VIRUS ALERT a coté de l'horloge

Bonjour,
voila le rappport hijackthis,merci d'avance

thisLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:25: VIRUS ALERT!, on 30/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\vsnpstd3.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://bl149w.blu149.mail.live.com/mail/mail.aspx?&n=1995364564
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer optimisé pour MSN
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: LabelCommand module - {18CB1A7B-94CD-4582-8022-ADA16851E44B} - (no file)
O2 - BHO: {5d243d04-6839-a82a-4434-1f7a68e86cd1} - {1dc68e86-a7f1-4344-a28a-938640d342d5} - C:\WINDOWS\system32\atvxrq.dll (file missing)
O2 - BHO: (no name) - {329C942A-1918-4C3D-9B81-C6CE8C09F776} - C:\WINDOWS\system32\pmnnLDTM.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E156AAE-FA60-44A1-8E69-2E0E0030F1F6} - C:\WINDOWS\system32\ddcCRJbb.dll (file missing)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.5470\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {BFB5F154-9212-46F3-B547-AC6106030A54} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O3 - Toolbar: fdkowvbp - {DA803CD1-6849-49F1-89C0-E69F2C99BEEA} - C:\WINDOWS\fdkowvbp.dll (file missing)
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\wianmpa.exe
O4 - HKLM\..\Run: [advap32] C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\scksexde.exe/r
O4 - HKLM\..\Run: [88a91f36] rundll32.exe "C:\WINDOWS\system32\bjaurvtb.dll",b
O4 - HKLM\..\Run: [SMrhclqfj0eja5] C:\Program Files\rhclqfj0eja5\rhclqfj0eja5.exe
O4 - HKLM\..\Run: [Antivirus] C:\Program Files\AVM\avm.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\RunOnce: [*Restore] C:\WINDOWS\system32\restore\rstrui.exe -i
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [SRS Audio Sandbox] "C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Antivirus] C:\Program Files\AVM\avm.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-21-789336058-1580436667-1801674531-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-789336058-1580436667-1801674531-1003\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background (User '?')
O4 - HKUS\S-1-5-21-789336058-1580436667-1801674531-1003\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
O4 - HKUS\S-1-5-21-789336058-1580436667-1801674531-1003\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe (User '?')
O4 - HKUS\S-1-5-21-789336058-1580436667-1801674531-1003\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User '?')
O4 - HKUS\S-1-5-21-789336058-1580436667-1801674531-1003\..\Run: [Antivirus] C:\Program Files\AVM\avm.exe (User '?')
O4 - HKUS\S-1-5-21-789336058-1580436667-1801674531-1003\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM= (User '?')
O4 - HKUS\S-1-5-21-789336058-1580436667-1801674531-1003\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-21-789336058-1580436667-1801674531-1003 Startup: BoontyBox 01net.lnk = C:\Program Files\Boonty\BoontyBox\BoontyBox.exe (User '?')
O4 - S-1-5-21-789336058-1580436667-1801674531-1003 Startup: YesMessenger.lnk = C:\Program Files\YesMessenger\YesMessenger.exe (User '?')
O4 - Startup: BoontyBox 01net.lnk = C:\Program Files\Boonty\BoontyBox\BoontyBox.exe
O4 - Startup: YesMessenger.lnk = C:\Program Files\YesMessenger\YesMessenger.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O15 - Trusted Zone: http://www.secuser.com
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by121fd.bay121.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://sabolivfournaise2.spaces.live.com/PhotoUpload/MsnPUpld.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll
O20 - Winlogon Notify: ddcCRJbb - ddcCRJbb.dll (file missing)
O21 - SSODL: wnslvxtf - {11627438-E83C-4EED-BC7D-8F1C59938480} - C:\WINDOWS\wnslvxtf.dll (file missing)
O21 - SSODL: eqvwamkl - {92B88A52-BD31-47F8-A2F0-B131F8AD8FDC} - C:\WINDOWS\eqvwamkl.dll (file missing)
O21 - SSODL: rqbmvpso - {324E7472-A137-4CED-A439-689EE4ED0545} - C:\WINDOWS\rqbmvpso.dll (file missing)
O21 - SSODL: pdoskegl - {6A5E6482-CE2F-4FA3-9330-44B22F27B20F} - C:\WINDOWS\pdoskegl.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 14742 bytes
Configuration: Windows XP
Internet Explorer 7.0

