Probleme avec antivir

Résolu
Bonjour, j'ai un petit probleme avec antivir!
j'ai une fenetre me signalant la detection d'un virus et je n'arrive rien a faire.... je selectionne toutes les options les unes apres les autres mais ca revient a chaque fois!
en plus ca s'embale il y a des jusquq'a 12 fenetres identiques qui s'ouvrent...
j'ai tout essayé:
j'ai lancé unscan complet, redemarré l'ordi...
si quelqu'un a une solution!!!
merci!
Configuration: Windows XP
Internet Explorer 7.0

10 réponses

  1. Contributeur sécurité
    Bienvenue sur le forum d’entraide de CommentCaMarche.net

    Nous connaissons votre situation et nous vous conseillons de ne surtout pas vous inquiéter.
    De plus, au vu du nombre croissant de désinfections effectuées sur le forum, nous vous demandons un peu de patience et surtout de ne pas créer plusieurs postes pour le même problème.
    Merci de votre compréhension.

    Télécharge HijackThis ici:
    http://telechargement.zebulon.fr/138-hijackthis-1991.html

    Dézippe le dans un dossier prévu à cet effet.
    Par exemple C:\hijackthis < Enregistre-le bien dans c : !
    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/Hijenr.gif

    Lance le puis:
    Clique sur "do a system scan and save logfile" (cf démo)
    Faire un copier coller du log entier sur le forum

    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/demohijack.htm

    Bon courage

    A+
    0
    1. je me trouve avec la demoiselle voila ce qu on trouve
      avec antivir hadjajr.ini trojan horse TR/Qhost.MY.2

      avec hijackLogfile of Trend Micro HijackThis v2.0.2
      Scan saved at 20:06:55, on 01/10/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16512)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
      C:\WINDOWS\ehome\ehtray.exe
      C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
      C:\WINDOWS\eHome\ehmsas.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\SPYWAREfighter\spftray.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\MSN Messenger\MsnMsgr.Exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\AntiVir PersonalEdition Classic\avcenter.exe
      C:\WINDOWS\system32\HPZipm12.exe
      C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
      C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
      C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
      C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
      C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
      C:\Program Files\Wanadoo\GestionnaireInternet.exe
      C:\Program Files\Wanadoo\ComComp.exe
      C:\PROGRA~1\Wanadoo\Toaster.exe
      C:\PROGRA~1\Wanadoo\Inactivity.exe
      C:\PROGRA~1\Wanadoo\PollingModule.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\Program Files\Wanadoo\Watch.exe
      C:\Program Files\MSN Messenger\usnsvc.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Documents and Settings\Natalia\Bureau\text.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
      O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
      O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
      O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
      O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
      O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
      O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
      O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
      O4 - HKLM\..\Run: [BDSwitchAgent] "C:\progra~1\softwin\bitdef~1\bdswitch.exe"
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [spywarefighterguard] C:\Program Files\SPYWAREfighter\spftray.exe
      O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\eMule.exe -AutoStart
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = ?
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
      O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O14 - IERESET.INF: START_PAGE_URL=https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
      O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
      O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - https://www.eset.com/
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O20 - AppInit_DLLs: C:\WINDOWS\system32\hadjajr.ini
      O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
      O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      0
      1. Contributeur sécurité
        Pardon?

        Si tu n'es pas l'auteur du poste, crée toi ton propre poste.

        a+
        0
        1. non c mon bof il est a coté de moi vu que je comprend rien il est venu m aider il a des notions en informatique lui
          c' est le resultat de hijack sur mon pc qu il a editer
          0
          1. Contributeur sécurité
            Je viens de comprendre lol
            Attention aux sites X.

            Télécharge ceci: (merci a S!RI pour ce programme).
            http://siri.urz.free.fr/Fix/SmitfraudFix.exe
            Exécute le Smitfraudfix.exe et choisit l’option 1, il va générer un rapport
            Copie/colle le sur le poste stp.
            ----------------------------------------------------------------------------
            Démarre en mode sans échec :
            Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
            Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
            Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
            (Si F8 ne marche pas utilise la touche F5).
            ----------------------------------------------------------------------------
            Relance le programme Smitfraud,
            Cette fois choisit l’option 2, répond oui a tous ;
            Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum
            0
            1. Bonjour,
              c'est encore nat 26!!!!
              c'est la merde ca a recommencé....
              j'ai refait la meme manip mais je pense que c'est pas bien normal!
              j'ai mis les 2 rapport sur le forum si tu a l'occas de jeter un coup d'oeil!
              merci!
              0
            2. Bonjour,
              SmitFraudFix v2.237

              Rapport fait à 17:16:23,67, 05/10/2007
              Executé à partir de C:\Documents and Settings\Victor\SmitfraudFix
              OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
              Le type du système de fichiers est NTFS
              Fix executé en mode normal

