Fenetre intempestive et virus

Résolu
Bonjour,

je viens souvent sur ce forum chercher des infos, et je remercie tout les membrzs actifs pour toutes les infos données, pour les internautes lambda comme moi, c'est un précieux outil d'information que ce forum.

J'ai chopé un vilain virus, Aprés plusieurs analyse, suivanty vos conseils j'ai changé dantivirus qui était avast pour antivir et ej vais dans le sens de ecrtains, la dernière analyse davst avaitpris deux heures pour ne pas trouver de virus. Pourtant monpc pataugeait toujours dans la semoule. J'ai changé installé antivir, aprés une analyse d'une petite heure antivir m'a trouvé 11 infections, donc je le pense plus efficace.

Monpc à récupérer de la vitesse d'éxécution mais il me reste quelque soucis, comme des fentres intempestives avec glairy utiltaire j'ai détecter les processus frauduleux qui sont des dll mais je ne peux les retirer, il me dit que le l'application est utilisée par une autre ressources.

donc je viens ici et sur un autre sujet, je vois que vous conseiller de faire un scan avec un logiciel ce quej'ai fait et je vouspasse donc ce scan, voir si quelqu'un aurait lagentillesse de m'aider.

Il me reste ausis un autre probléme, j'ai remaqrué que mes points de restauration avait été supprimés, sinon le probléme aurait été vite réglé, (malin ce virus) mai saussi les mises à jours automatiques, j'arive par diverses manipulation préconisée par microsoft à les réinstallées mais elle se retire toujours puis je faire quelques chose?

Vous lavez compris je suis dans la panade, et je serais trs hurexu que vous me donniez un coup de main.

ha oui tant que j'y suis un dernier truc je nai pas de cd bootable de xp j'ai essayé d'en faire un avec bartpe, mais il ma dit qu'il nepouvai tle faire accés à la source refusé, un conseil une idée pourpasser outre?

voici le rapport du scan hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:27:57, on 14/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\lxdncoms.exe
C:\Program Files\PC Tools Firewall Plus\FWService.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\X3U4JG34\HiJackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {4F13C35F-424B-460A-BE00-4EC11A3266E9} - C:\WINDOWS\system32\mlJBRKBu.dll (file missing)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {AF002D63-1F40-4119-A22C-6809D3AB807E} - C:\WINDOWS\system32\iifebApQ.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: (no name) - {BFEC4FFD-9C0E-4B2E-A6C7-03A9437447D9} - C:\WINDOWS\system32\urqNHyvS.dll
O2 - BHO: {9ea0ab2e-a1df-049b-cff4-c34d42cf470e} - {e074fc24-d43c-4ffc-b940-fd1ae2ba0ae9} - C:\WINDOWS\system32\qugbso.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [d8cceb9e] rundll32.exe "C:\WINDOWS\system32\uxpufcmk.dll",b
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O20 - AppInit_DLLs: npfffm.dll qugbso.dll
O20 - Winlogon Notify: urqNHyvS - C:\WINDOWS\SYSTEM32\urqNHyvS.dll
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: lxdnCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdnserv.exe
O23 - Service: lxdn_device - - C:\WINDOWS\system32\lxdncoms.exe
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe

--
End of file - 7320 bytes

Merci davance.
Configuration: Windows XP
Internet Explorer 7.0

32 réponses

Résumé de la discussion

Des symptômes persistants après une infection virale surviennent sur un PC Windows XP, malgré des changements d’antivirus et des scans variés en durée et en efficacité. Des analyses avec HijackThis et des outils comme ComboFix et Toolbar-S&D ont été tentées, mais les problèmes persistent et les points de restauration ont été supprimés. Les éléments problématiques signalés incluent des DLL et des services résidents, des hooks de navigateur et des modules appInit_DLLs, avec l’impossibilité de démarrer une clé USB bootable XP. Enfin, l’absence de console de récupération et les difficultés à démarrer sur support externe compliquent les réparations hors ligne et poussent à envisager une réinstallation du système.

