Même problème que kwini

Résolu
Bonjour,
HELP !! J'ai exactement le même problème que kwini. Je suis sans cesse redirigée vers des pages telles que livesearch, everydayhealth ou beddidle...J'ai téléchargé et renommé HighJackThis et j'ai le log suivant :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:47:15, on 28/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\LaCie\Backup Software\LaCieBackup.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HJT.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] "%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe"
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [ChangeResolution] C:\Documents and Settings\Administrateur\ChangeResolution.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LaCie Backup] C:\Program Files\LaCie\Backup Software\\LaCieBackup.exe /background
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 8219 bytes

Merci par avance !
Configuration: Windows XP
Firefox 3.0.3

27 réponses

Résumé de la discussion

Problème de redirections intempestives vers des pages comme livesearch et beddidle, signalé avec un log HijackThis détaillant de nombreuses entrées au démarrage et des modules Browser Helper Objects problématiques. Des solutions évoquées incluent des nettoyages en mode sans échec avec SmitFraudFix, l'utilisation de JavaRa pour nettoyer les anciennes versions Java, puis ComboFix pour neutraliser les composants malveillants et lier les restaurations. Les échanges montrent aussi des conseils complémentaires sur l'évaluation des résultats avec JavaRa et la nécessité de poster un nouveau rapport HijackThis après chaque étape, afin d'assurer une extinction complète des infections.

Bobot (l’IA à votre service)
  1. Bonjour,

    J'ai le meme pb, c"est à dire, que lorque je lance une recherche avec google à partir de IE, le lien de redirige vers "Bedibble" ou un autre site du genre. J'ai lu vos aides apportés à Kwini ou Jaam, et est-ce leur solution peut etre appliqué à mon PC?
    Merci par avance pour votre aide
    0
    1. Contributeur sécurité
      oui si tu ne veux pas télécharger le logiciel tu peux le supprimer de ton bureau..

      voilà tout est fait ;-)

      je dois partir donc je te souhaite de passer une bonne soirée..

      à une prochaine fois peut etre ;-)
      0
      1. Ah non en fait c'est un raccourci qui m'envoie sur le site de java où je peux télécharger openoffice...Je pense que je peux le supprimer alors...
        0
        1. Contributeur sécurité
          pour le point de restauration tu as tout compris à son fonctionnement ;-)

          le fichier d openoffice que tu as sur ton bureau c est le fichier d installation ??
          0
          1. J'ai fait tout ce que tu m'as dit. Voici le rapport de Toolscanner. J'ai oublié de te demander 2 choses :
            - quand j'ai mis à jour java, il m'a rajouté openoffice.org sur mon bureau...j'en fais quoi ?
            - le point de restauration du système que j'ai créé me sert à revenir à ce stade si à l'avenir je suis re-infectée ou rien à voir ?
            Encore merci.

            [ Rapport ToolsCleaner version 2.2.3 (par A.Rothstein & dj QUIOU) ]

            -->- Recherche:

            C:\Combofix.txt: trouvé !
            C:\fixnavi.txt: trouvé !
            C:\Qoobox: trouvé !
            C:\Documents and Settings\Administrateur\Bureau\HijackThis.lnk: trouvé !
            C:\Documents and Settings\Administrateur\Bureau\Navilog1.exe: trouvé !
            C:\Documents and Settings\Administrateur\Bureau\ComboFix.exe: trouvé !
            C:\Documents and Settings\Administrateur\Bureau\SmitFraudFix.exe: trouvé !
            C:\Documents and Settings\Administrateur\Bureau\hijackthis.log: trouvé !
            C:\Documents and Settings\Administrateur\Bureau\SmitFraudfix: trouvé !
            C:\Documents and Settings\Administrateur\Recent\HijackThis.lnk: trouvé !
            C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: trouvé !
            C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
            C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: trouvé !
            C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
            C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: trouvé !
            C:\Program Files\Navilog1: trouvé !
            C:\Program Files\Navilog1\Navilog1.bat: trouvé !
            C:\Program Files\Trend Micro\HijackThis: trouvé !
            C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !

