Infecé par Advanced virus remover

Bonjour,
Jesuis infecté par cette saleté de virus. J'ai eu beau me mettre en mode sans échec et baayer avec spybot, adware, a2, Tend... rien à faire il est toujours là. Merci de me dire ce qu'i faut faire pour s'en débarasser.
Merci davance
Configuration: Windows XP Internet Explorer 7.0

23 réponses

  1. Contributeur sécurité
    Bonsoir,

    Malwarebyte's anti-malware ----->

    [x] Télécharge Malwarebyte's anti-malware (MBAM) à cette adresse : http://www.malwarebytes.org/mbam/program/mbam-setup.exe

    [x] Installe le

    [x] Un tutoriel pour son utilisation est disponible ici : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

    [x] Suis les indications données sur le lien précédent puis copie/colle le rapport généré dans ton prochain message
    0
    1. Contributeur sécurité
      bonsoir,

      Xplode avant de faire malware il serait bon d'analyser son pc afin de voir ce qu'il à :

      ▶ Télécharge Random's System Information Tool (RSIT).

      ▶ Un tutoriel est à ta disposition pour l'installer et l'utiliser correctement ici

      ▶ Double clique sur RSIT.exe pour lancer l'outil.

      ▶ Clique sur 'Continue' à l'écran Disclaimer.

      ▶ Si l'outil Hijackthis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

      ▶ Une fois le scan fini , 2 rapports vont apparaitre. ▶ Héberge le contenu des 2 rapports.

      ( C:\RSIT\log.txt et C:\RSIT\info.txt )

      CTRL A pour sélectionner tout, CTRL C pour copier et puis CTRL V pour coller

      Petite chose à faire pour les rapports générés par RSIT avant de continuer

      ▶ Vous devez fusionner les deux rapports.
      ▶ C'est-à-dire, copier/coller le contenu du rapport info.txt à la suite du rapport log.txt pour ne faire qu'un seul rapport.
      ▶ Ensuite enregistrer le rapport log.txt.

      Ensuite :

      ▶ Rendez-vous à cette adresse d'hébergement gratuit : https://www.cjoint.com/

      ▶ Cliquez sur parcourir, puis sur créer le lien cjoint

      ▶ Une fois le lien crée, faite un clique droit dessus et copier l'adresse du lien pour venir le coller dans votre réponse

      0
      1. Contributeur sécurité
        Il me manque juste le rapport hijackthis dans les 2 alors fais moi ceci merci :

        téléchargez le fichier d'installation d'HijackThis. </gras>

        Tutoriaux Hijackthis

        Afin de pouvoir me donner le rapport hijackthis qui me manque merci.
        0
        1. Bonsoir Pimprenelle

          Merci de ta réponse et désolé que tu n'aies pas ce qu'il te fallait.
          Je me suis un peu embrouillé car HijackThis ne marchait pas. Donc j'ai téléchargé Hijackthis et je suis revenu à ton message précédent en exécutant RSIT etj'ai obtenu deux fichiers que j'ai regroupé et que je je t'ai fait envoyer.
          Sur HitjackThis, le tutoriel expliquait qu'il fallait renommer le fichier en hjt.exe mais je ne l'ai pas fat.
          As tu toutes les infos désormais ? D'avance merci
          0
          1. Contributeur sécurité
            Désolé il me manque juste ce log là https://www.androidworld.fr/

            Tu lance hijackthis qui est sur ton bureau, et tu clique sur do a system scan an save a logefile et tu me joint ce rapport là. merci.
            0
            1. Bonjour