Bobot (l’IA à votre service)
  1. Modérateur
    Pour le mode sans échec :
    http://forum.telecharger.01net.com/forum/high-tech/SECURITE/Securite/redemarrer-mode-echec-sujet_1526_1.htm

    "alors oui le parapluie dantivir est fermé sigen quil nest aps actif pourtant, il me dit quil fonctionne, jai désinstallé et réinstallé ca le fait toujours est ce normal? "
    ---> Installe la pré-version française :
    https://www.mediafire.com/?sharekey=1ab12433e284b403d2db6fb9a8902bda
    0
    1. d"abord un grand merci pour tonaide tu as remis mon pc en état, merci beaucoup pour tout ce temps passé.

      alors oui le parapluie dantivir est fermé sigen quil nest aps actif pourtant, il me dit quil fonctionne, jai désinstallé et réinstallé ca le fait toujours est ce normal?

      Deuxiémement juste pour infomation cets quoi la manip démarrer sans erreur?
      0
      1. Modérateur
        Tu peux supprimer Tools Cleaner et ComboFix.

        Des questions ?
        0
        1. [ Rapport ToolsCleaner version 2.2.3 (par A.Rothstein & dj QUIOU) ]

          -->- Recherche:

          C:\Combofix.txt: trouvé !
          C:\TB.txt: trouvé !
          C:\Qoobox: trouvé !
          C:\Toolbar SD: trouvé !
          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
          C:\Documents and Settings\Propriétaire\Bureau\HijackThis.lnk: trouvé !
          C:\Documents and Settings\Propriétaire\Bureau\ComboFix.exe: trouvé !
          C:\Documents and Settings\Propriétaire\Bureau\ToolBarSD.exe: trouvé !
          C:\Documents and Settings\Propriétaire\Mes documents\hijackthis.log: trouvé !
          C:\Program Files\Microsoft Games\Age of Mythology\history\units\avenger.txt: trouvé !
          C:\Program Files\Microsoft Games\Age of Mythology\history2\units\avenger.txt: trouvé !
          C:\Program Files\Trend Micro\HijackThis: trouvé !
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
          C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !

          ---------------------------------
          -->- Suppression:

          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
          C:\Documents and Settings\Propriétaire\Bureau\HijackThis.lnk: supprimé !
          C:\Documents and Settings\Propriétaire\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
          C:\Documents and Settings\Propriétaire\Bureau\ToolBarSD.exe: supprimé !
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
          C:\Combofix.txt: supprimé !
          C:\TB.txt: supprimé !
          C:\Documents and Settings\Propriétaire\Mes documents\hijackthis.log: supprimé !
          C:\Program Files\Microsoft Games\Age of Mythology\history\units\avenger.txt: supprimé !
          C:\Program Files\Microsoft Games\Age of Mythology\history2\units\avenger.txt: supprimé !
          C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
          C:\Qoobox: supprimé !
          C:\Toolbar SD: supprimé !
          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
          C:\Program Files\Trend Micro\HijackThis: supprimé !
          0
          1. Modérateur
            Pour finir :

            ---> Télécharge CCleaner (N'installe pas la Yahoo Toolbar) :
            https://www.ccleaner.com/ccleaner/download

            ---> Lance-le. Va dans "Options" puis "Avancé", tu décoches la case "Effacer uniquement les fichiers etc...". Tu vas dans "Nettoyeur", tu fais "Analyse". Une fois terminé, tu lances le nettoyage. Puis tu vas dans "Registre", tu fais "Chercher des erreurs". Une fois terminé, tu répares toutes les erreurs sans sauvegarder la base de registre.