            ---------------------------------
            -->- Suppression:

            C:\Documents and Settings\Administrateur\Bureau\HijackThis.lnk: supprimé !
            C:\Documents and Settings\Administrateur\Bureau\Navilog1.exe: supprimé !
            C:\Documents and Settings\Administrateur\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
            C:\Documents and Settings\Administrateur\Bureau\SmitFraudFix.exe: supprimé !
            C:\Documents and Settings\Administrateur\Recent\HijackThis.lnk: supprimé !
            C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: supprimé !
            C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
            C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: supprimé !
            C:\Program Files\Navilog1\Navilog1.bat: supprimé !
            C:\Combofix.txt: supprimé !
            C:\fixnavi.txt: supprimé !
            C:\Documents and Settings\Administrateur\Bureau\hijackthis.log: supprimé !
            C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
            C:\Qoobox: supprimé !
            C:\Documents and Settings\Administrateur\Bureau\SmitFraudfix: supprimé !
            C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
            C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: supprimé !
            C:\Program Files\Navilog1: supprimé !
            C:\Program Files\Trend Micro\HijackThis: supprimé !

            Fichiers temporaires nettoyés !
            0
            1. Contributeur sécurité
              ok mais de rien ;-)

              C est pour cela que je te demandais si tu n avais plus de problèmes :-D

              Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques :

              ▶ Télécharge Toolscleaner sur ton Bureau :

              (c est le numéro 15 en bas de la page)

              ▶ Double-clique sur ToolsCleaner2.exe et laisse le travailler
              ▶ Clique sur Recherche et laisse le scan se terminer.
              ▶ Clique sur Suppression pour finaliser.
              ▶ Tu peux, si tu le souhaites, te servir des Options facultatives.
              ▶ Clique sur Quitter, pour que le rapport puisse se créer.
              ▶ Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse

              Désactive et réactive la Restauration du système :

              1 Dans la barre des tâches de Windows, clique sur Démarrer.

              2 Clique avec le bouton droit de la souris sur Poste de travail puis clique sur Propriétés.

              3 Dans l'onglet Restauration du système, coche "Désactiver la Restauration du système"

              4 Clique sur Appliquer.

              5 Ensuite décoche "Désactiver la restauration du systeme"

              6 clique sur appliquer puis ok

              7 vas créer un point de restauration en cliquant sur démarrer => tous les programmes => accessoires =>

              outils systeme => restauration du systeme => créer un point de restauration => tu mets un nom

              (exemple : après désinfection sur CCM) puis tu valides.

              PS : les liens de toolscleaner, etc... C est mon site web si ca peut t aider ;-)
              0
              1. En tout cas, un grand merci :)
                Et dernière petite question : est-ce que je garde tout ce que j'ai installé lors de cette grande procédure de "nettoyage" ?
                0
                1. A priori je n'ai plus de problèmes. Voici le rapport :

                  JavaRa 1.11 Removal Log.

                  Report follows after line.

                  ------------------------------------

                  The JavaRa removal process was started on Sun Sep 28 23:09:07 2008

                  Found and removed: C:\Program Files\Java\jre1.5.0

                  Found and removed: Software\JavaSoft\Java2D\1.5.0

                  Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}

                  Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510000

                  Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510000

                  Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510000

                  Found and removed: SOFTWARE\Classes\JavaPlugin.150

                  Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

                  Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0

                  Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5

                  Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0

                  Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}

                  Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510000

                  Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510000

                  Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150000}

                  Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

                  Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0\

                  Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

                  Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

                  Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

                  Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

                  Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

                  Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

                  Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

                  ------------------------------------

                  Finished reporting.
                  0
                  1. Contributeur sécurité
                    ▶ Télécharge JavaRa.zip

                    ▶ Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)

                    ▶ Double-clique sur le répertoire JavaRa obtenu.

                    ▶ Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)

                    ▶ Clique sur Search For Updates.

                    ▶ Sélectionne Update Using jucheck.exe puis clique sur Search.

                    ▶ Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.

                    ▶ Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.

                    ▶ Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.

                    ▶ Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.