              »»»»»»»»»»»»»»»»»»»»»»»» Process

              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
              C:\WINDOWS\system32\cisvc.exe
              C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
              C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              C:\Program Files\Spyware Doctor\svcntaux.exe
              C:\Program Files\Spyware Doctor\swdsvc.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
              C:\WINDOWS\wanmpsvc.exe
              C:\Program Files\VirusBuster\Bin\VBSNTW.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\WINDOWS\System32\alg.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\cidaemon.exe
              C:\WINDOWS\system32\wscntfy.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
              C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe
              C:\WINDOWS\tsnpstd3.exe
              C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
              C:\WINDOWS\SOUNDMAN.EXE
              C:\WINDOWS\vsnpstd3.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\WINDOWS\system32\igfxtray.exe
              C:\WINDOWS\system32\hkcmd.exe
              C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
              C:\Program Files\Hotbar\bin\10.0.342.0\OEAddOn.exe
              C:\Program Files\Hotbar\bin\10.0.342.0\HotbarSA.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\Program Files\Spyware Doctor\SDTrayApp.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\Program Files\Fichiers communs\AOL\1167939182\ee\aolsoftware.exe
              C:\Program Files\WinZip\WZQKPICK.EXE
              C:\PROGRA~1\Mozilla Firefox\firefox.exe
              C:\Program Files\MSN Messenger\usnsvc.exe
              C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
              C:\WINDOWS\system32\regmod.exe
              C:\WINDOWS\system32\cmd.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe

              »»»»»»»»»»»»»»»»»»»»»»»» hosts

              Fichier hosts corrompu !

              127.0.0.1 legal-at-spybot.info
              127.0.0.1 www.legal-at-spybot.info

              »»»»»»»»»»»»»»»»»»»»»»»» C:\

              »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

              »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

              »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

              »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

              C:\WINDOWS\system32\ieffse32.dll PRESENT !
              C:\WINDOWS\system32\regmod.exe PRESENT !
              C:\WINDOWS\system32\vzfhprk.dll PRESENT !

              »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Victor

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Victor\Application Data

              »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

              C:\DOCUME~1\ALLUSE~1\MENUDM~1\Online Security Guide.url PRESENT !
              C:\DOCUME~1\ALLUSE~1\MENUDM~1\Security Troubleshooting.url PRESENT !

              »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Victor\Favoris

              »»»»»»»»»»»»»»»»»»»»»»»» Bureau

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

              C:\Program Files\Online Video Add-on\ PRESENT !

              »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

              »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
              "Source"="About:Home"
              "SubscribedURL"="About:Home"
              "FriendlyName"="Ma page d'accueil"

              »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll

              »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
              "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~3\\GOEC62~1.DLL"
              "LoadAppInit_DLLs"=dword:00000001

              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
              "System"=""

              »»»»»»»»»»»»»»»»»»»»»»»» Rustock

              »»»»»»»»»»»»»»»»»»»»»»»» DNS

              Description: Intel(R) PRO/100 VE Network Connection - Miniport d'ordonnancement de paquets
              DNS Server Search Order: 192.168.1.2

              Description: AOLbox - Miniport d'ordonnancement de paquets
              DNS Server Search Order: 192.168.1.1

              HKLM\SYSTEM\CCS\Services\Tcpip\..\{5D9B9945-C887-4F4E-9972-38216B68036D}: NameServer=192.168.1.2
              HKLM\SYSTEM\CCS\Services\Tcpip\..\{71B4C5EC-6F49-41FF-921C-B1C9D1EDB07F}: DhcpNameServer=192.168.1.1
              HKLM\SYSTEM\CCS\Services\Tcpip\..\{FF0F230D-72E2-4E75-9C9B-4EFE8136A3CD}: NameServer=192.168.1.1
              HKLM\SYSTEM\CS1\Services\Tcpip\..\{5D9B9945-C887-4F4E-9972-38216B68036D}: NameServer=192.168.1.2
              HKLM\SYSTEM\CS1\Services\Tcpip\..\{71B4C5EC-6F49-41FF-921C-B1C9D1EDB07F}: DhcpNameServer=192.168.1.1
              HKLM\SYSTEM\CS1\Services\Tcpip\..\{FF0F230D-72E2-4E75-9C9B-4EFE8136A3CD}: NameServer=192.168.1.1
              HKLM\SYSTEM\CS2\Services\Tcpip\..\{5D9B9945-C887-4F4E-9972-38216B68036D}: NameServer=192.168.1.2
              HKLM\SYSTEM\CS2\Services\Tcpip\..\{71B4C5EC-6F49-41FF-921C-B1C9D1EDB07F}: DhcpNameServer=192.168.1.1
              HKLM\SYSTEM\CS2\Services\Tcpip\..\{FF0F230D-72E2-4E75-9C9B-4EFE8136A3CD}: NameServer=192.168.1.1
              HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
              HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
              HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