            ---> Télécharge Tools Cleaner sur ton Bureau :
            http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
            * Clique sur Recherche et laisse le scan agir.
            * Clique sur Suppression pour finaliser.
            * Tu peux, si tu le souhaites, te servir des Options facultatives.
            * Clique sur Quitter pour obtenir le rapport.
            * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

            ---> Il est nécessaire de désactiver puis réactiver la restauration système pour la purger :
            http://www.infos-du-net.com/forum/272480-11-desactiver-activer-restauration-systeme

            ---> Je te conseille de créer un point de restauration que tu pourras utiliser plus tard si tu as un problème :
            https://www.vulgarisation-informatique.com/creer-point-restauration.php
            0
            1. tout à l'air de fonctionner comme il faut. ca rame plus du tout et plsu defenetre ou autre qui surgissent.
              0
              1. Modérateur
                As-tu encore des problèmes ou on peut passer à la dernière étape ?
                0
                1. Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 21:27:15, on 14/10/2008
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                  C:\WINDOWS\system32\igfxtray.exe
                  C:\WINDOWS\system32\hkcmd.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                  C:\WINDOWS\system32\lxdncoms.exe
                  C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
                  C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\Program Files\Windows Live\Messenger\usnsvc.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                  C:\WINDOWS\system32\NOTEPAD.EXE

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
                  O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                  O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                  O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                  O23 - Service: lxdnCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdnserv.exe
                  O23 - Service: lxdn_device - - C:\WINDOWS\system32\lxdncoms.exe
                  O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
                  O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
                  0
                  1. Modérateur
                    ---> Relance HijackThis et choisis Do a system scan only

                    ---> Coche les cases qui sont devant les lignes suivantes :

                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')

                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

                    O20 - AppInit_DLLs: npfffm.dll qugbso.dll

                    ---> Clique en bas sur Fix checked. Mets oui si HijackThis te demande quelque chose.

                    ---> Redémarre ton PC et poste un nouveau rapport HijackThis.
                    0
                    1. Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 20:48:09, on 14/10/2008
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                      C:\WINDOWS\system32\igfxtray.exe
                      C:\WINDOWS\system32\hkcmd.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                      C:\WINDOWS\system32\lxdncoms.exe
                      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
                      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
                      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                      O20 - AppInit_DLLs: npfffm.dll qugbso.dll
                      O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                      O23 - Service: lxdnCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdnserv.exe
                      O23 - Service: lxdn_device - - C:\WINDOWS\system32\lxdncoms.exe
                      O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
                      O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
                      0
                      1. Modérateur
                        ---> Poste un nouveau rapport HijackThis.
                        0
                        1. ---> Rien de tel pour se faire infecter.

                          Oui c'est de la que ca vient. ^^

                          -----------\\ ToolBar S&D 1.2.2 XP/Vista

                          Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                          X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 2.40GHz )
                          BIOS : Phoenix ROM BIOS PLUS Version 1.10 A07
                          USER : Propriétaire ( Administrator )
                          BOOT : Normal boot
                          Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)
                          Firewall : Sunbelt Personal Firewall 4.6.1845 T (Activated)
                          A:\ (USB)
                          C:\ (Local Disk) - NTFS - Total : 37 Go Free : 18 Go
                          D:\ (CD or DVD)
                          E:\ (CD or DVD) - CDFS - Total : 0 Go Free : 0 Go
                          F:\ (CD or DVD)

                          "C:\ToolBar SD" ( MAJ : 04-10-2008|21:00 )
                          Option : [2] ( mar. 14/10/2008|20:23 )

                          -----------\\ SUPPRESSION

                          Supprime! - C:\Program Files\DAEMON Tools Toolbar\_DTLite.xml
                          Supprime! - C:\Program Files\DAEMON Tools Toolbar

                          -----------\\ Recherche de Fichiers / Dossiers ...

                          -----------\\ [..\Internet Explorer\Main]

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                          "Local Page"="C:\\windows\\system32\\blank.htm"
                          "Start Page"="https://www.google.fr/?gws_rd=ssl"
                          "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                          "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                          "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                          "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                          "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                          "Local Page"="C:\\windows\\system32\\blank.htm"
                          "Start Page"="https://www.msn.com/fr-fr/"

                          --------------------\\ Recherche d'autres infections

                          --------------------\\ Cracks & Keygens ..