49 réponses

Résumé de la discussion

Un poste Windows XP est infecté selon un rapport HijackThis, nécessitant un nettoyage et des mesures de sécurité pour éliminer les éléments indésirables et rétablir la stabilité. Plusieurs solutions essentielles sont proposées: relancer HijackThis en mode scan, cocher et supprimer les entrées suspectes, puis mettre à jour Java et Adobe Reader. Des recommandations précises incluent la suppression d’éléments Boonty et Wanadoo, la désinstallation des anciennes versions Java, puis la mise à jour d’Adobe Reader et le contrôle des extensions suspectes. En cas de problème, d’autres réponses évoquent des nettoyages supplémentaires et des rapports ultérieurs, sans conclure sur l’état final et en recommandant de vérifier les outils et les mises à jour.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    re,

    commence par faire ceci stp :

    Option 1 - Recherche :

    télécharge smitfraudfix et enregistre le sur le bureau à cette adresse (c est le numéro 2 en bas de la page) :

    https://www.androidworld.fr/

    Ensuite double clique sur smitfraudfix puis exécuter

    Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.

    copier/coller le rapport dans la réponse.
    0
    1. SmitFraudFix v2.342

      Recherche Process...
      C:\Documents and Settings\Propriétaire\Bureau\SmitfraudFix\ProcessList.vbs(15, 1
      ) (null): 0x80041002

      Recherche hosts...
      Recherche C:\...
      Recherche C:\WINDOWS\...
      Recherche C:\WINDOWS\system...
      Recherche C:\WINDOWS\Web...
      Recherche C:\WINDOWS\system32...
      Recherche C:\WINDOWS\system32\LogFiles...
      Recherche C:\Documents and Settings\Propriétaire...
      Recherche C:\Documents and Settings\Propriétaire\Application Data...
      Recherche Menu Démarrer...
      Recherche C:\DOCUME~1\PROPRI~1\Favoris...
      Recherche Bureau...
      Recherche C:\Program Files...
      Recherche présence de clés corrompues
      Recherche éléments du bureau
      Recherche IEDFix
      ^CTerminer le programme de commandes (O/N) ?
      0
      1. Contributeur sécurité
        le rapport est incomplet...il faut que tu recommence :s
        0
        1. j'ai etais trop vite
          a tout de suite
          0
          1. le voici complet sympa rapide et ..

            SmitFraudFix v2.342

            Rapport fait à 1:52:34,12, 30/08/2008
            Executé à partir de C:\Documents and Settings\Propri‚taire\Bureau\SmitfraudFix
            OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
            Le type du système de fichiers est NTFS
            Fix executé en mode normal

            »»»»»»»»»»»»»»»»»»»»»»»» Process

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            Fichier hosts corrompu !

            127.0.0.1 www.legal-at-spybot.info
            127.0.0.1 legal-at-spybot.info

            »»»»»»»»»»»»»»»»»»»»»»»» C:\

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

            C:\WINDOWS\privacy_danger PRESENT !

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Propri‚taire

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Propri‚taire\Application Data

            C:\Documents and Settings\Propri‚taire\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk PRESENT !

            »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

            »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\PROPRI~1\Favoris

            »»»»»»»»»»»»»»»»»»»»»»»» Bureau

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

            C:\Program Files\AVM\ PRESENT !
            C:\Program Files\PCHealthCenter\ PRESENT !

            »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

            »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
            "Source"="About:Home"
            "SubscribedURL"="About:Home"
            "FriendlyName"="Ma page d'accueil"

            »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            IEDFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» VACFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            VACFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            404Fix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            AntiXPVSTFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~3\\GOEC62~1.DLL,avgrsstx.dll"
            "LoadAppInit_DLLs"=dword:00000001

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
            "System"="lsass.exe"

            »»»»»»»»»»»»»»»»»»»»»»»» RK

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

            »»»»»»»»»»»»»»»»»»»»»»»» Fin
            0
            1. Contributeur sécurité
              ok maintenant fais ce qui suit dans l ordre stp :

              Télécharge cet outil de SiRi:

              http://siri.urz.free.fr/RHosts.php

              Double clique dessus pour l'exécuter

              et cliques sur " Restore original Hosts "

              ps : c est normal que rien ne se passe

              ensuire redémarre le pc

              ensuite :

              Option 2 - Nettoyage :

              Redémarrer l'ordinateur en mode sans échec (tapoter F8 au boot pour obtenir le menu de démarrage).

              Double cliquer sur smitfraudfix

              Sélectionner 2 pour supprimer les fichiers responsables de l'infection.