              Je vous joins le rapport de hitjackthis.
              Merci
              0
              1. Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 19:16:58, on 24/08/2009
                Platform: Windows XP SP3 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16876)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\csrss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                D:\aawservice.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
                D:\Spyware Doctor\pctsTray.exe
                C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Garmin\gStart.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Trend Micro\BM\TMBMSRV.exe
                C:\Program Files\Fichiers communs\Acronis\Agent\agent.exe
                C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\Program Files\Bonjour\mDNSResponder.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                C:\WINDOWS\system32\nvsvc32.exe
                C:\WINDOWS\system32\HPZipm12.exe
                D:\Spyware Doctor\pctsAuxs.exe
                D:\Spyware Doctor\pctsSvc.exe
                C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
                C:\WINDOWS\system32\SearchIndexer.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe
                C:\WINDOWS\System32\alg.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\rundll32.exe
                C:\WINDOWS\system32\SearchProtocolHost.exe
                C:\Program Files\Trend Micro\HijackThis\HJT.exe
                C:\WINDOWS\system32\SearchFilterHost.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
                O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [ISTray] "D:\Spyware Doctor\pctsTray.exe"
                O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [gStart] C:\Garmin\gStart.exe
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\S-1-5-18\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll
                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O16 - DPF: Garmin Communicator Plug-In - https://my.garmin.com/static/m/cab/2.6.4/GarminAxControl.CAB
                O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
                O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://webmail.maif.fr/iNotes6W.cab
                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cab
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                O20 - Winlogon Notify: 24d5715e658 - C:\WINDOWS\System32\deskadp32.dll
                O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\aawservice.exe
                O23 - Service: Acronis Remote Agent (AcronisAgent) - Acronis - C:\Program Files\Fichiers communs\Acronis\Agent\agent.exe
                O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
                O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                O23 - Service: Service Google Update (gupdate1c9bf9ff4671f0) (gupdate1c9bf9ff4671f0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - D:\Spyware Doctor\pctsAuxs.exe
                O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - D:\Spyware Doctor\pctsSvc.exe
                O23 - Service: Composant de commande centrale Trend Micro (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
                O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
                O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
                0
                1. Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 19:16:58, on 24/08/2009
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16876)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\csrss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  D:\aawservice.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
                  D:\Spyware Doctor\pctsTray.exe
                  C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Garmin\gStart.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Trend Micro\BM\TMBMSRV.exe
                  C:\Program Files\Fichiers communs\Acronis\Agent\agent.exe
                  C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\WINDOWS\system32\HPZipm12.exe
                  D:\Spyware Doctor\pctsAuxs.exe
                  D:\Spyware Doctor\pctsSvc.exe
                  C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
                  C:\WINDOWS\system32\SearchIndexer.exe
                  C:\WINDOWS\system32\wbem\wmiprvse.exe
                  C:\WINDOWS\System32\alg.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\rundll32.exe
                  C:\WINDOWS\system32\SearchProtocolHost.exe
                  C:\Program Files\Trend Micro\HijackThis\HJT.exe
                  C:\WINDOWS\system32\SearchFilterHost.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
                  O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [ISTray] "D:\Spyware Doctor\pctsTray.exe"
                  O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [gStart] C:\Garmin\gStart.exe
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\S-1-5-18\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                  O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: Garmin Communicator Plug-In - https://my.garmin.com/static/m/cab/2.6.4/GarminAxControl.CAB
                  O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
                  O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://webmail.maif.fr/iNotes6W.cab
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                  O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                  O20 - Winlogon Notify: 24d5715e658 - C:\WINDOWS\System32\deskadp32.dll
                  O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\aawservice.exe
                  O23 - Service: Acronis Remote Agent (AcronisAgent) - Acronis - C:\Program Files\Fichiers communs\Acronis\Agent\agent.exe
                  O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Service Google Update (gupdate1c9bf9ff4671f0) (gupdate1c9bf9ff4671f0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                  O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - D:\Spyware Doctor\pctsAuxs.exe
                  O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - D:\Spyware Doctor\pctsSvc.exe
                  O23 - Service: Composant de commande centrale Trend Micro (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
                  O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
                  O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
                  0
                  1. Contributeur sécurité
                    A supprimer Ad-Aware 2007 car il n'est plus efficace et plus à jour.

                    Ensuite infection google tool bar :

                    Sous Vista : ▶ Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                    ▶ Clique sur Démarrer puis sur panneau de configuration
                    ▶ Double Clique sur l'icône "Comptes d'utilisateurs"
                    ▶ Clique ensuite sur désactiver et valide.
                    ▶ Redémarre le PC.

                    Option 1 - Recherche :

                    ▶ télécharge smitfraudfix et enregistre le sur le bureau

                    ▶ Sous XP : Double clique sur smitfraudfix puis exécuter

                    ▶ sous vista : Clic-droit sur SmitfraudFix présent sur le bureau et choisis "Exécuter en tant qu'administrateur"

                    ▶ Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.

                    (attention : N utilises pas l option 2 si je ne te l ai pas demandé !!)

                    ▶ copier/coller le rapport dans la réponse.

                    Voici un tutoriel sonore et animé en cas de problème d'utilisation

                    (Attention : "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool".
                    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains,
                    cet utilitaire pourrait arrêter des logiciels de sécurité.)