              »»»»»»»»»»»»»»»»»»»»»»»» Fin
              0
          2. dFix v2.234

            Rapport fait à 22:47:55,09, 01/10/2007
            Executé à partir de C:\Documents and Settings\Natalia\Bureau\SmitfraudFix
            OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
            Le type du système de fichiers est NTFS
            Fix executé en mode normal

            »»»»»»»»»»»»»»»»»»»»»»»» Process

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
            C:\WINDOWS\System32\FTRTSVC.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\WINDOWS\system32\WgaTray.exe
            C:\WINDOWS\ehome\ehtray.exe
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
            C:\Program Files\SPYWAREfighter\spftray.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\MSN Messenger\MsnMsgr.Exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
            C:\PROGRA~1\Wanadoo\ComComp.exe
            C:\PROGRA~1\Wanadoo\Toaster.exe
            C:\PROGRA~1\Wanadoo\Inactivity.exe
            C:\PROGRA~1\Wanadoo\PollingModule.exe
            C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
            C:\PROGRA~1\Wanadoo\Watch.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
            C:\WINDOWS\eHome\ehmsas.exe
            C:\WINDOWS\exploeee.exe
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\WINDOWS\system32\HPZipm12.exe
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\WINDOWS\system32\HPZipm12.exe
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\system32\cmd.exe
            C:\WINDOWS\system32\HPZipm12.exe

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            »»»»»»»»»»»»»»»»»»»»»»»» C:\

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

            C:\WINDOWS\system32\hadjajr.ini PRESENT !
            C:\WINDOWS\system32\vtr???.dll PRESENT !

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Natalia

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Natalia\Application Data

            »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

            »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Natalia\Favoris

            »»»»»»»»»»»»»»»»»»»»»»»» Bureau

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

            »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

            »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
            "Source"="About:Home"
            "SubscribedURL"="About:Home"
            "FriendlyName"="Ma page d'accueil"

            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLs"="C:\\WINDOWS\\system32\\hadjajr.ini"

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "System"=""

            »»»»»»»»»»»»»»»»»»»»»»»» Rustock

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            Description: Broadcom 802.11b/g WLAN - Miniport d'ordonnancement de paquets
            DNS Server Search Order: 192.168.1.1
            DNS Server Search Order: 0.0.0.0

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{18BC9557-F9EF-4DD6-93E9-DBACFDBFE888}: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{18BC9557-F9EF-4DD6-93E9-DBACFDBFE888}: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CS2\Services\Tcpip\..\{18BC9557-F9EF-4DD6-93E9-DBACFDBFE888}: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0

            »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

            »»»»»»»»»»»»»»»»»»»»»»»» Fin

            EN MODE SANS ECHECdFix v2.234

            Rapport fait à 23:05:25,43, 01/10/2007
            Executé à partir de C:\Documents and Settings\Natalia\Bureau\SmitfraudFix
            OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
            Le type du système de fichiers est NTFS
            Fix executé en mode sans echec

            »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            127.0.0.1 localhost

            »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

            S!Ri's WS2Fix: LSP not Found.

            »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

            GenericRenosFix by S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

            C:\WINDOWS\system32\vtr???.dll supprimé

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{18BC9557-F9EF-4DD6-93E9-DBACFDBFE888}: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{18BC9557-F9EF-4DD6-93E9-DBACFDBFE888}: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CS2\Services\Tcpip\..\{18BC9557-F9EF-4DD6-93E9-DBACFDBFE888}: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
            HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0

            »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "System"=""

            »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

            Nettoyage terminé.

            »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» Fin
            0
            1. ça a l air d etre bon
              en une soirée probleme resolu
              BRAVO Regis59

              ET ATTENTION AU SITE X
              L'ABUS D'ALCOOL ET DANGEREUX POUR LA SANTé
              0
              1. bon le message a reapparut mais a priori la mise en quarantane a fonctionné!.....
                merci!!!!
                un petit conseil: avast ou antivir?
                0
                1. Contributeur sécurité
                  Re

                  Sans hésitations, antivir.

                  Redemarre ton pc et refais un hijackthis + un smitfraudfix

                  a+
                  0
                  1. Contributeur sécurité
                    Bonjour,

                    Il serait préférable que tu fasses ton message personnel, cela rendra les postes plus compréhensibles et la réponse à ton problème sera plus efficace
                    Procèdes comme ceci :
                    http://pageperso.aol.fr/balltrap34/demofairesontmessage.htm

                    A bientôt
                    0