Antispyexpert

Résolu
Bonjour,
je suis infecté par antispyexpert et je ne suis pas très bon en informatique si quelqu'un peut m'aider?merci
Configuration: Windows 2000
Internet Explorer 6.0

24 réponses

Résumé de la discussion

Plusieurs échanges portent sur une infection par antispyexpert sur Windows 2000 et Internet Explorer 6, avec des rapports HijackThis et des demandes d’aide pour désinfecter l’ordinateur. Des réponses recommandent notamment de poster un nouveau rapport HijackThis, de réactiver la protection résidente et d’envisager un antivirus plus efficace, avec des références pratiques à Combofix et à des réglages du navigateur. Plusieurs participants évoquent des logs détaillés, des difficultés à réactiver Avast, et l’utilisation d’outils additionnels comme SmitfraudFix et des tutoriels en ligne pour guider la désinfection. D’ailleurs, des échanges mentionnent des infections datant d’octobre, et des tutoriels ainsi que des liens de téléchargement pour SmitfraudFix et des guides de nettoyage ont été fournis.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonjour,

    Merci de suivre la procédure suivante pour générer un rapport hijackthis qui me permettra de diagnostiquer le problème de ton ordinateur :

    Télécharge hijackthis sur ton bureau : https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/

    Installe le, puis fais ceci avant de le lancer :
    Va dans le menu démarrer --> Poste de travail --> disque local C --> Program Files --> Trend Micro --> Hijackthis --> cherche hijackthis.exe et fais un clic droit dessus --> renomme le en Jack.exe

    Ensuite lance le et clique sur "Do a system scan and save a logfile".
    Fais un copier-coller du rapport entier sur le forum

    1. voila le rappoLogfile of Trend Micro HijackThis v2.0.2
      Scan saved at 10:05:22, on 29/09/2008
      Platform: Windows 2000 SP2 (WinNT 5.00.2195)
      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
      Boot mode: Normal

