Spyware-secure/com

Résolu
Bonjour,

En lisant différents article sur le foru je me rend compte que je ne suis pas le seul a avoir des roblèmes avec spyware-secure
Depuis ce matin il me dit que je suis infecte et je n'arrive pour ainsi dire a me conecter aun site sans qu'il ne vienne deranger tout
uune pecision j'ai installer messenger skinner voila un jour ou deux , je l'ai desintallé
quelqu'un peut m'aider
d'avance merci

j'oubliais bonne année à tous

gegifa
Configuration: Windows XP
Internet Explorer 7.0  +   mozilla firefoa

44 réponses

Résumé de la discussion

Une infection par spyware-secure sur Windows XP bloque l’accès à Internet et affiche des alertes d’infection après l’installation puis la désinstallation d’un module prétendument lié à Messenger Skinner. Des réponses recommandent des analyses et nettoyages avec des outils spécialisés tels que HijackThis, SmitfraudFix et Navilog, puis un redémarrage en mode Sans Échec et la suppression des éléments suspects. D'autres conseils évoquent des protections gratuites (antivirus, pare-feu et antispyware) et recommandent d’éviter les solutions payantes non fiables, tout en mettant en avant l’importance de mises à jour Windows, Java et du navigateur. Des messages insistent aussi sur l’échange de rapports techniques (navilog, logs) pour analyse et éviter des suppressions sans vérification.

Bobot (l’IA à votre service)
  1. bonsoir gegifa ! de rien ! bitdefender est tres bien ! n'hesite pas si tu as des questions je serais ici ! lol

    bonne soiree !
    1. CARROSIER13

      j AI MENTIONNE QUE LE PROBLEME ETAIT RESOLU MAIS J AURAI ENCORE PEUT ETRE BESOIN DE TES CONSEILS ALORS JE NE VOUDRAIS PAS QUE LES PONTS SOIT COUPES ET JE NE SAIS COMMENT FAIRE

      SALUT ET BONNE SOIREE

      GEGIFA
      1. BONSOIR CARROSIER13

        AVANT TOUTE CHOSE JE TIENS A TE REMERCIER DE TOUTE L'AIDE ET DE PATIENCE QUE TU M'AS APPORTEE TOUT AU LONG DE NOTRE DIALOGUE.LLES PROBLEMES SONT TERMINES,ET CONCERNANT IMAGE ZONE J'AI POSE LE PROBLEME A LA FIRME HP.CONCERNANT NORTON JE VAIS M'EN DEFAIRE ,QUE PENSES-TU DE BITDEFENDER ON M'EN A DIT BEAUCOUP DE BIEN,FERAIT IL LE MEME TRAVAIL QUE TOUS LES PROGAMMES QUE TU ME DONNES DANS TON DERNIER MESSAGE JE SAIS IL EST PAYANT CELA NE CAUSE PAS DE PROBLEME
        ENCORE MERCI POUR TA COOPERATION

        GEGIFA
        1. bonsoir gegifa , tu vas bien ? ou en est ton petit disfonctionnement ?

          voici que je peu te proposer comme protection gratuite! (inspire by g!rly)

          outils de desinstalation de norton ( il le fait tres mal tout seul !) http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/e1422b2508cec946882568c70062bbf8/1168d30686f6fdb080256fe3003757be?OpenDocument

          voici ce que je peux te proposer pour te proteger, c´est ce que j´ai d´installé sur mon pc...