                          C:\DOCUME~1\PROPRI~1\Application Data\uTorrent\Settlers.VI.Rise.Of.An.Empire.CRACK-WBB.rar.torrent
                          C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\The Elder Scrolls IV Oblivion + NoDVD Crack
                          C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\[NewTorrents.info]_Anno_1701.CRACK.ONLY-Razor1911
                          C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\The Elder Scrolls IV Oblivion + NoDVD Crack\The.Elder.Scrolls.IV.Oblivion.uif
                          C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\[NewTorrents.info]_Anno_1701.CRACK.ONLY-Razor1911\rzr.tl-1701.nfo
                          C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\[NewTorrents.info]_Anno_1701.CRACK.ONLY-Razor1911\rzr.tl-1701.rar
                          C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\[NewTorrents.info]_Anno_1701.CRACK.ONLY-Razor1911\rzr.tl-1701.sfv
                          C:\DOCUME~1\PROPRI~1\Mes documents\jeu\Crack.exe
                          C:\DOCUME~1\PROPRI~1\Recent\Crack.lnk

                          1 - "C:\ToolBar SD\TB_1.txt" - mar. 14/10/2008|14:22 - Option : [1]
                          2 - "C:\ToolBar SD\TB_2.txt" - mar. 14/10/2008|20:15 - Option : [1]
                          3 - "C:\ToolBar SD\TB_3.txt" - mar. 14/10/2008|20:29 - Option : [2]

                          -----------\\ Fin du rapport a 20:29:26,81
                          0
                          1. Modérateur
                            ---> Relance ToolBar S&D, fais l'option 2 et poste le rapport.

                            "C:\DOCUME~1\PROPRI~1\Application Data\uTorrent\Settlers.VI.Rise.Of.An.Empire.CRACK-WBB.rar.torrent
                            C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\The Elder Scrolls IV Oblivion + NoDVD Crack
                            C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\[NewTorrents.info]_Anno_1701.CRACK.ONLY-Razor1911
                            C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\The Elder Scrolls IV Oblivion + NoDVD Crack\The.Elder.Scrolls.IV.Oblivion.uif
                            C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\[NewTorrents.info]_Anno_1701.CRACK.ONLY-Razor1911\rzr.tl-1701.nfo
                            C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\[NewTorrents.info]_Anno_1701.CRACK.ONLY-Razor1911\rzr.tl-1701.rar
                            C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\[NewTorrents.info]_Anno_1701.CRACK.ONLY-Razor1911\rzr.tl-1701.sfv
                            C:\DOCUME~1\PROPRI~1\Mes documents\jeu\Crack.exe
                            C:\DOCUME~1\PROPRI~1\Recent\Crack.lnk "

                            ---> Rien de tel pour se faire infecter.
                            0
                            1. -----------\\ ToolBar S&D 1.2.2 XP/Vista

                              Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                              X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 2.40GHz )
                              BIOS : Phoenix ROM BIOS PLUS Version 1.10 A07
                              USER : Propriétaire ( Administrator )
                              BOOT : Normal boot
                              Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)
                              Firewall : Sunbelt Personal Firewall 4.6.1845 T (Activated)
                              A:\ (USB)
                              C:\ (Local Disk) - NTFS - Total : 37 Go Free : 18 Go
                              D:\ (CD or DVD)
                              E:\ (CD or DVD) - CDFS - Total : 0 Go Free : 0 Go
                              F:\ (CD or DVD)

                              "C:\ToolBar SD" ( MAJ : 04-10-2008|21:00 )
                              Option : [1] ( mar. 14/10/2008|20:10 )

                              -----------\\ Recherche de Fichiers / Dossiers ...

                              C:\Program Files\DAEMON Tools Toolbar
                              C:\Program Files\DAEMON Tools Toolbar\_DTLite.xml

                              -----------\\ [..\Internet Explorer\Main]

                              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                              "Local Page"="C:\\windows\\system32\\blank.htm"
                              "Start Page"="https://www.google.fr/?gws_rd=ssl"
                              "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                              "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                              "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                              "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                              "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                              "Local Page"="C:\\windows\\system32\\blank.htm"
                              "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"

                              --------------------\\ Recherche d'autres infections

                              --------------------\\ Cracks & Keygens ..