                    * Note : le rapport se trouve aussi là : ( C:\JavaRa.log )

                    ▶ Ferme l'application.

                    est ce que tu as encore des problemes ??
                    0
                    1. Et voici celui de high jack this (sans avoir redémarré) :

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 17:15:33, on 28/09/2008
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\WINDOWS\system32\igfxtray.exe
                      C:\WINDOWS\system32\hkcmd.exe
                      C:\WINDOWS\AGRSMMSG.exe
                      C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                      C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                      C:\WINDOWS\system32\dla\tfswctrl.exe
                      C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
                      C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
                      C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\LaCie\Backup Software\LaCieBackup.exe
                      C:\Program Files\Windows Media Player\WMPNSCFG.exe
                      C:\Program Files\FinePixViewer\QuickDCF.exe
                      C:\Program Files\HPQ\SHARED\HPQWMI.exe
                      C:\WINDOWS\system32\wbem\wmiapsrv.exe
                      C:\WINDOWS\system32\notepad.exe
                      C:\WINDOWS\explorer.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Program Files\Trend Micro\HijackThis\HJT.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
                      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                      O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                      O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                      O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
                      O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
                      O4 - HKLM\..\Run: [hpWirelessAssistant] "%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe"
                      O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
                      O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
                      O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [LaCie Backup] C:\Program Files\LaCie\Backup Software\\LaCieBackup.exe /background
                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                      O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
                      O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
                      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
                      O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                      O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
                      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                      0
                      1. Voici le rapport de combofix (NB : il n'y a pas eu de redémarrage) :
                        ComboFix 08-09-27.03 - Administrateur 2008-09-28 17:08:42.2 - NTFSx86
                        Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.200 [GMT 2:00]
                        Lancé depuis: C:\Documents and Settings\Administrateur\Bureau\ComboFix.exe
                        Commutateurs utilisés :: C:\Documents and Settings\Administrateur\Bureau\CFScript.txt
                        * Un nouveau point de restauration a été créé

                        [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]

                        FILE ::
                        c:\program files\internet explorer\iekey.dll
                        c:\windows\system32\tdssadw.dll
                        c:\windows\system32\tdssinit.dll
                        c:\windows\system32\tdssl.dll
                        c:\windows\system32\tdsslog.dll
                        c:\windows\system32\tdssmain.dll
                        c:\windows\system32\tdssserf.dll
                        c:\windows\system32\tdssservers.dat
                        .

                        (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                        .

                        c:\windows\system32\tdsslog.dll
                        c:\windows\system32\tdssserf.dll

                        .
                        ((((((((((((((((((((((((((((( Fichiers créés du 2008-08-28 au 2008-09-28 ))))))))))))))))))))))))))))))))))))
                        .

                        2008-09-28 15:14 . 2008-09-28 15:32 4,348 --a------ C:\WINDOWS\system32\tmp.reg
                        2008-09-28 14:41 . 2008-09-28 14:44 <REP> d-------- C:\Program Files\Navilog1
                        2008-09-28 12:45 . 2008-09-28 12:45 <REP> d-------- C:\Program Files\Trend Micro
                        2008-09-28 11:10 . 2008-09-28 11:10 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                        2008-09-28 11:10 . 2008-09-28 11:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                        2008-09-28 11:10 . 2008-09-28 11:10 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
                        2008-09-28 11:10 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
                        2008-09-28 11:10 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
                        2008-09-27 21:11 . 2008-09-28 12:05 8,192 --a------ C:\WINDOWS\system32\tdssserf1.dll
                        2008-09-18 21:22 . 2008-09-18 21:23 <REP> d-------- C:\Program Files\PDFCreator
                        2008-09-18 21:22 . 2004-03-09 00:00 662,288 --a------ C:\WINDOWS\system32\MSCOMCT2.OCX
                        2008-09-18 21:22 . 2005-10-15 12:32 196,608 --a------ C:\WINDOWS\system32\pdfcmnnt.dll
                        2008-09-18 21:22 . 1998-07-13 01:08 141,312 --a------ C:\WINDOWS\system32\MSCMCFR.DLL
                        2008-09-18 21:22 . 1998-06-24 00:00 137,000 --a------ C:\WINDOWS\system32\MSMAPI32.OCX
                        2008-09-18 21:22 . 1998-07-13 01:08 119,568 --a------ C:\WINDOWS\system32\VB6FR.DLL
                        2008-09-18 21:22 . 1998-07-13 01:08 59,904 --a------ C:\WINDOWS\system32\MSCC2FR.DLL
                        2008-09-18 21:22 . 1998-07-06 00:00 23,552 --a------ C:\WINDOWS\system32\MSMPIDE.DLL