          anti virus : antivir

          https://www.malekal.com/avira-free-security-antivirus-gratuit/

          http://mickael.barroux.free.fr/securite/antivir.php <- tutoriel + complet

          pare feu zone alarm :http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/zonealarm-tutorial-sujet_169658_1.htm

          firefox : http://www.commentcamarche.net/telecharger/telechargement 111 firefox car plus seururise et plus performant ( garde explorer pour mises a jours window et scannes en ligne )

          l´utilisation de firefox et de ad blok plus par exemple ( plug in firefox)

          https://www.hugedomains.com/domain_profile.cfm?d=geckozone&e=org

          moi j´utilise aussi le plug in https://addons.mozilla.org/fr/firefox/addon/433 il bloque les annimations flash et les remplace par un f clickable pour voir l ánnimation si desiré

          anti spyware :

          spywareblaster : tres pratique pour proteger les bho

          http://www.brightfort.com/spywareblaster.html

          c´est un resident, il suffit de le mettre a jour de temps en temps car la version gratuite ne le fait pas toute seul , une fois installé et mis a jour tu mets toutes les protections sur "enable"

          telecharge aussi cet anti spyware il a aussi un resident le teatimer :

          http://www.safer-networking.org/fr/faq/33.html

          spyware gard : complementaire a spyware blaster bho

          https://www.zebulon.fr/dossiers/securite/47-spywareguard.html

          tous les trois sont complementaires, alors si tu veux; tu peux tous les installer...

          dernieres choses :

          -> mise a jour java, par le panneau de configuration > click sur l´icone java et dans la console sur l´onglet update et met le a jour; une fois a jour (version 1.6.0_03) tu peux virer les autres updates par le panneau de configuration > ajoue et suppression de prgramme = gain de place sur disk dur ( les updates font un peut pres 100 mo chacune...)

          -> mise a jour windows par le site de microsoft...

          puis quand tu auras tout installé tu peux faire ce test de securité et rendre invisible les ports a l´aide de kerio celon ce qu´il t´affiche :

          https://www.grc.com/x/ne.dll?bh0bkyd2
          1. BOSOIR CAROSIER13

            VOICI LE RAPPORT
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 22:59, on 2008-01-17
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16574)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Defender\MsMpEng.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            C:\WINDOWS\system32\tcpsvcs.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
            C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Documents and Settings\georges guillaume\Bureau\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (file missing)
            O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
            O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
            O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
            O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -masquer
            O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
            O4 - HKLM\..\Run: [ccApp] C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
            O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
            O14 - IERESET.INF: START_PAGE_URL=http://www.tele2.be/startpage/dialup/be/fr/
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
            O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
            O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
            O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
            O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
            O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
            1. bonjour gegifa tu va bien ? relance hijackthis do a scan systeme only et fix ces lignes

              O17 - HKLM\System\CCS\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer = 130.244.127.161,130.244.127.169
              O17 - HKLM\System\CS2\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer = 130.244.127.161,130.244.127.169
              O17 - HKLM\System\CS3\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer = 130.244.127.161,130.244.127.169

              norton n'est pas bon du tout ! tu recherche plus un payant ou un antivirus free ?
              1. JE L4ai depuis le debut mais si tu as autre choses à proposer je suis ouvert à toute suggestion mais il me reste encore une centaine de jours d'abonnement.POurquoi Norton poe^se t il problème
                1. rebonsoir

                  voila hijjackthis

                  Logfile of HijackThis v1.99.1
                  Scan saved at 23:23, on 2008-01-15
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16574)

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Windows Defender\MsMpEng.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\tcpsvcs.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\WINDOWS\system32\NOTEPAD.EXE
                  C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (file missing)
                  O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                  O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
                  O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -masquer
                  O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                  O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                  O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O11 - Options group: [INTERNATIONAL] International*
                  O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                  O14 - IERESET.INF: START_PAGE_URL=http://www.tele2.be/startpage/dialup/be/fr/
                  O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer = 130.244.127.161,130.244.127.169
                  O17 - HKLM\System\CS2\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer = 130.244.127.161,130.244.127.169
                  O17 - HKLM\System\CS3\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer = 130.244.127.161,130.244.127.169
                  O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                  O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                  O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                  O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                  O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                  O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                  O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                  O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
                  O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                  O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                  O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe

                  gegifa
                  1. Bonsoir carrosier13

                    Voici le rapport fait en mode sans echec

                    SmitFraudFix v2.274

                    Rapport fait à 22:20:14.75, 2008-01-15
                    Executé à partir de C:\Documents and Settings\georges guillaume\Bureau\SmitfraudFix
                    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                    Le type du système de fichiers est NTFS
                    Fix executé en mode sans echec

                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                    127.0.0.1 localhost

                    »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                    S!Ri's WS2Fix: LSP not Found.