      Running processes:
      C:\WINNT\System32\smss.exe
      C:\WINNT\system32\winlogon.exe
      C:\WINNT\system32\services.exe
      C:\WINNT\system32\lsass.exe
      C:\WINNT\system32\svchost.exe
      C:\WINNT\system32\spoolsv.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINNT\System32\svchost.exe
      C:\WINNT\System32\NMSSvc.exe
      C:\WINNT\system32\regsvc.exe
      C:\WINNT\system32\MSTask.exe
      C:\WINNT\system32\stisvc.exe
      C:\WINNT\System32\WBEM\WinMgmt.exe
      C:\WINNT\System32\mspmspsv.exe
      C:\WINNT\Explorer.EXE
      C:\WINNT\System32\Promon.exe
      C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
      C:\Program Files\Lexmark 2400 Series\lxcrmon.exe
      C:\Program Files\Lexmark 2400 Series\ezprint.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Fichiers communs\ACD Systems\EN\DevDetect.exe
      C:\WINNT\loadqm.exe
      C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINNT\System32\internat.exe
      C:\Program Files\SuperCopier\SuperCopier.exe
      C:\Program Files\MSN Messenger\MsnMsgr.Exe
      C:\WINNT\System32\lxcrcoms.exe
      C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\video232.cfg.exe
      C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
      C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\b.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\jack.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://portail.free.fr/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://portail.free.fr/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
      O2 - BHO: (no name) - {4A3F62A9-AFEB-4543-AE4D-DC2442444E64} - C:\WINNT\System32\opnonoNH.dll (file missing)
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
      O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
      O2 - BHO: (no name) - {C22E8711-AB35-4261-B10C-11AAC1B61693} - C:\WINNT\System32\rqRhGWNh.dll (file missing)
      O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
      O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
      O4 - HKLM\..\Run: [tourpath] regedit /s c:\winnt\tour.reg
      O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
      O4 - HKLM\..\Run: [Promon.exe] Promon.exe
      O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
      O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\NTFSCLUP.EXE
      O4 - HKLM\..\Run: [CSScheduleCheck] C:\CFGSAFE\SCHWIZEX.EXE -CHECK
      O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe"
      O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe"
      O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
      O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINNT\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [Device Detector] DevDetect.exe -autorun
      O4 - HKLM\..\Run: [LoadQM] loadqm.exe
      O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKCU\..\Run: [internat.exe] internat.exe
      O4 - HKCU\..\Run: [SuperCopier.exe] C:\Program Files\SuperCopier\SuperCopier.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [17439454330749638309807948345579] C:\Program Files\XP Antivirus\xpa.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [Somefox] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\video232.cfg.exe
      O4 - HKCU\..\Run: [Cognac] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\b.exe
      O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
      O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
      O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
      O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
      O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk (file missing)
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: Alice ADSL - {0962BEEC-ABDA-4E1E-ADA4-4CB37F38290D} - https://portail.free.fr/ (file missing) (HKCU)
      O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
      O14 - IERESET.INF: START_PAGE_URL=https://portail.free.fr/
      O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
      O20 - Winlogon Notify: opnonoNH - opnonoNH.dll (file missing)
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
      O23 - Service: LXCRCustomerConnect - Unknown owner - C:\WINNT\System32\spool\DRIVERS\W32X86\3\\LXCRserv.exe
      O23 - Service: lxcr_device - - C:\WINNT\System32\lxcrcoms.exe
      O23 - Service: NMS Service (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
      O24 - Desktop Component 0: (no name) - file:///C:/Images/Dragon%20Ball/Dragon%20Ball%20Z/Dragon%20Ball%20Z%20-%20Calendrier%202007/Vegeta/veg_11.jpg
      1. voila le rappoLogfile of Trend Micro HijackThis v2.0.2
        Scan saved at 10:05:22, on 29/09/2008
        Platform: Windows 2000 SP2 (WinNT 5.00.2195)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
        Boot mode: Normal

