Pc portable qui rame enormement

Résolu
Bonjour,donc me revoilà,je vous mets un rapport hijackthis de suite
Configuration: Windows Vista
Firefox 3.5.1

96 réponses

Résumé de la discussion

Plusieurs éléments décrivent une infection sur Windows Vista, avec un rapport HijackThis et une quête de solutions via des outils anti‑malware pour nettoyer le système. En pratique, la meilleure approche consiste à exécuter Malwarebytes' Anti‑Malware pour un balayage rapide, supprimer les infections détectées et, si nécessaire, redémarrer l’ordinateur pour terminer le nettoyage. D'autres recommandations évoquent Ad-Remover ou l'analyse des rapports HijackThis pour identifier les éléments persistants et les déconnecter des programmes au démarrage et des services concernés. Par ailleurs, les éléments du log HijackThis et la liste des fichiers modifiés indiquent une activité étendue, notamment des modifications de démarrage et des services, nécessitant une vérification croisée avec les outils système.

Bobot (l’IA à votre service)
  1. Contributeur
    Passez plutôt Malwarebytes !!

    Edit :

    Télécharge Malwarebytes' Anti-Malware

    - Installe le > double-clic sur Mbam-setup.exe, à la fin de l'installation, il se mettra automatiquement à jour
    -
    Une fois installé, ferme toutes les applications en cours et lances Malwarebytes

    - Exécute un examen rapide du pc ( tu n'auras pas accès à internet pendant l'analyse)

    - A la fin du scan clic sur " Afficher les résultats ", si Malwarebytes a trouvé des infections >> clic sur " Supprimer la sélection "

    - Si il a besoin de redémarrer le pc pour finir la désinfection, accepte

    - Un rapport s'établira, postes son contenu.
    1. voilà le rapport

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:40:12, on 31/07/2009
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18294)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Windows\System32\igfxpers.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Users\PROPRI~1\AppData\Local\Temp\RtkBtMnt.exe
      C:\Users\PROPRIETAIRE\Desktop\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
      O1 - Hosts: ::1 localhost
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Crux P2P\Plugins\RazaWebHook.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
      O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
      O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Crux P2P\Plugins\RazaWebHook.dll/3000
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O20 - AppInit_DLLs: eNetHook.dll
      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
      O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
      O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
      O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
      O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
      O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
      O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
      O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
      O23 - Service: Orange Contrôle Parental (OPTENET_FILTER) - Orange - C:\Program Files\Controle Parental\bin\optproxy.exe
      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
      1. bonjour à mouton72 et à ^^Marie^^ :

        j'ai vu 2 lignes bizzar sur ce rapoort :

        R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll

        O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll

        Classés sur internet par les differants site comme très méchants !!!

        en plus de ces lignes, il y a ceci comme d'hab :

        O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

        mais avant tout :

        O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Crux P2P\Plugins\RazaWebHook.dll

        ;-)
        1. Salut toi ;))
          Je sais qu'il y a une infection (SMTF), mais l'internaute balance son rapport ainsi, nous ne sommes pas des robots. Un minimum pourrait être judicieux pour exposer son problème.

          Je te laisse la suite.

          ++
      2. je vais pas tarder de retourner bosser, je suis de passage chez moi, je mange un bout et je repars : )))
        mais dés mon retours, je regarderai, promis , lol

        P:S pour mouton72 :mets ton curseur de sourie sur mon pseudo, tout est dit là dessus ;-)

        pour rappel :

        O.o°• ♪♪♫ Réspire à fond, Rédige ton message en bon français et de manière claire.
        Une fois ton problème passé, coche ton message comme résolu.
        Ca va bien se passer, tu verras, enfin on essaie !!! o°.Oø¤º°`°º¤ø


        à + ^^Marie^^
        1. salut,desolé de ne pas avoir été plus precis,c'est parce que j'ai deja fait un post a ce sujet hier soir et pesonne ne m'a repondu,donc j'en ai refait un ce matin en esperant avoir de l'aide.
          donc c'est sur il y a de l'infection dans l'air.que dois je faire maintenant?
          merci
          1. donne nous un peu plus de détail sur l'apparition de pannes.
            des precisions serons des bienvenues : symptomes, l'état dy système ......, vu que nous sommes à distance, on exploite ce que tu nous donne, la matière première est essentiel dans le diagnostique des anomalies ;-)

            ___________________________________________________________________________________
            Comme cadeau de fin d'année, j'ai demandé au père nöel, une boule de christal afin de ne pas avoir à poser des questions pour en savoir plus, il m'a répondu : tu l'auras un jour !!!!! Snif !!!!!!!!