                    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                    GenericRenosFix by S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                    IEDFix.exe by S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer=130.244.127.161,130.244.127.169
                    HKLM\SYSTEM\CS2\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer=130.244.127.161,130.244.127.169
                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer=130.244.127.161,130.244.127.169

                    »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                    Nettoyage terminé.

                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Fin

                    Bonne soirée

                    gegifa
                    1. tutoriel demarrage mode sans echecs:http://forum.telecharger.01net.com/forum/

                      Redémarrer en mode Sans Échec (le démarrage peut prendre plusieurs minutes)
                      Attention, pas d’accès à internet dans ce mode. Enregistrer ou imprimer les consignes.
                      Relancer le Pc et tapoter la touche F8 ( ou F5 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
                      Avec les touches « flèches », sélectionner Mode sans échec ==> entrée ==>nom utilisateur habituel
                      ---
                      Relancer Smitfraudfix
                      = Choisir Option5
                      = Accepte le nettoyage du registre
                      = Sauver le rapport
                      = Copier/coller les rapports dans la réponse
                      1. Rebonsoir

                        CI joint le rapport SmitFraudFix

                        bonne nuit

                        gegifa

                        SmitFraudFix v2.274

                        Rapport fait à 22:45:59.14, 2008-01-14
                        Executé à partir de C:\Documents and Settings\georges guillaume\Bureau\SmitfraudFix
                        OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                        Le type du système de fichiers est NTFS
                        Fix executé en mode normal

                        »»»»»»»»»»»»»»»»»»»»»»»» Process

                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Windows Defender\MsMpEng.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\tcpsvcs.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                        C:\Program Files\Windows Defender\MSASCui.exe
                        C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                        C:\Program Files\Internet Explorer\IEXPLORE.EXE
                        C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                        C:\WINDOWS\system32\cmd.exe

                        »»»»»»»»»»»»»»»»»»»»»»»» hosts

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\georges guillaume

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\georges guillaume\Application Data

                        »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\GEORGE~1\Favoris

                        »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                        »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                        »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                        "Source"="About:Home"
                        "SubscribedURL"="About:Home"
                        "FriendlyName"="Ma page d'accueil"

                        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        IEDFix.exe by S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                        "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~1\\GOEC62~1.DLL"

                        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                        »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                        »»»»»»»»»»»»»»»»»»»»»»»» DNS

                        Description: Carte réseau Fast Ethernet PCI Realtek RTL8139 Family #2 - Miniport d'ordonnancement de paquets
                        DNS Server Search Order: 130.244.127.161
                        DNS Server Search Order: 130.244.127.169

                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer=130.244.127.161,130.244.127.169
                        HKLM\SYSTEM\CS2\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer=130.244.127.161,130.244.127.169
                        HKLM\SYSTEM\CS3\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer=130.244.127.161,130.244.127.169

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                        »»»»»»»»»»»»»»»»»»»»»»»» Fin
                        1. ca n'a pas marcher supprime fix wareout !

                          Télécharge SmitfraudFix (by jorginho67)
                          Utilitaire de S!Ri: Moe et balltrap34
                          http://siri.urz.free.fr/Fix/SmitfraudFix.php

                          (2) Installe le à la racine de C

                          double clique sur l'exe pour le décompresser et lancer le fix.
                          Utilisation option 1 Recherche :
                          Double clique sur smitfraudfix.cmd
                          Sélectionne 1 pour créer un rapport des fichiers responsables de l'infection.
                          Copie/colle le sur ta prochaine réponse sur ce post stp.