              A la question Voulez-vous nettoyer le registre ? répondre O (oui) afin de débloquer le fond d'écran et supprimer les clés de démarrage automatique de l'infection.

              Le fix déterminera si le fichier wininet.dll est infecté. A la question Corriger le fichier infecté ? répondre O (oui) pour remplacer le fichier corrompu.

              Redémarrer en mode normal et poster le rapport.

              ensuite :

              Télécharger sur le bureau malwarebytes à cette adresse :

              https://www.androidworld.fr/

              Voici un tuto pour bien l installer et bien l utiliser :

              https://www.androidworld.fr/

              Après l analyse, redémarrer le pc et poste le rapport !!

              Et refais un nouveau rapport hijackthis stp
              0
              1. SmitFraudFix v2.342

                Rapport fait à 2:41:15,68, 30/08/2008
                Executé à partir de C:\Documents and Settings\Propri‚taire\Bureau\SmitfraudFix
                OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                Le type du système de fichiers est NTFS
                Fix executé en mode normal

                »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                SrchSTS.exe by S!Ri
                Search SharedTaskScheduler's .dll

                »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                127.0.0.1 localhost

                »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                VACFix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                S!Ri's WS2Fix: LSP not Found.

                »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                GenericRenosFix by S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                C:\Documents and Settings\Propri‚taire\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk supprimé

                »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                IEDFix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                404Fix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

                AntiXPVSTFix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» RK

                »»»»»»»»»»»»»»»»»»»»»»»» DNS

                »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                "System"="lsass.exe"

                »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                Nettoyage terminé.

                »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                SrchSTS.exe by S!Ri
                Search SharedTaskScheduler's .dll

                »»»»»»»»»»»»»»»»»»»»»»»» Fin
                0
                1. Contributeur sécurité
                  c est en mode sans échec qu il fallait faire la suppression :s
                  0
                  1. est ce que je peux recommencer la procedure?
                    0
                2. voici le rapport en mode sans échec

                  SmitFraudFix v2.342

                  Rapport fait à 10:25:03,28, 30/08/2008
                  Executé à partir de C:\Documents and Settings\Propri‚taire\Bureau\SmitfraudFix
                  OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                  Le type du système de fichiers est NTFS
                  Fix executé en mode sans echec

                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                  127.0.0.1 localhost

                  »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                  VACFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                  S!Ri's WS2Fix: LSP not Found.

                  »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                  GenericRenosFix by S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                  »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                  IEDFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                  404Fix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

                  AntiXPVSTFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» RK

                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                  »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                  "System"="lsass.exe"

                  »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                  Nettoyage terminé.

                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Fin
                  0
                  1. Contributeur sécurité
                    Salut !!

                    refais une recherche avec smitfraudfix en mode normal stp
                    0
                    1. Voici le rapport aprés examen

                      Malwarebytes' Anti-Malware 1.25
                      Version de la base de données: 1096
                      Windows 5.1.2600 Service Pack 2

                      15:59:50 30/08/2008
                      mbam-log-08-30-2008 (15-59-50).txt

                      Type de recherche: Examen complet (C:\|F:\|H:\|)
                      Eléments examinés: 187717
                      Temps écoulé: 1 hour(s), 18 minute(s), 39 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 34
                      Valeur(s) du Registre infectée(s): 10
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 20
                      Fichier(s) infecté(s): 21

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1dc68e86-a7f1-4344-a28a-938640d342d5} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\CLSID\{1dc68e86-a7f1-4344-a28a-938640d342d5} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7e156aae-fa60-44a1-8e69-2e0e0030f1f6} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddccrjbb (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\CLSID\{7e156aae-fa60-44a1-8e69-2e0e0030f1f6} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\labelcommand.labelcommand (Trojan.BHO) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\labelcommand.labelcommand.1 (Trojan.BHO) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\tbsb05999.ietoolbar (Adware.DosPopToolbar) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\tbsb05999.ietoolbar.1 (Adware.DosPopToolbar) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\tbsb05999.tbsb05999 (Adware.DosPopToolbar) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\tbsb05999.tbsb05999.3 (Adware.DosPopToolbar) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\Interface\{4897bba6-48d9-468c-8efa-846275d7701b} (Adware.SoftMate) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\Interface\{9ebb289a-2d7b-465b-825f-1530b813e95a} (Adware.DosPopToolbar) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\Interface\{cd5c92ae-97b0-4bc3-ba65-ba0308d543bf} (Adware.DosPopToolbar) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\CLSID\{ca3eb689-8f09-4026-aa10-b9534c691ce0} (Trojan.BHO) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\Typelib\{4509d3cc-b642-4745-b030-645b79522c6d} (Adware.SoftMate) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18cb1a7b-94cd-4582-8022-ada16851e44b} (Trojan.BHO) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Secure Solutions (Rogue.Multiple) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\rhclqfj0eja5 (Rogue.Multiple) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\VAV (Rogue.VistaAntivirus2008) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\TypeLib\{2429bce0-3ced-4a29-82d2-324f8b129e9b} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\Interface\{752a2f92-43e3-4201-acc1-aaa7b81dfc23} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\Interface\{8ab5cba1-2a87-4966-bf20-1c3acc3d098d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\fdkowvbp.bewo (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\fdkowvbp.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\qalkfxor.bafv (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\qalkfxor.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.

