTEM\CS1\Services\Tcpip\..\{5D9B9945-C887-4F4E-9972-38216B68036D}: NameServer=192.168.1.2
                HKLM\SYSTEM\CS1\Services\Tcpip\..\{71B4C5EC-6F49-41FF-921C-B1C9D1EDB07F}: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CS1\Services\Tcpip\..\{FF0F230D-72E2-4E75-9C9B-4EFE8136A3CD}: NameServer=192.168.1.1
                HKLM\SYSTEM\CS2\Services\Tcpip\..\{5D9B9945-C887-4F4E-9972-38216B68036D}: NameServer=192.168.1.2
                HKLM\SYSTEM\CS2\Services\Tcpip\..\{71B4C5EC-6F49-41FF-921C-B1C9D1EDB07F}: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CS2\Services\Tcpip\..\{FF0F230D-72E2-4E75-9C9B-4EFE8136A3CD}: NameServer=192.168.1.1
                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                »»»»»»»»»»»»»»»»»»»»»»»» Fin
                0
            2. non c mon bof il est a coté de moi vu que je comprend rien il est venu m aider il a des notions en informatique lui
              c' est le resultat de hijack sur mon pc qu il a editer
              0
              1. Contributeur sécurité
                Pardon?

                Si tu n'es pas l'auteur du poste, crée toi ton propre poste.

                a+
                0
                1. je me trouve avec la demoiselle voila ce qu on trouve
                  avec antivir hadjajr.ini trojan horse TR/Qhost.MY.2

                  avec hijackLogfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 20:06:55, on 01/10/2007
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16512)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                  C:\WINDOWS\System32\FTRTSVC.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  C:\WINDOWS\ehome\ehtray.exe
                  C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
                  C:\WINDOWS\eHome\ehmsas.exe
                  C:\WINDOWS\system32\rundll32.exe
                  C:\Program Files\QuickTime\qttask.exe
                  C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\Program Files\SPYWAREfighter\spftray.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\MSN Messenger\MsnMsgr.Exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\AntiVir PersonalEdition Classic\avcenter.exe
                  C:\WINDOWS\system32\HPZipm12.exe
                  C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
                  C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
                  C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
                  C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
                  C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
                  C:\Program Files\Wanadoo\GestionnaireInternet.exe
                  C:\Program Files\Wanadoo\ComComp.exe
                  C:\PROGRA~1\Wanadoo\Toaster.exe
                  C:\PROGRA~1\Wanadoo\Inactivity.exe
                  C:\PROGRA~1\Wanadoo\PollingModule.exe
                  C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                  C:\Program Files\Wanadoo\Watch.exe
                  C:\Program Files\MSN Messenger\usnsvc.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Documents and Settings\Natalia\Bureau\text.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                  O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                  O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
                  O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
                  O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                  O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
                  O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
                  O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
                  O4 - HKLM\..\Run: [BDSwitchAgent] "C:\progra~1\softwin\bitdef~1\bdswitch.exe"
                  O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                  O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKLM\..\Run: [spywarefighterguard] C:\Program Files\SPYWAREfighter\spftray.exe
                  O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
                  O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                  O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\eMule.exe -AutoStart
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                  O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = ?
                  O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                  O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                  O14 - IERESET.INF: START_PAGE_URL=https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                  O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
                  O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - https://www.eset.com/
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O20 - AppInit_DLLs: C:\WINDOWS\system32\hadjajr.ini
                  O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
                  O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                  0
                  1. Contributeur sécurité
                    Bienvenue sur le forum d’entraide de CommentCaMarche.net

                    Nous connaissons votre situation et nous vous conseillons de ne surtout pas vous inquiéter.
                    De plus, au vu du nombre croissant de désinfections effectuées sur le forum, nous vous demandons un peu de patience et surtout de ne pas créer plusieurs postes pour le même problème.
                    Merci de votre compréhension.

                    Télécharge HijackThis ici:
                    http://telechargement.zebulon.fr/138-hijackthis-1991.html

                    Dézippe le dans un dossier prévu à cet effet.
                    Par exemple C:\hijackthis < Enregistre-le bien dans c : !
                    Démo : (Merci a Balltrap34 pour cette réalisation)
                    http://pageperso.aol.fr/balltrap34/Hijenr.gif

                    Lance le puis:
                    Clique sur "do a system scan and save logfile" (cf démo)
                    Faire un copier coller du log entier sur le forum

                    Démo : (Merci a Balltrap34 pour cette réalisation)
                    http://pageperso.aol.fr/balltrap34/demohijack.htm

                    Bon courage

                    A+
                    0