                        .
                        (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        2008-09-28 08:32 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\uTorrent
                        2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
                        2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
                        2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
                        2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
                        2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
                        2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
                        2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
                        2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
                        2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
                        2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
                        2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
                        2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
                        2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
                        2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
                        2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
                        2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
                        2008-07-07 20:31 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
                        2007-01-19 21:25 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
                        2006-05-14 16:16 61,248 ----a-w C:\Documents and Settings\Administrateur\Application Data\GDIPFONTCACHEV1.DAT
                        .

                        ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        .
                        *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                        REGEDIT4

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
                        "LaCie Backup"="C:\Program Files\LaCie\Backup Software\\LaCieBackup.exe" [2006-01-24 2633728]
                        "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
                        "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-11-16 155648]
                        "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-11-16 126976]
                        "SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
                        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0\bin\jusched.exe" [2005-04-18 36972]
                        "UpdateManager"="C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
                        "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-08-03 122939]
                        "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 98394]
                        "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 688218]
                        "eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-11-01 290816]
                        "Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2004-09-07 213054]
                        "hpWirelessAssistant"="C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe" [2004-11-12 790528]
                        "WatchDog"="C:\Program Files\InterVideo\DVD Check\DVDCheck.exe" [2004-10-26 184320]
                        "REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
                        "Ulead AutoDetector v2"="C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe" [2004-08-27 90112]
                        "AGRSMMSG"="AGRSMMSG.exe" [2004-08-24 C:\WINDOWS\AGRSMMSG.exe]

                        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                        "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15360]

                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                        "msacm.divxa32"= msaud32_divx.acm

                        [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                        "AntiVirusOverride"=dword:00000001

                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                        "%windir%\\system32\\sessmgr.exe"=
                        "C:\\Program Files\\Messenger\\msmsgs.exe"=
                        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                        "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
                        "C:\\Program Files\\MSN Messenger\\livecall.exe"=
                        "C:\\Program Files\\uTorrent\\uTorrent.exe"=
                        "C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=

                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                        "2737:UDP"= 2737:UDP:Windows Media Format SDK (firefox.exe)
                        "2736:UDP"= 2736:UDP:Windows Media Format SDK (firefox.exe)

                        R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
                        R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
                        S3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2004-05-03 80384]

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4d3a6d3e-86a6-11da-8a3a-0012f010e6fe}]
                        \Shell\AutoRun\command - ie.exe
                        \Shell\explore\Command - ie.exe
                        \Shell\open\Command - ie.exe

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{54ef1c5c-2a67-11dd-8d9b-0012f010e6fe}]
                        \Shell\AutoRun\command - WD_Windows_Tools\Setup.exe

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f7cfa3e6-c353-11db-8aaa-0012f010e6fe}]
                        \Shell\AutoRun\command - E:\ie.exe
                        \Shell\explore\Command - E:\ie.exe
                        \Shell\open\Command - E:\ie.exe
                        .

                        **************************************************************************

                        catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                        Rootkit scan 2008-09-28 17:10:56
                        Windows 5.1.2600 Service Pack 2 NTFS

                        Recherche de processus cachés ...

                        Recherche d'éléments en démarrage automatique cachés ...

                        HKLM\Software\Microsoft\Windows\CurrentVersion\Run
                        Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????5?6?3?0??????? ???B???????????????B? ??????

                        Recherche de fichiers cachés ...