            à+
            1. alors en fait ce pc n'est pas le mien,mais au demarrage il rame comme c'est pas possible.entre chaque etape il reste pusieurs minutes sur un ecran noir et je n'est que la fleche blanche qi s'affiche.
              hier soir j'ai installé antivir(a la place de l'antivirus d'orange d'origine),et lors d'un scan le pc a planté et impossible d'agir'du coup j'ai etains a partir du bouton de mise sous tension
              1. j'ai trouvé unsite qui decit bien comment analyser un rapport hijackthis,j'ai effacé les lignes suspctes et je vous mets un nouveau apport,mais j preffere quand meme votre aide au cas où

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 13:34:45, on 31/07/2009
                Platform: Windows Vista SP1 (WinNT 6.00.1905)
                MSIE: Internet Explorer v7.00 (7.00.6001.18294)
                Boot mode: Normal

                Running processes:
                C:\Windows\system32\Dwm.exe
                C:\Windows\Explorer.EXE
                C:\Windows\system32\taskeng.exe
                C:\Windows\RtHDVCpl.exe
                C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                C:\Windows\System32\igfxpers.exe
                C:\Program Files\Windows Media Player\wmpnscfg.exe
                C:\Users\PROPRI~1\AppData\Local\Temp\RtkBtMnt.exe
                C:\Windows\system32\SearchFilterHost.exe
                C:\Users\PROPRIETAIRE\Desktop\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                O1 - Hosts: ::1 localhost
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Crux P2P\Plugins\RazaWebHook.dll/3000
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                O13 - Gopher Prefix:
                O20 - AppInit_DLLs: eNetHook.dll
                O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
                O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
                O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
                O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                O23 - Service: Orange Contrôle Parental (OPTENET_FILTER) - Orange - C:\Program Files\Controle Parental\bin\optproxy.exe
                O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                1. Contributeur sécurité
                  Bonjour mouton72

                  Pardon pour cette intrusion mais ne fixe pas de lignes tant que celui qui t'aide ne te le demande pas.
                  Pour certaines, ça ne sert à rien et cela risque de masquer des infections.
              2. re,

                Télécharge Smitfraudfix : (merci a S!RI pour ce petit programme).

                http://siri.urz.free.fr/Fix/SmitfraudFix.exe

                Pour ceux qui ont vista, ne pas oublier de désactiver Le contrôle des comptes utilisateurs
                https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

                Clique droit sur le logo de smithfarudfix, « executer en tant qu’Administrateur »

                Exécute le, Double click sur Smitfraudfix.exe en option 1,
                voila a quoi cela ressemble : http://siri.urz.free.fr/Fix/SmitfraudFix.php
                il va générer un rapport : copie/colle le sur le poste stp.

                Tuto: http://pagesperso-orange.fr/rginformatique/section%20virus/smitfraudfix.htm

                process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus

                enregistyre le rapport sur ton bureau, et poste son contenu sur ton prochain message

                je file bosser, bon courage et à ce soir
                1. ok,a ce soir,moi aussi je dois m'absenter,pas pour le taf mais pour faire changer les 4 pneus de ma voiture,sniffff
                  bon je rdeviens serieux,voilà lr rapport

                  SmitFraudFix v2.423

                  Scan done at 14:41:19,14, 31/07/2009
                  Run from C:\Program Files\Mozilla Firefox\SmitfraudFix
                  OS: Microsoft Windows [version 6.0.6001] - Windows_NT
                  The filesystem type is NTFS
                  Fix run in normal mode

                  »»»»»»»»»»»»»»»»»»»»»»»» Process

                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\wininit.exe
                  C:\Windows\system32\winlogon.exe
                  C:\Windows\system32\services.exe
                  C:\Windows\system32\lsass.exe
                  C:\Windows\system32\lsm.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\SLsvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\System32\spoolsv.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\Avira\AntiVir Desktop\sched.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\alg.exe
                  C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                  C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
                  C:\Windows\system32\dllhost.exe
                  C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
                  C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                  C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                  C:\Acer\Empowering Technology\eNet\eNet Service.exe
                  C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
                  C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  C:\Acer\Mobility Center\MobilityService.exe
                  C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                  C:\Windows\system32\locator.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\snmptrap.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\UI0Detect.exe
                  C:\Windows\System32\vds.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\wbem\WmiApSrv.exe
                  C:\Windows\system32\SearchIndexer.exe
                  C:\Windows\system32\DRIVERS\xaudio.exe
                  C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
                  C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                  C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                  C:\Program Files\Windows Media Player\wmpnetwk.exe
                  C:\Windows\system32\wbem\unsecapp.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\RtHDVCpl.exe
                  C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Windows\System32\igfxpers.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Users\PROPRI~1\AppData\Local\Temp\RtkBtMnt.exe
                  C:\Windows\System32\msdtc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Users\PROPRIETAIRE\Desktop\HijackThis.exe
                  C:\Windows\system32\NOTEPAD.EXE
                  C:\Windows\system32\conime.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Windows\system32\cmd.exe
                  C:\Windows\system32\wbem\wmiprvse.exe