        Running processes:
        C:\WINNT\System32\smss.exe
        C:\WINNT\system32\winlogon.exe
        C:\WINNT\system32\services.exe
        C:\WINNT\system32\lsass.exe
        C:\WINNT\system32\svchost.exe
        C:\WINNT\system32\spoolsv.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINNT\System32\svchost.exe
        C:\WINNT\System32\NMSSvc.exe
        C:\WINNT\system32\regsvc.exe
        C:\WINNT\system32\MSTask.exe
        C:\WINNT\system32\stisvc.exe
        C:\WINNT\System32\WBEM\WinMgmt.exe
        C:\WINNT\System32\mspmspsv.exe
        C:\WINNT\Explorer.EXE
        C:\WINNT\System32\Promon.exe
        C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
        C:\Program Files\Lexmark 2400 Series\lxcrmon.exe
        C:\Program Files\Lexmark 2400 Series\ezprint.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Fichiers communs\ACD Systems\EN\DevDetect.exe
        C:\WINNT\loadqm.exe
        C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINNT\System32\internat.exe
        C:\Program Files\SuperCopier\SuperCopier.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\WINNT\System32\lxcrcoms.exe
        C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\video232.cfg.exe
        C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
        C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\b.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Trend Micro\HijackThis\jack.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://portail.free.fr/
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://portail.free.fr/
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
        O2 - BHO: (no name) - {4A3F62A9-AFEB-4543-AE4D-DC2442444E64} - C:\WINNT\System32\opnonoNH.dll (file missing)
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
        O2 - BHO: (no name) - {C22E8711-AB35-4261-B10C-11AAC1B61693} - C:\WINNT\System32\rqRhGWNh.dll (file missing)
        O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
        O4 - HKLM\..\Run: [tourpath] regedit /s c:\winnt\tour.reg
        O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
        O4 - HKLM\..\Run: [Promon.exe] Promon.exe
        O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
        O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\NTFSCLUP.EXE
        O4 - HKLM\..\Run: [CSScheduleCheck] C:\CFGSAFE\SCHWIZEX.EXE -CHECK
        O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe"
        O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe"
        O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
        O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINNT\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
        O4 - HKLM\..\Run: [Device Detector] DevDetect.exe -autorun
        O4 - HKLM\..\Run: [LoadQM] loadqm.exe
        O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKCU\..\Run: [internat.exe] internat.exe
        O4 - HKCU\..\Run: [SuperCopier.exe] C:\Program Files\SuperCopier\SuperCopier.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [17439454330749638309807948345579] C:\Program Files\XP Antivirus\xpa.exe
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [Somefox] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\video232.cfg.exe
        O4 - HKCU\..\Run: [Cognac] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\b.exe
        O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
        O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
        O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
        O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
        O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
        O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk (file missing)
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: Alice ADSL - {0962BEEC-ABDA-4E1E-ADA4-4CB37F38290D} - https://portail.free.fr/ (file missing) (HKCU)
        O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
        O14 - IERESET.INF: START_PAGE_URL=https://portail.free.fr/
        O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
        O20 - Winlogon Notify: opnonoNH - opnonoNH.dll (file missing)
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
        O23 - Service: LXCRCustomerConnect - Unknown owner - C:\WINNT\System32\spool\DRIVERS\W32X86\3\\LXCRserv.exe
        O23 - Service: lxcr_device - - C:\WINNT\System32\lxcrcoms.exe
        O23 - Service: NMS Service (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
        O24 - Desktop Component 0: (no name) - file:///C:/Images/Dragon%20Ball/Dragon%20Ball%20Z/Dragon%20Ball%20Z%20-%20Calendrier%202007/Vegeta/veg_11.jpg
        1. Contributeur sécurité
          Télécharge SmitfraudFix : http://siri.urz.free.fr/Fix/SmitfraudFix.exe

          - Enregistre-le sur le bureau

          - Double-clique sur SmitfraudFix.exe et choisis l'option 1 puis Entrée

          - Un rapport sera généré, poste-le dans ta prochaine réponse stp.

          Tutoriel ici pour t'aider : http://www.malekal.com//tutorial_SmitFraudfix.php

          1. voila le rapport que tu m'as demandé merci beucoup pour ton aide;
            SmitFraudFix v2.354

            Rapport fait à 15:22:25,76, mer. 01/10/2008
            Executé à partir de C:\Documents and Settings\Administrateur\Bureau\SmitfraudFix
            OS: Microsoft Windows 2000 [Version 5.00.2195] - Windows_NT
            Le type du système de fichiers est FAT32
            Fix executé en mode normal

            »»»»»»»»»»»»»»»»»»»»»»»» Process

            C:\WINNT\System32\smss.exe
            C:\WINNT\system32\winlogon.exe
            C:\WINNT\system32\services.exe
            C:\WINNT\system32\lsass.exe
            C:\WINNT\system32\svchost.exe
            C:\WINNT\system32\spoolsv.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINNT\System32\svchost.exe
            C:\WINNT\system32\regsvc.exe
            C:\WINNT\system32\MSTask.exe
            C:\WINNT\system32\stisvc.exe
            C:\WINNT\System32\WBEM\WinMgmt.exe
            C:\WINNT\System32\mspmspsv.exe
            C:\WINNT\Explorer.EXE
            C:\WINNT\System32\Promon.exe
            C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
            C:\Program Files\Lexmark 2400 Series\lxcrmon.exe
            C:\Program Files\Lexmark 2400 Series\ezprint.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
            C:\Program Files\Fichiers communs\ACD Systems\EN\DevDetect.exe
            C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\WINNT\System32\internat.exe
            C:\Program Files\SuperCopier\SuperCopier.exe
            C:\Program Files\MSN Messenger\MsnMsgr.Exe
            C:\WINNT\System32\lxcrcoms.exe
            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
            C:\Documents and Settings\Administrateur\Bureau\SmitfraudFix\Policies.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Documents and Settings\Administrateur\Bureau\SmitfraudFix\Policies.exe
            C:\WINNT\System32\cmd.exe