                      Valeur(s) du Registre infectée(s):
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\advap32 (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\88a91f36 (Trojan.Vundo) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smrhclqfj0eja5 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\eqvwamkl (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\wnslvxtf (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\rqbmvpso (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\pdoskegl (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully.

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      C:\Program Files\SpyShredder (Rogue.SpyShredder) -> Quarantined and deleted successfully.
                      C:\WINDOWS\PIF (Trojan.Agent) -> Quarantined and deleted successfully.
                      C:\Program Files\rhclqfj0eja5 (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Propriétaire\Application Data\rhclqfj0eja5 (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Propriétaire\Application Data\rhclqfj0eja5\Quarantine (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Propriétaire\Application Data\rhclqfj0eja5\Quarantine\Autorun (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Propriétaire\Application Data\rhclqfj0eja5\Quarantine\Autorun\HKCU (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Propriétaire\Application Data\rhclqfj0eja5\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Propriétaire\Application Data\rhclqfj0eja5\Quarantine\Autorun\HKLM (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Propriétaire\Application Data\rhclqfj0eja5\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Propriétaire\Application Data\rhclqfj0eja5\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Propriétaire\Application Data\rhclqfj0eja5\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Propriétaire\Application Data\rhclqfj0eja5\Quarantine\BrowserObjects (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Propriétaire\Application Data\rhclqfj0eja5\Quarantine\Packages (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\All Users\Application Data\Secure Solutions (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\BASE (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\DELETED (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\SAVED (Rogue.Multiple) -> Quarantined and deleted successfully.

                      Fichier(s) infecté(s):
                      C:\WINDOWS\system32\atvxrq.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                      C:\WINDOWS\system32\ddcCRJbb.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Propriétaire\Local Settings\Application Data\msomk_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Propriétaire\Local Settings\Application Data\msomk_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Propriétaire\Local Settings\Application Data\msomk.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Propriétaire\Mes documents\Official-eMule_setup.exe (Adware.NaviPromo) -> Quarantined and deleted successfully.
                      C:\WINDOWS\ebpx.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      C:\WINDOWS\esea.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      C:\Program Files\rhclqfj0eja5\MFC71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Program Files\rhclqfj0eja5\msvcp71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Program Files\rhclqfj0eja5\msvcr71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG\20080827091440765.log (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG\20080827103819843.log (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG\20080827180213484.log (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG\20080827185939312.log (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG\20080827192606453.log (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG\20080828084133734.log (Rogue.Multiple) -> Quarantined and deleted successfully.
                      C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
                      C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
                      C:\WINDOWS\rodqgpvlkmb.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      C:\WINDOWS\system32\blphcgqfj0eja5.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      0
                      1. Contributeur sécurité
                        refais une recherche avec smitfraudfix stp
                        0
                        1. SmitFraudFix v2.342

                          Rapport fait à 19:05:37,96, 30/08/2008
                          Executé à partir de C:\Documents and Settings\Propri‚taire\Bureau\SmitfraudFix
                          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                          Le type du système de fichiers est NTFS
                          Fix executé en mode normal

                          »»»»»»»»»»»»»»»»»»»»»»»» Process

                          »»»»»»»»»»»»»»»»»»»»»»»» hosts

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Propri‚taire

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Propri‚taire\Application Data

                          »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\PROPRI~1\Favoris

                          »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                          »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                          »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          IEDFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          VACFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          404Fix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          AntiXPVSTFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                          "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~3\\GOEC62~1.DLLavgrsstx.dll"
                          "LoadAppInit_DLLs"=dword:00000001

                          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                          "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                          "System"="lsass.exe"