                          Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
                          1. rebonjour carrosier

                            comme demandé voici les 2 rapports

                            Username "georges guillaume" - 2008-01-14 16:58:32 [Fixwareout edited 9/01/2007]

                            ~~~~~ Prerun check

                            Impossible de vider la cache de résolution DNS : La fonction a échoué lors de l'exécution.

                            System was rebooted successfully.

                            ~~~~~ Postrun check
                            ....
                            ....
                            ~~~~~ Misc files.
                            ....
                            ~~~~~ Checking for older varients.
                            ....

                            ~~~~~ Current runs (hklm hkcu "run" Keys Only)
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                            "Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
                            "osCheck"="\"C:\\Program Files\\Norton Internet Security\\osCheck.exe\""
                            "Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -masquer"
                            "SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
                            "!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

                            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            "Uniblue RegistryBooster 2"="C:\\Program Files\\Uniblue\\RegistryBooster 2\\RegistryBooster.exe /S"
                            "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
                            ....
                            Hosts file was reset, If you use a custom hosts file please replace it...
                            ~~~~~ End report ~~~~~

                            <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 17:09, on 2008-01-14
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Windows Defender\MsMpEng.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\tcpsvcs.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\notepad.exe
                            C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                            C:\Program Files\Windows Defender\MSASCui.exe
                            C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                            C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Documents and Settings\georges guillaume\Bureau\HijackThis.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-be
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (file missing)
                            O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                            O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
                            O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -masquer
                            O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                            O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
                            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
                            O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                            O14 - IERESET.INF: START_PAGE_URL=http://www.tele2.be/startpage/dialup/be/fr/
                            O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                            O17 - HKLM\System\CCS\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer = 130.244.127.161,130.244.127.169
                            O17 - HKLM\System\CS2\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer = 130.244.127.161,130.244.127.169
                            O17 - HKLM\System\CS3\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer = 130.244.127.161,130.244.127.169
                            O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
                            O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                            O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                            O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
                            1. bonjour gegifa heureux que ton pc aille un peu mieux on va continuer car il reste encore quelques truc ( lignes 017 , ...)

                              télécharger FixWareout d'un de ces deux sites sur le bureau :
                              http://downloads.subratam.org/Fixwareout.exe
                              http://swandog46.geekstogo.com/Fixwareout.exe

                              * Lancer le fix, cliquer sur Next, puis Install, s'assurer que "Run fixit" est activé, ensuite cliquer sur Finish.

                              Le fix commencera, suivre les messages à l'écran. Il sera demandé à la fin de redémarrer l'ordinateur (si le système met un peu plus de temps au démarrage, c'est normal !)

                              ainsi qu'un nouveau log hijackthis
                              1. bonjour carrosier 13

                                je vais bien et mon pc aussi la connection se fait en 3 ou4 mn au lieu de 8à10 avant
                                Quand au probleme du logiciel HP image zone je recois toujours le meme message qui est le suivant

                                hipqgalry.exe Service de débobage du Common Language Runtime

                                L'applicatiion a généré une exception non gérée

                                ID processus=0Xda4(3492)IDthread=0x130c(4876)

                                CLIC pour terminer action

                                clic annuler pour deboguer application

                                voila le rapport hijackthis

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 13:49, on 2008-01-14
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                                Boot mode: Normal

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\Windows Defender\MsMpEng.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\tcpsvcs.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                C:\Program Files\Windows Defender\MSASCui.exe
                                C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\Program Files\Mozilla Firefox\firefox.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                                C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
                                C:\Documents and Settings\georges guillaume\Bureau\HijackThis.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-be
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (file missing)
                                O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
                                O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -masquer
                                O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
                                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
                                O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
                                O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                                O14 - IERESET.INF: START_PAGE_URL=http://www.tele2.be/startpage/dialup/be/fr/
                                O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                                O17 - HKLM\System\CCS\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer = 130.244.127.161,130.244.127.169
                                O17 - HKLM\System\CS2\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer = 130.244.127.161,130.244.127.169
                                O17 - HKLM\System\CS3\Services\Tcpip\..\{155C8E01-AEB6-444C-9980-34CD9912B161}: NameServer = 130.244.127.161,130.244.127.169
                                O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                                O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                                O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
                                O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                                O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                                O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
                                1. bonjour gegifa tu va bien , poste un nouveau rapport hijackthis stp !