                        Scan terminé avec succès
                        Fichiers cachés: 0

                        **************************************************************************
                        .
                        Heure de fin: 2008-09-28 17:12:23
                        ComboFix-quarantined-files.txt 2008-09-28 15:12:11
                        ComboFix2.txt 2008-09-28 14:45:11

                        Avant-CF: 4ÿ788ÿ801ÿ536 octets libres
                        Après-CF: 4,787,613,696 octets libres

                        139 --- E O F --- 2008-09-28 08:21:56
                        0
                        1. Contributeur sécurité
                          oui tu avais bien aussi antispywareExpert mais il a été supprimé par smitfraudfix et malwarebytes ;-)

                          fais ce que je t ai demandé au message précédent, je reviendrai tout à l heure pour vérifier tes rapports

                          @+
                          0
                          1. Contributeur sécurité
                            ▶ Copie le texte en gras ci-dessous :

                            File::
                            c:\program files\internet explorer\iekey.dll
                            c:\windows\system32\tdssadw.dll
                            c:\windows\system32\tdssinit.dll
                            c:\windows\system32\tdssl.dll
                            c:\windows\system32\tdssmain.dll
                            c:\windows\system32\tdssservers.dat
                            c:\windows\system32\tdssserf.dll
                            c:\windows\system32\tdsslog.dll

                            Folder::

                            Registry::


                            ▶ Ouvre le Bloc-Notes puis colle le texte copié.
                            (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
                            ▶ Sauvegarde ce fichier sous le nom de CFScript.txt.

                            ▶ Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

                            http://sd-1.archive-host.com/membres/up/1366464061/CFScript.gif

                            ▶ Cela va relancer Combofix,

                            ▶ Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

                            ▶ Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

                            Ne touche à rien tant que le scan n'est pas terminé.

                            ▶ Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

                            ▶ S'il n'y a pas de rédémarrage, poste quand même les rapports.

                            @+
                            0
                            1. ALLELUIA !!! Je crois que c'est bon. En cliquant sur les liens de google quand je fais une recherche, je tombe sur la bonne page et non sur beddidle et compagnie...C'est fou ! MERCI pour ton savoir. Je ne sais pas si ça va avec le problème de redirection vers les pages sus mentionnées, mais je voulais te dire que j'ai eu de manière concomitante un truc affreux qui s'appelle antispyware expert qui s'installe tout seul et qui utilise un peu les mêmes logos que windows...J'ai l'impression que tout est parti...
                              0
                              1. Alors j'ai récupéré combofix.exe à partir d'un autre ordinateur et j'ai lancé l'analyse. Je n'ai pas téléchargé la console de récupération...C'est grave? En tout cas voici ce qu'il me sort :

                                ComboFix 08-09-27.03 - Administrateur 2008-09-28 16:34:45.1 - NTFSx86
                                Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.188 [GMT 2:00]
                                Lancé depuis: C:\Documents and Settings\Administrateur\Bureau\ComboFix.exe
                                * Un nouveau point de restauration a été créé

                                [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                                .

                                (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                .

                                C:\Documents and Settings\Administrateur\Cookies\administrateur@bluestreak[2].txt
                                C:\Documents and Settings\Administrateur\Cookies\administrateur@edt02[2].txt
                                C:\Program Files\internet explorer\iekey.dll
                                C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
                                C:\WINDOWS\system32\drivers\tdssserv.sys
                                C:\WINDOWS\system32\tdssadw.dll
                                C:\WINDOWS\system32\tdssinit.dll
                                C:\WINDOWS\system32\tdssl.dll
                                C:\WINDOWS\system32\tdssmain.dll
                                C:\WINDOWS\system32\tdssservers.dat

                                .
                                ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                                .

                                -------\Legacy_TDSSSERV
                                -------\Service_TDSSserv

                                ((((((((((((((((((((((((((((( Fichiers créés du 2008-08-28 au 2008-09-28 ))))))))))))))))))))))))))))))))))))
                                .