                              C:\DOCUME~1\PROPRI~1\Application Data\uTorrent\Settlers.VI.Rise.Of.An.Empire.CRACK-WBB.rar.torrent
                              C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\The Elder Scrolls IV Oblivion + NoDVD Crack
                              C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\[NewTorrents.info]_Anno_1701.CRACK.ONLY-Razor1911
                              C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\The Elder Scrolls IV Oblivion + NoDVD Crack\The.Elder.Scrolls.IV.Oblivion.uif
                              C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\[NewTorrents.info]_Anno_1701.CRACK.ONLY-Razor1911\rzr.tl-1701.nfo
                              C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\[NewTorrents.info]_Anno_1701.CRACK.ONLY-Razor1911\rzr.tl-1701.rar
                              C:\DOCUME~1\PROPRI~1\Mes documents\Downloads\[NewTorrents.info]_Anno_1701.CRACK.ONLY-Razor1911\rzr.tl-1701.sfv
                              C:\DOCUME~1\PROPRI~1\Mes documents\jeu\Crack.exe
                              C:\DOCUME~1\PROPRI~1\Recent\Crack.lnk

                              1 - "C:\ToolBar SD\TB_1.txt" - mar. 14/10/2008|14:22 - Option : [1]
                              2 - "C:\ToolBar SD\TB_2.txt" - mar. 14/10/2008|20:15 - Option : [1]

                              -----------\\ Fin du rapport a 20:15:34,98
                              0
                              1. Modérateur
                                ---> Supprime SmitfraudFix.

                                ---> Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
                                https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

                                * Lance l'installation du programme en exécutant le fichier téléchargé.
                                * Double-clique maintenant sur le raccourci de Toolbar-S&D.
                                * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
                                * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
                                * Poste le rapport généré. (C:\TB.txt)
                                0
                                1. SmitFraudFix v2.360

                                  Rapport fait à 19:38:43,73, mar. 14/10/2008
                                  Executé à partir de C:\Documents and Settings\Propri‚taire\Bureau\SmitfraudFix
                                  OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                                  Le type du système de fichiers est NTFS
                                  Fix executé en mode sans echec

                                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                  SrchSTS.exe by S!Ri
                                  Search SharedTaskScheduler's .dll

                                  »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                  127.0.0.1 localhost

                                  »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                                  VACFix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                                  S!Ri's WS2Fix: LSP not Found.

                                  »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                                  GenericRenosFix by S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                                  C:\Program Files\Smart Antivirus 2009\ supprimé

                                  »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                                  IEDFix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                                  404Fix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

                                  AntiXPVSTFix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» RK

                                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{61D94F0B-CEF8-4FF7-8053-91430D5E2EAA}: DhcpNameServer=192.168.1.1
                                  HKLM\SYSTEM\CS1\Services\Tcpip\..\{61D94F0B-CEF8-4FF7-8053-91430D5E2EAA}: DhcpNameServer=192.168.1.1
                                  HKLM\SYSTEM\CS2\Services\Tcpip\..\{61D94F0B-CEF8-4FF7-8053-91430D5E2EAA}: DhcpNameServer=192.168.1.1
                                  HKLM\SYSTEM\CS3\Services\Tcpip\..\{61D94F0B-CEF8-4FF7-8053-91430D5E2EAA}: DhcpNameServer=192.168.1.1
                                  HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                  HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                  HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                  HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                                  »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                  "System"=""

                                  »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                                  Nettoyage terminé.

                                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                  SrchSTS.exe by S!Ri
                                  Search SharedTaskScheduler's .dll

                                  »»»»»»»»»»»»»»»»»»»»»»»» Fin
                                  0
                                  1. Modérateur
                                    - Redémarre ton ordinateur en mode sans échec :
                                    https://blog.sosordi.net/

                                    - Double-clique sur SmitfraudFix.exe, choisis l'option 2 et Entrée

                                    - Réponds O(oui) à ces deux questions si elles te sont posées

                                    Voulez-vous nettoyer le registre ?
                                    Corriger le fichier infecté ?