                                  ou en sont tes problemes ??
                                  1. Bonsoir carrosier13

                                    voici les rapports que tu as demandé SDFix.exe et le log Hijackthis

                                    SDFix: Version 1.126

                                    Run by georges guillaume on 2008-01-13 at 23:13

                                    Microsoft Windows XP [version 5.1.2600]

                                    Running From: C:\SDFix

                                    Safe Mode:
                                    Checking Services:

                                    Restoring Windows Registry Values
                                    Restoring Windows Default Hosts File

                                    Rebooting...

                                    Normal Mode:
                                    Checking Files:

                                    Trojan Files Found:

                                    C:\WINDOWS\SYSTEM32\HPODST~1.DLL - Deleted

                                    Removing Temp Files...

                                    ADS Check:

                                    C:\WINDOWS
                                    No streams found.

                                    C:\WINDOWS\system32
                                    No streams found.

                                    C:\WINDOWS\system32\svchost.exe
                                    No streams found.

                                    C:\WINDOWS\system32\ntoskrnl.exe
                                    No streams found.

                                    Final Check:

                                    catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                    Rootkit scan 2008-01-13 23:21:44
                                    Windows 5.1.2600 Service Pack 2 NTFS

                                    scanning hidden processes ...

                                    scanning hidden services & system hive ...

                                    scanning hidden registry entries ...

                                    scanning hidden files ...

                                    scan completed successfully
                                    hidden processes: 0
                                    hidden services: 0
                                    hidden files: 0

                                    Remaining Services:
                                    ------------------

                                    Authorized Application Key Export:

                                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                                    "C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"
                                    "C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"="C:\\Program Files\\IncrediMail\\bin\\IMApp.exe:*:Enabled:IncrediMail"
                                    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

                                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                                    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

                                    Remaining Files:
                                    ---------------

                                    File Backups: - C:\SDFix\backups\backups.zip

                                    Files with Hidden Attributes:

                                    Wed 14 Feb 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
                                    Wed 15 Aug 2007 4,578,712 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\98b8194d1ae84b5736214021182097b9\BIT20.tmp"
                                    Thu 23 Aug 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\9ea4bd44590095c905a506afd4d5a7ce\BIT1F.tmp"
                                    Sat 12 Jan 2008 25,088 ...H. --- "C:\Documents and Settings\georges guillaume\Application Data\Microsoft\Word\~WRL0005.tmp"
                                    Sun 10 Dec 2006 1,857,536 ...H. --- "C:\Documents and Settings\georges guillaume\Application Data\Microsoft\Word\~WRL0561.tmp"
                                    Sun 10 Dec 2006 1,831,936 ...H. --- "C:\Documents and Settings\georges guillaume\Application Data\Microsoft\Word\~WRL3528.tmp"
                                    Sun 10 Dec 2006 1,831,936 ...H. --- "C:\Documents and Settings\georges guillaume\Application Data\Microsoft\Word\~WRL3588.tmp"
                                    Sun 10 Dec 2006 1,831,936 ...H. --- "C:\Documents and Settings\georges guillaume\Application Data\Microsoft\Word\~WRL3964.tmp"
                                    Tue 11 Oct 2005 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp"

                                    Finished!

                                    Dans ce dernier rapport hijackthis peux tu controler si il ny a pas encore quelque lignes a enlever
                                    un salut amlical

                                    gegifa
                                    • 1
                                    • 2
                                    • 3