                          »»»»»»»»»»»»»»»»»»»»»»»» RK

                          »»»»»»»»»»»»»»»»»»»»»»»» DNS

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                          »»»»»»»»»»»»»»»»»»»»»»»» Fin
                          0
                          1. Contributeur sécurité
                            ok...refais un nouveau rapport hijackthis stp
                            0
                            1. Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 22:10:40, on 30/08/2008
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                              C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              C:\Program Files\Ahead\InCD\InCDsrv.exe
                              C:\WINDOWS\system32\nvsvc32.exe
                              C:\WINDOWS\system32\HPZipm12.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                              C:\PROGRA~1\AVG\AVG8\avgemc.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\WINDOWS\system32\wuauclt.exe
                              C:\WINDOWS\system32\RunDll32.exe
                              C:\WINDOWS\vsnpstd3.exe
                              C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
                              C:\WINDOWS\system32\hphmon05.exe
                              C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                              C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
                              C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                              C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
                              C:\Program Files\Ahead\InCD\InCD.exe
                              C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                              C:\WINDOWS\system32\rundll32.exe
                              C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                              C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                              C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
                              C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                              C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                              C:\Program Files\Windows Live\Messenger\usnsvc.exe
                              C:\Program Files\Internet Explorer\IEXPLORE.EXE
                              C:\WINDOWS\system32\wuauclt.exe
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer optimisé pour MSN
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                              O2 - BHO: (no name) - {329C942A-1918-4C3D-9B81-C6CE8C09F776} - C:\WINDOWS\system32\pmnnLDTM.dll (file missing)
                              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.5470\swg.dll
                              O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                              O3 - Toolbar: (no name) - {BFB5F154-9212-46F3-B547-AC6106030A54} - (no file)
                              O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                              O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
                              O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
                              O3 - Toolbar: fdkowvbp - {DA803CD1-6849-49F1-89C0-E69F2C99BEEA} - C:\WINDOWS\fdkowvbp.dll (file missing)
                              O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
                              O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
                              O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
                              O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
                              O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                              O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
                              O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                              O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
                              O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
                              O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                              O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                              O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\wianmpa.exe
                              O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                              O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                              O4 - HKLM\..\RunOnce: [*Restore] C:\WINDOWS\system32\restore\rstrui.exe -i
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
                              O4 - HKCU\..\Run: [SRS Audio Sandbox] "C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme
                              O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                              O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
                              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')
                              O4 - HKUS\S-1-5-21-789336058-1580436667-1801674531-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
                              O4 - HKUS\S-1-5-21-789336058-1580436667-1801674531-1003\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background (User '?')
                              O4 - HKUS\S-1-5-21-789336058-1580436667-1801674531-1003\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
                              O4 - HKUS\S-1-5-21-789336058-1580436667-1801674531-1003\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe (User '?')
                              O4 - HKUS\S-1-5-21-789336058-1580436667-1801674531-1003\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User '?')
                              O4 - HKUS\S-1-5-21-789336058-1580436667-1801674531-1003\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM= (User '?')
                              O4 - HKUS\S-1-5-21-789336058-1580436667-1801674531-1003\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User '?')
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                              O4 - S-1-5-21-789336058-1580436667-1801674531-1003 Startup: BoontyBox 01net.lnk = C:\Program Files\Boonty\BoontyBox\BoontyBox.exe (User '?')
                              O4 - S-1-5-21-789336058-1580436667-1801674531-1003 Startup: YesMessenger.lnk = C:\Program Files\YesMessenger\YesMessenger.exe (User '?')
                              O4 - Startup: BoontyBox 01net.lnk = C:\Program Files\Boonty\BoontyBox\BoontyBox.exe
                              O4 - Startup: YesMessenger.lnk = C:\Program Files\YesMessenger\YesMessenger.exe
                              O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
                              O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
                              O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
                              O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                              O15 - Trusted Zone: http://www.secuser.com
                              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by121fd.bay121.hotmail.msn.com/resources/MsnPUpld.cab
                              O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
                              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                              O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://sabolivfournaise2.spaces.live.com/PhotoUpload/MsnPUpld.cab
                              O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                              O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLLavgrsstx.dll
                              O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                              O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                              O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                              O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
                              O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                              O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                              O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
                              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                              0
                              1. Contributeur sécurité
                                tu as encore une toolbar infectée...fais ceci stp :

                                Télécharge Toolbar-S&D (Team IDN) sur ton Bureau à cette adresse :

                                (c est le numéro 6 en bas de la page) : https://www.androidworld.fr/

                                * Lance l'installation du programme en exécutant le fichier téléchargé.
                                * Double-clique maintenant sur le raccourci de Toolbar-S&D.
                                * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
                                * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
                                * Poste le rapport généré. (C:\TB.txt)
                                0
                                1. -----------\\ ToolBar S&D 1.1.6 XP/Vista

                                  ( : )
                                  USER : Propriétaire ( Administrator )

                                  "C:\ToolBar SD" ( MAJ : 30-08-2008|00:19 )
                                  Option : [1] ( 30/08/2008|22:30 )

                                  -----------\\ Recherche de Fichiers / Dossiers ...