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            »»»»»»»»»»»»»»»»»»»»»»»» C:\

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\Web

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system32

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrateur

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrateur\Application Data

            »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

            »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\FAVORIS

            »»»»»»»»»»»»»»»»»»»»»»»» Bureau

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

            C:\Program Files\PCHealthCenter\ PRESENT !
            C:\Program Files\sav\ PRESENT !

            »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

            »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
            "Source"="file:///C:/Images/Dragon%20Ball/Dragon%20Ball%20Z/Dragon%20Ball%20Z%20-%20Calendrier%202007/Vegeta/veg_11.jpg"
            "SubscribedURL"="file:///C:/Images/Dragon%20Ball/Dragon%20Ball%20Z/Dragon%20Ball%20Z%20-%20Calendrier%202007/Vegeta/veg_11.jpg"
            "FriendlyName"=""

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
            "Source"="About:Home"
            "SubscribedURL"="About:Home"
            "FriendlyName"="Ma page d'accueil"

            »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            o4Patch
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            IEDFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» VACFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            VACFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            404Fix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            AntiXPVSTFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "Userinit"="C:\\WINNT\\system32\\userinit.exe,"
            "System"=""

            »»»»»»»»»»»»»»»»»»»»»»»» RK

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            Description: Intel 8255x-based Integrated Fast Ethernet
            DNS Server Search Order: 192.168.1.1

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{B6ABF9F3-C561-4E1B-BA00-081DA7F38736}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{B6ABF9F3-C561-4E1B-BA00-081DA7F38736}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS2\Services\Tcpip\..\{B6ABF9F3-C561-4E1B-BA00-081DA7F38736}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

            »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

            »»»»»»»»»»»»»»»»»»»»»»»» Fin
            1. Contributeur sécurité
              Très bien :)

              1) Maintenant, démarre en mode sans échec :
              Pour cela, tu tapotes sur la touche F8 (F5 sur certains pc) dès le début de l’allumage du PC sans t’arrêter, avant l'apparition du logo Windows. Un menu va apparaitre, déplace-toi avec les flèches du clavier sur Démarrer en mode sans échec puis tape Entrée. Choisis ta session habituelle, et ne t'inquiète pas si les couleurs et la taille des icônes changent, c'est normal !

              Relance le programme SmitfraudFix.
              Cette fois, choisis l’option 2, répond oui à tous;
              A la fin, sauvegarde le rapport, redémarre en mode normal, copie-colle le rapport sauvegardé sur le forum.

              2) Télécharge et installe Malwarebytes' Anti-Malware
              - A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée
              - Lance MBAM, laisse les Mises à jour se télécharger et referme le programme

              Redémarre en "Mode sans échec" : redémarre ton ordinateur et tapote sur la touche F8 jusqu'à l'affichage du menu des options avancées de Windows, et sélectionne "Mode sans échec". Choisis ta session habituelle

              Lance MBAM
              - Puis va dans l'onglet "Recherche", coche "Exécuter un examen complet" puis "Rechercher"
              - Sélectionne tes disques durs" puis clique sur "Lancer l’examen"
              - A la fin du scan, clique sur Afficher les résultats puis sur Enregistrer le rapport
              - Suppression des éléments détectés --> clique sur Supprimer la sélection
              - S'il t'es demandé de redémarrer, clique sur Yes

              Poste le rapport de scan après la suppression ici

              1. voici le rapport après avoir lancer SmitfraudFix
                SmitFraudFix v2.354

                Rapport fait à 16:06:35,59, jeu. 02/10/2008
                Executé à partir de C:\Documents and Settings\Administrateur\Bureau\SmitfraudFix
                OS: Microsoft Windows 2000 [Version 5.00.2195] - Windows_NT
                Le type du système de fichiers est FAT32
                Fix executé en mode sans echec

                »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                SrchSTS.exe by S!Ri
                Search SharedTaskScheduler's .dll

                »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                VACFix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                S!Ri's WS2Fix: LSP not Found.