                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\PROPRIETAIRE

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\PROPRI~1\AppData\Local\Temp

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\PROPRIETAIRE\Application Data

                  »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\PROPRI~1\FAVORI~1

                  »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                  C:\Program Files\Google\googletoolbar1.dll FOUND !

                  »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                  »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                  »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                  !!!Attention, following keys are not inevitably infected!!!

                  o4Patch
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                  !!!Attention, following keys are not inevitably infected!!!

                  IEDFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                  !!!Attention, following keys are not inevitably infected!!!

                  Agent.OMZ.Fix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                  !!!Attention, following keys are not inevitably infected!!!

                  VACFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                  !!!Attention, following keys are not inevitably infected!!!

                  404Fix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                  !!!Attention, following keys are not inevitably infected!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                  !!!Attention, following keys are not inevitably infected!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                  "AppInit_DLLs"="eNetHook.dll"
                  "LoadAppInit_DLLs"=dword:00000001

                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                  !!!Attention, following keys are not inevitably infected!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                  "Userinit"="C:\\Windows\\system32\\userinit.exe,"

                  »»»»»»»»»»»»»»»»»»»»»»»» RK

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                  Description: Atheros AR5007EG Wireless Network Adapter
                  DNS Server Search Order: 192.168.1.1

                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{575AB2E7-82AB-4BF4-B085-4BDE27FF55DB}: NameServer=
                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{8CBCE04D-8479-474D-BA7D-6C0BDA868B9F}: DhcpNameServer=192.168.1.1

                  »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                  »»»»»»»»»»»»»»»»»»»»»»»» End
                  1. recouco,me revoilou, si tu es là electricien69 tu es tjrs ok pour continuer a m'aider?
                    1. oui, je viens de le voir,
                      le faite que tu ais supprimé les lignes avec hijackthis fausse un peu les données
                      fait une option 2 avec smithfraudfix et poste le rapport

                      clique droit sur l'icone pour le lancer en mode administrateur
                      1. je vois que j'ai fait une connerie,mais j'espere quand meme que tu trouveras la solution! dsl

                        je pensais,je n'ai pas supprimer le premier rapport hijack avant que j'efface les lignes!!

                        voilà le rapport smitf

                        SmitFraudFix v2.423

                        Scan done at 19:03:40,52, 31/07/2009
                        Run from C:\Program Files\Mozilla Firefox\SmitfraudFix
                        OS: Microsoft Windows [version 6.0.6001] - Windows_NT
                        The filesystem type is NTFS
                        Fix run in normal mode

                        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                        !!!Attention, following keys are not inevitably infected!!!

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                        »»»»»»»»»»»»»»»»»»»»»»»» hosts

                        ::1 localhost

                        »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                        VACFix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                        S!Ri's WS2Fix: LSP not Found.

                        »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                        GenericRenosFix by S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                        C:\Program Files\Google\googletoolbar1.dll Deleted

                        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                        IEDFix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

                        Agent.OMZ.Fix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                        404Fix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» RK

                        »»»»»»»»»»»»»»»»»»»»»»»» DNS

                        Description: Atheros AR5007EG Wireless Network Adapter
                        DNS Server Search Order: 192.168.1.1

                        »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

                        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                        !!!Attention, following keys are not inevitably infected!!!

                        »»»»»»»»»»»»»»»»»»»»»»»» RK.2

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        Registry Cleaning done.

                        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                        !!!Attention, following keys are not inevitably infected!!!

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        »»»»»»»»»»»»»»»»»»»»»»»» End
                        1. Edit:

                          Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
                          https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

                          * Lance l'installation du programme en exécutant le fichier téléchargé.
                          * Double-clique maintenant sur le raccourci de Toolbar-S&D.
                          * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
                          * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
                          * Poste le rapport généré. (C:\TB.txt)

                          puis :

                          Configuration de Antivir :

                          clic droit sur son icône dans la barre des taches et sélectionner Configurer Antivir.