                                  -----------\\ [..\Internet Explorer\Main]

                                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                  "Local Page"="C:\\windows\\system32\\blank.htm"
                                  "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                                  "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                                  "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                                  "Url"="http://www.microsoft.com/athome/community/rss.xml"
                                  "Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
                                  "Url"="http://www.microsoft.com/atwork/community/rss.xml"

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                                  "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                                  "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                                  "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                                  "Local Page"="C:\\windows\\system32\\blank.htm"
                                  "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"

                                  --------------------\\ Recherche d'autres infections

                                  C:\DOCUME~1\PROPRI~1\LOCALS~1\APPLIC~1\ysaoa.dat
                                  C:\DOCUME~1\PROPRI~1\LOCALS~1\APPLIC~1\ysaoa.exe
                                  C:\DOCUME~1\PROPRI~1\LOCALS~1\APPLIC~1\ysaoa_nav.dat
                                  C:\DOCUME~1\PROPRI~1\LOCALS~1\APPLIC~1\ysaoa_navps.dat
                                  C:\DOCUME~1\PROPRI~1\LOCALS~1\APPLIC~1\ysaoa_navup.dat
                                  [b]==> EGDACCESS <==/b

                                  C:\WINDOWS\system32\MTDLnnmp.ini
                                  C:\WINDOWS\system32\MTDLnnmp.ini2
                                  [b]==> VUNDO <==/b

                                  -----------\\ Fin du rapport a 22:31:13,00
                                  0
                                  1. Contributeur sécurité
                                    ok maintenant :

                                    Relance Toolbar-S&D en double-cliquant sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".
                                    ! Ne ferme pas la fenêtre lors de la suppression !
                                    Un rapport sera généré, poste son contenu ici.

                                    NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
                                    Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
                                    Tape explorer puis valide.

                                    ensuite refais un nouveau rapport hijackthis pour vérifier stp
                                    0
                                    1. -----------\\ ToolBar S&D 1.1.6 XP/Vista

                                      ( : )
                                      USER : Propriétaire ( Administrator )

                                      "C:\ToolBar SD" ( MAJ : 30-08-2008|00:19 )
                                      Option : [2] ( 30/08/2008|22:39 )

                                      -----------\\ Recherche de Fichiers / Dossiers ...

                                      -----------\\ [..\Internet Explorer\Main]

                                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                      "Local Page"="C:\\windows\\system32\\blank.htm"
                                      "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                                      "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                                      "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                                      "Url"="http://www.microsoft.com/athome/community/rss.xml"
                                      "Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
                                      "Url"="http://www.microsoft.com/atwork/community/rss.xml"

                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                                      "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                                      "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                                      "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                                      "Local Page"="C:\\windows\\system32\\blank.htm"
                                      "Start Page"="https://www.msn.com/fr-fr/"

                                      --------------------\\ Recherche d'autres infections

                                      C:\DOCUME~1\PROPRI~1\LOCALS~1\APPLIC~1\ysaoa.dat
                                      C:\DOCUME~1\PROPRI~1\LOCALS~1\APPLIC~1\ysaoa.exe
                                      C:\DOCUME~1\PROPRI~1\LOCALS~1\APPLIC~1\ysaoa_nav.dat
                                      C:\DOCUME~1\PROPRI~1\LOCALS~1\APPLIC~1\ysaoa_navps.dat
                                      C:\DOCUME~1\PROPRI~1\LOCALS~1\APPLIC~1\ysaoa_navup.dat
                                      [b]==> EGDACCESS <==/b

                                      C:\WINDOWS\system32\MTDLnnmp.ini
                                      C:\WINDOWS\system32\MTDLnnmp.ini2
                                      [b]==> VUNDO <==/b

                                      -----------\\ Fin du rapport a 22:40:03,62
                                      0
                                      1. entre deux je te remercie de ton aide,super site je ne connaissais pas
                                        0
                                        • 1
                                        • 2
                                        • 3