                                    - Un rapport sera généré, sauvegarde-le sur le bureau

                                    - Redémarre en mode normal

                                    - Poste le rapport SmitfraudFix
                                    0
                                    1. C:\WINDOWS\System32\smss.exe
                                      C:\WINDOWS\system32\winlogon.exe
                                      C:\WINDOWS\system32\services.exe
                                      C:\WINDOWS\system32\lsass.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\WINDOWS\system32\spoolsv.exe
                                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                      C:\WINDOWS\Explorer.EXE
                                      C:\WINDOWS\system32\lxdncoms.exe
                                      C:\Program Files\PC Tools Firewall Plus\FWService.exe
                                      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                      C:\WINDOWS\system32\igfxtray.exe
                                      C:\WINDOWS\system32\hkcmd.exe
                                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                      C:\WINDOWS\system32\ctfmon.exe
                                      C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                                      C:\Program Files\Windows Live\Messenger\usnsvc.exe
                                      C:\Program Files\Internet Explorer\iexplore.exe
                                      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                      C:\WINDOWS\system32\cmd.exe

                                      »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Propri‚taire

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Propri‚taire\Application Data

                                      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\PROPRI~1\Favoris

                                      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                                      C:\Program Files\Smart Antivirus 2009\ PRESENT !

                                      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                                      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                                      "Source"="About:Home"
                                      "SubscribedURL"="About:Home"
                                      "FriendlyName"="Ma page d'accueil"

                                      »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                      o4Patch
                                      Credits: Malware Analysis & Diagnostic
                                      Code: S!Ri

                                      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                      IEDFix
                                      Credits: Malware Analysis & Diagnostic
                                      Code: S!Ri

                                      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                      VACFix
                                      Credits: Malware Analysis & Diagnostic
                                      Code: S!Ri

                                      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                      404Fix
                                      Credits: Malware Analysis & Diagnostic
                                      Code: S!Ri

                                      »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
                                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                      AntiXPVSTFix
                                      Credits: Malware Analysis & Diagnostic
                                      Code: S!Ri

                                      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                      SrchSTS.exe by S!Ri
                                      Search SharedTaskScheduler's .dll

                                      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                                      "AppInit_DLLs"="npfffm.dll qugbso.dll"

                                      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                      "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                                      "System"=""

                                      »»»»»»»»»»»»»»»»»»»»»»»» RK

                                      »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                      Description: Intel(R) PRO/1000 MT Network Connection - Miniport d'ordonnancement de paquets
                                      DNS Server Search Order: 192.168.1.1

                                      HKLM\SYSTEM\CCS\Services\Tcpip\..\{61D94F0B-CEF8-4FF7-8053-91430D5E2EAA}: DhcpNameServer=192.168.1.1
                                      HKLM\SYSTEM\CS1\Services\Tcpip\..\{61D94F0B-CEF8-4FF7-8053-91430D5E2EAA}: DhcpNameServer=192.168.1.1
                                      HKLM\SYSTEM\CS2\Services\Tcpip\..\{61D94F0B-CEF8-4FF7-8053-91430D5E2EAA}: DhcpNameServer=192.168.1.1
                                      HKLM\SYSTEM\CS3\Services\Tcpip\..\{61D94F0B-CEF8-4FF7-8053-91430D5E2EAA}: DhcpNameServer=192.168.1.1
                                      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                                      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                                      »»»»»»»»»»»»»»»»»»»»»»»» Fin
                                      0
                                      1. Modérateur
                                        - Télécharge SmitfraudFix (de de S!Ri, balltrap34 et moe31) :
                                        http://siri.urz.free.fr/Fix/SmitfraudFix.exe ou http://www.geekstogo.com/forum/files/file/6-smitfraudfix/

                                        - Enregistre-le sur le bureau

                                        - Double-clique sur SmitfraudFix.exe et choisis l'option 1 puis Entrée

                                        - Un rapport sera généré, poste-le dans ta prochaine réponse.

                                        [*] process.exe est détecté par certains antivirus comme étant un risktool. Il ne s'agit pas d'un virus mais d'un utilitaire destiné à mettre fin à des processus.[*]

                                        ** Ne fais l'étape 2 que si on te le demande, on doit d'abord examiner le premier rapport de SmitfraudFix
                                        0
                                        • 1
                                        • 2