                                2008-09-28 15:14 . 2008-09-28 15:32 4,348 --a------ C:\WINDOWS\system32\tmp.reg
                                2008-09-28 14:41 . 2008-09-28 14:44 <REP> d-------- C:\Program Files\Navilog1
                                2008-09-28 12:45 . 2008-09-28 12:45 <REP> d-------- C:\Program Files\Trend Micro
                                2008-09-28 11:10 . 2008-09-28 11:10 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                                2008-09-28 11:10 . 2008-09-28 11:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                                2008-09-28 11:10 . 2008-09-28 11:10 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
                                2008-09-28 11:10 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
                                2008-09-28 11:10 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
                                2008-09-27 21:11 . 2008-09-28 12:05 12,288 --a------ C:\WINDOWS\system32\tdssserf.dll
                                2008-09-27 21:11 . 2008-09-28 12:05 11,264 --a------ C:\WINDOWS\system32\tdsslog.dll
                                2008-09-27 21:11 . 2008-09-28 12:05 8,192 --a------ C:\WINDOWS\system32\tdssserf1.dll
                                2008-09-18 21:22 . 2008-09-18 21:23 <REP> d-------- C:\Program Files\PDFCreator
                                2008-09-18 21:22 . 2004-03-09 00:00 662,288 --a------ C:\WINDOWS\system32\MSCOMCT2.OCX
                                2008-09-18 21:22 . 2005-10-15 12:32 196,608 --a------ C:\WINDOWS\system32\pdfcmnnt.dll
                                2008-09-18 21:22 . 1998-07-13 01:08 141,312 --a------ C:\WINDOWS\system32\MSCMCFR.DLL
                                2008-09-18 21:22 . 1998-06-24 00:00 137,000 --a------ C:\WINDOWS\system32\MSMAPI32.OCX
                                2008-09-18 21:22 . 1998-07-13 01:08 119,568 --a------ C:\WINDOWS\system32\VB6FR.DLL
                                2008-09-18 21:22 . 1998-07-13 01:08 59,904 --a------ C:\WINDOWS\system32\MSCC2FR.DLL
                                2008-09-18 21:22 . 1998-07-06 00:00 23,552 --a------ C:\WINDOWS\system32\MSMPIDE.DLL

                                .
                                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                2008-09-28 08:32 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\uTorrent
                                2007-01-19 21:25 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
                                2006-05-14 16:16 61,248 ----a-w C:\Documents and Settings\Administrateur\Application Data\GDIPFONTCACHEV1.DAT
                                .

                                ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                .
                                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                REGEDIT4

                                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
                                "LaCie Backup"="C:\Program Files\LaCie\Backup Software\\LaCieBackup.exe" [2006-01-24 2633728]
                                "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
                                "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-11-16 155648]
                                "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-11-16 126976]
                                "SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
                                "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0\bin\jusched.exe" [2005-04-18 36972]
                                "UpdateManager"="C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
                                "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-08-03 122939]
                                "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 98394]
                                "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 688218]
                                "eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-11-01 290816]
                                "Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2004-09-07 213054]
                                "hpWirelessAssistant"="C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe" [2004-11-12 790528]
                                "WatchDog"="C:\Program Files\InterVideo\DVD Check\DVDCheck.exe" [2004-10-26 184320]
                                "REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
                                "Ulead AutoDetector v2"="C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe" [2004-08-27 90112]
                                "AGRSMMSG"="AGRSMMSG.exe" [2004-08-24 C:\WINDOWS\AGRSMMSG.exe]

                                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15360]

                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                                "msacm.divxa32"= msaud32_divx.acm

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                                "AntiVirusOverride"=dword:00000001

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                "%windir%\\system32\\sessmgr.exe"=
                                "C:\\Program Files\\Messenger\\msmsgs.exe"=
                                "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
                                "C:\\Program Files\\MSN Messenger\\livecall.exe"=
                                "C:\\Program Files\\uTorrent\\uTorrent.exe"=
                                "C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                                "2737:UDP"= 2737:UDP:Windows Media Format SDK (firefox.exe)
                                "2736:UDP"= 2736:UDP:Windows Media Format SDK (firefox.exe)

                                R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
                                R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
                                S3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2004-05-03 80384]

                                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4d3a6d3e-86a6-11da-8a3a-0012f010e6fe}]
                                \Shell\AutoRun\command - ie.exe
                                \Shell\explore\Command - ie.exe
                                \Shell\open\Command - ie.exe

                                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{54ef1c5c-2a67-11dd-8d9b-0012f010e6fe}]
                                \Shell\AutoRun\command - WD_Windows_Tools\Setup.exe

                                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f7cfa3e6-c353-11db-8aaa-0012f010e6fe}]
                                \Shell\AutoRun\command - E:\ie.exe
                                \Shell\explore\Command - E:\ie.exe
                                \Shell\open\Command - E:\ie.exe
                                .
                                - - - - ORPHELINS SUPPRIMES - - - -

                                HKCU-Run-WOOKIT - C:\PROGRA~1\Wanadoo\Shell.exe
                                HKLM-Run-ChangeResolution - C:\Documents and Settings\Administrateur\ChangeResolution.exe
                                Notify-WgaLogon - (no file)

                                .
                                ------- Examen supplémentaire -------
                                .
                                FireFox -: Profile - C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\gjvfh7mr.default\
                                FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
                                FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.orange.fr
                                FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
                                FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
                                FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava11.dll
                                FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava12.dll
                                FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava13.dll
                                FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava14.dll
                                FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava32.dll
                                FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJPI150.dll
                                FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPOJI610.dll
                                .