                    0
                    1. SmitFraudFix v2.423

                      Rapport fait à 23:23:46,64, 24/08/2009
                      Executé à partir de C:\Documents and Settings\MAIF\Bureau\SmitfraudFix
                      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                      Le type du système de fichiers est NTFS
                      Fix executé en mode normal

                      »»»»»»»»»»»»»»»»»»»»»»»» Process

                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\csrss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      D:\aawservice.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
                      D:\Spyware Doctor\pctsTray.exe
                      C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Garmin\gStart.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Trend Micro\BM\TMBMSRV.exe
                      C:\Program Files\Fichiers communs\Acronis\Agent\agent.exe
                      C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\WINDOWS\system32\HPZipm12.exe
                      D:\Spyware Doctor\pctsAuxs.exe
                      D:\Spyware Doctor\pctsSvc.exe
                      C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
                      C:\WINDOWS\system32\SearchIndexer.exe
                      C:\WINDOWS\system32\wbem\wmiprvse.exe
                      C:\WINDOWS\System32\alg.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\rundll32.exe
                      C:\Program Files\Outlook Express\msimn.exe
                      C:\WINDOWS\system32\msiexec.exe
                      C:\Program Files\internet explorer\iexplore.exe
                      C:\Documents and Settings\MAIF\Bureau\SmitfraudFix\Policies.exe
                      C:\WINDOWS\system32\SearchProtocolHost.exe
                      C:\WINDOWS\system32\SearchFilterHost.exe
                      C:\WINDOWS\system32\cmd.exe
                      0
                      1. SmitFraudFix v2.423

                        Rapport fait à 23:23:46,64, 24/08/2009
                        Executé à partir de C:\Documents and Settings\MAIF\Bureau\SmitfraudFix
                        OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                        Le type du système de fichiers est NTFS
                        Fix executé en mode normal

                        »»»»»»»»»»»»»»»»»»»»»»»» Process

                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\csrss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        D:\aawservice.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
                        D:\Spyware Doctor\pctsTray.exe
                        C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Garmin\gStart.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Trend Micro\BM\TMBMSRV.exe
                        C:\Program Files\Fichiers communs\Acronis\Agent\agent.exe
                        C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
                        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        C:\Program Files\Bonjour\mDNSResponder.exe
                        C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                        C:\WINDOWS\system32\nvsvc32.exe
                        C:\WINDOWS\system32\HPZipm12.exe
                        D:\Spyware Doctor\pctsAuxs.exe
                        D:\Spyware Doctor\pctsSvc.exe
                        C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
                        C:\WINDOWS\system32\SearchIndexer.exe
                        C:\WINDOWS\system32\wbem\wmiprvse.exe
                        C:\WINDOWS\System32\alg.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\rundll32.exe
                        C:\Program Files\Outlook Express\msimn.exe
                        C:\WINDOWS\system32\msiexec.exe
                        C:\Program Files\internet explorer\iexplore.exe
                        C:\Documents and Settings\MAIF\Bureau\SmitfraudFix\Policies.exe
                        C:\WINDOWS\system32\SearchProtocolHost.exe
                        C:\WINDOWS\system32\SearchFilterHost.exe
                        C:\WINDOWS\system32\cmd.exe
                        0
                        1. Contributeur sécurité
                          le rappot n'est pas complet il ne passe pas essaye c-joint.
                          0
                          1. Contributeur sécurité
                            je parlais de smith fraud qui n'était pas complet pas de hijackthis.
                            0
                            1. Contributeur sécurité
                              non ba il ne là pas détecté comme infecté.

                              Pour demain :

                              Télécharge : MSNFix (!aur3n7) choisi le serveur 2 et décompresse-le sur le Bureau.

                              Regarde bien le Tuto Ici

                              Ensuite :

                              Redémarre en mode sans échec comme indiqué ici ; Choisis ta session courante.

                              Lance le fichier MSNFix.bat qui se trouve dans le dossier MSNfix, sur le bureau.
                              - Exécute l'option R.
                              - Si l'infection est détectée, exécute l'option N.
                              - Sauvegarde ce rapport sur ton bureau.

                              Pour ceux qui ont vista, ne pas oublier de désactiver Le contrôle des comptes utilisateurs

                              Le rapport sera enregistré dans C:\Windows\ sous le nom de MSNFix
                              0
                              1. Bonsoir ,

                                MSNFix , a était retirer par son auteur , veuillez ne plus l'utiliser , même si encore disponible ici au téléchargement.

                                Merci
                                0
                                1. Bonjour

                                  Merci pour les deux réponses mais je fais quoi déormais J'ai toujours ce virus qui me ralentit la machine et me et des message de plus enplus.
                                  Merci de ta réponse.
                                  0
                                  • 1
                                  • 2