                          cocher la case : Mode Expert( en haut à gauche de la fenêtre)..

                          => Cliquer sur Scanner dans le volet de gauche :

                          > Dans "Fichiers" sélectionner Tous les fichiers.

                          > Dans procédure de recherche, cocher Autoriser l'arrêt, et dans "priorité scanner" sélectionner Moyen.

                          > Dans "Autres réglages" cocher toutes les cases.

                          NE SURTOUT PAS OUBLIER LA RECHERCHE DES ROOTKIT QUI EST TRES IMPORTANTE !

                          => Cliquer sur "Recherche" dans le volet de gauche et appliquer les mêmes paramètres que précédemment.

                          => Dérouler "Recherche" en cliquant sur le +. Cliquer sur "Heuristique" :

                          > Cocher "Heuristique de MacroVirus" et "Heuristique fichier Win32" avec degré d'indentification MOYEN !

                          => Dans le volet de gauche, dérouler "Guard" :
                          coche : contrôler pendant la lecture et l’écriture, puis à côté : tous les fichiers.
                          aide en images :
                          https://www.commentcamarche.net/faq/16831-tutoriel-configuration-optimale-d-antivir-personal#2-la-configuration

                          NOTE : Pour que le nettoyage soit efficace, il faut lancer le scan d’avira en mode sans échec.
                          1. ok,voilà le rapport,sinon pour faire un scan en mode sans echec je dois redemarrer lepc,pui selectionner "mode sans echec"?ensuite?

                            -----------\\ ToolBar S&D 1.2.8 XP/Vista

                            Microsoft® Windows Vista™ Édition Familiale Basique ( v6.0.6001 ) Service Pack 1
                            X86-based PC ( Multiprocessor Free : Intel(R) Celeron(R) M CPU 430 @ 1.73GHz )
                            BIOS : Ver 1.00PARTTBLP
                            USER : PROPRIETAIRE ( Administrator )
                            BOOT : Normal boot
                            Antivirus : avast! antivirus 4.8.1169 [VPS 080331-0] 4.8.1169 (Activated)
                            C:\ (Local Disk) - NTFS - Total:33 Go (Free:5 Go)
                            D:\ (Local Disk) - NTFS - Total:33 Go (Free:30 Go)
                            E:\ (CD or DVD)

                            "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                            Option : [1] ( 31/07/2009|19:27 )

                            [ UAC => 0 ]

                            -----------\\ Recherche de Fichiers / Dossiers ...

                            C:\Program Files\GamesBar
                            C:\Program Files\GamesBar\Localization2-French.ini
                            C:\Program Files\Search Settings
                            C:\Program Files\Search Settings\kb127
                            C:\Program Files\Search Settings\SearchSettings.exe
                            C:\Program Files\Search Settings\kb127\res
                            C:\Program Files\Search Settings\kb127\SearchSettingsRes409.dll
                            C:\Program Files\Search Settings\kb127\temp

                            -----------\\ [..\Internet Explorer\Main]

                            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                            "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                            "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                            "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                            "Local Page"="C:\\windows\\system32\\blank.htm"
                            "Url"="https://www.msn.com/fr-fr/actualite/"

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                            "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                            "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                            "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                            "Local Page"="C:\\windows\\system32\\blank.htm"
                            "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"

                            --------------------\\ Recherche d'autres infections

                            C:\Windows\System32\nvs2.inf

                            C:\Users\PROPRI~1\AppData\Local\amknebl.dat
                            C:\Users\PROPRI~1\AppData\Local\amknebl.exe
                            C:\Users\PROPRI~1\AppData\Local\amknebl_nav.dat
                            C:\Users\PROPRI~1\AppData\Local\amknebl_navps.dat
                            [b]==> EGDACCESS <==/b

                            [ UAC => 1 ]

                            1 - "C:\ToolBar SD\TB_1.txt" - 31/07/2009|19:28 - Option : [1]

                            -----------\\ Fin du rapport a 19:28:29,37
                            1. par contre je vois ds le rapport qu'il met avast alors que j'ai installé antivir hier soir!!!
                              1. Salut

                                Tu as Norton aussi ;)
                            2. passe à option 2 avec toolbar s&d
                              avec le rapport bien sur :-)
                              • 1
                              • 2
                              • 3
                              • 4
                              • 5