                                **************************************************************************

                                catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                Rootkit scan 2008-09-28 16:39:51
                                Windows 5.1.2600 Service Pack 2 NTFS

                                Recherche de processus cachés ...

                                Recherche d'éléments en démarrage automatique cachés ...

                                HKLM\Software\Microsoft\Windows\CurrentVersion\Run
                                Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????5?6?3?0??????? ???B???????????????B? ??????

                                Recherche de fichiers cachés ...

                                Scan terminé avec succès
                                Fichiers cachés: 0

                                **************************************************************************
                                .
                                ------------------------ Autres processus actifs ------------------------
                                .
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                C:\WINDOWS\system32\scardsvr.exe
                                C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                                C:\Program Files\Windows Media Player\wmpnetwk.exe
                                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                C:\Program Files\LaCie\Backup Software\LacieBackup.exe
                                C:\Program Files\FinePixViewer\QuickDCF.exe
                                C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                C:\Program Files\HPQ\Shared\hpqwmi.exe
                                C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                .
                                **************************************************************************
                                .
                                Heure de fin: 2008-09-28 16:45:09 - La machine a redémarré
                                ComboFix-quarantined-files.txt 2008-09-28 14:45:03

                                Avant-CF: 4ÿ860ÿ252ÿ160 octets libres
                                Après-CF: 4,813,115,392 octets libres

                                162 --- E O F --- 2008-09-28 08:21:56
                                0
                                1. Contributeur sécurité
                                  essayes avec internet explorer...chez moi ca marche avec firefox :s
                                  0
                                  1. Je n'arrive pas à télécharger combofix, ni à accéder à la page de Bleeping computer :
                                    "La connexion a échoué
                                    Firefox ne peut établir de connexion avec le serveur à l'adresse www.bleepingcomputer.com."
                                    0
                                    1. Contributeur sécurité
                                      ok maintenant fais combofix stp
                                      0
                                      1. Et voici :

                                        SmitFraudFix v2.354

                                        Rapport fait à 15:30:54,65, 28/09/2008
                                        Executé à partir de C:\Documents and Settings\Administrateur\Bureau\SmitfraudFix
                                        OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                                        Le type du système de fichiers est
                                        Fix executé en mode sans echec

                                        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                        SrchSTS.exe by S!Ri
                                        Search SharedTaskScheduler's .dll

                                        »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                                        »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                        127.0.0.1 localhost

                                        »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                                        VACFix
                                        Credits: Malware Analysis & Diagnostic
                                        Code: S!Ri

                                        »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                                        S!Ri's WS2Fix: LSP not Found.

                                        »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                                        GenericRenosFix by S!Ri

                                        »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                                        C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\AntiSpywareExpert supprimé

                                        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                                        IEDFix
                                        Credits: Malware Analysis & Diagnostic
                                        Code: S!Ri

                                        »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                                        404Fix
                                        Credits: Malware Analysis & Diagnostic
                                        Code: S!Ri

                                        »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

                                        »»»»»»»»»»»»»»»»»»»»»»»» RK

                                        »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{84598CBA-5281-4C71-9627-578755E02ABD}: DhcpNameServer=192.168.1.1
                                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{84598CBA-5281-4C71-9627-578755E02ABD}: DhcpNameServer=192.168.1.1
                                        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                                        »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                                        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                        "System"=""

                                        »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                                        Nettoyage terminé.

                                        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                        SrchSTS.exe by S!Ri
                                        Search SharedTaskScheduler's .dll

                                        »»»»»»»»»»»»»»»»»»»»»»»» Fin
                                        0
                                        • 1
                                        • 2