                »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                GenericRenosFix by S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                C:\Program Files\PCHealthCenter\ supprimé
                C:\Program Files\sav\ supprimé

                »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                IEDFix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                404Fix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

                AntiXPVSTFix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» RK

                »»»»»»»»»»»»»»»»»»»»»»»» DNS

                HKLM\SYSTEM\CCS\Services\Tcpip\..\{B6ABF9F3-C561-4E1B-BA00-081DA7F38736}: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CS1\Services\Tcpip\..\{B6ABF9F3-C561-4E1B-BA00-081DA7F38736}: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CS2\Services\Tcpip\..\{B6ABF9F3-C561-4E1B-BA00-081DA7F38736}: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                "System"=""

                »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                Nettoyage terminé.

                »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                SrchSTS.exe by S!Ri
                Search SharedTaskScheduler's .dll

                »»»»»»»»»»»»»»»»»»»»»»»» Fin
                1. voila le scan après avoir lancé MBAM
                  Malwarebytes' Anti-Malware 1.28
                  Version de la base de données: 1225
                  Windows 5.0.2195 Service Pack 2

                  02/10/2008 17:22:17
                  mbam-log-2008-10-02 (17-22-09).txt

                  Type de recherche: Examen complet (A:\|C:\|D:\|E:\|)
                  Eléments examinés: 65599
                  Temps écoulé: 48 minute(s), 43 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 3
                  Valeur(s) du Registre infectée(s): 2
                  Elément(s) de données du Registre infecté(s): 2
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 2

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4a3f62a9-afeb-4543-ae4d-dc2442444e64} (Trojan.Vundo.H) -> No action taken.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\opnononh (Trojan.Vundo.H) -> No action taken.
                  HKEY_CLASSES_ROOT\CLSID\{4a3f62a9-afeb-4543-ae4d-dc2442444e64} (Trojan.Vundo.H) -> No action taken.

                  Valeur(s) du Registre infectée(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\rhc5uaj0erjm (Rogue.AntivirusXP2008) -> No action taken.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Cognac (Trojan.FakeAlert) -> No action taken.

                  Elément(s) de données du Registre infecté(s):
                  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders (Broken.SecurityProviders) -> Bad: (msapsspc.dll schannel.dll digest.dll msnsspc.dll) Good: (msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll) -> No action taken.
                  HKEY_CLASSES_ROOT\scrfile\shell\open\command\ (Broken.OpenCommand) -> Bad: ("%1" %*) Good: ("%1" /S) -> No action taken.

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  C:\WINNT\System32\opnonoNH.dll (Trojan.Vundo.H) -> No action taken.
                  C:\Documents and Settings\Administrateur\admin.exe (Trojan.Agent) -> No action taken.
                  1. voila le scan après avoir lancé MBAM
                    Malwarebytes' Anti-Malware 1.28
                    Version de la base de données: 1225
                    Windows 5.0.2195 Service Pack 2

                    02/10/2008 17:22:17
                    mbam-log-2008-10-02 (17-22-09).txt

                    Type de recherche: Examen complet (A:\|C:\|D:\|E:\|)
                    Eléments examinés: 65599
                    Temps écoulé: 48 minute(s), 43 second(s)

                    Processus mémoire infecté(s): 0
                    Module(s) mémoire infecté(s): 0
                    Clé(s) du Registre infectée(s): 3
                    Valeur(s) du Registre infectée(s): 2
                    Elément(s) de données du Registre infecté(s): 2
                    Dossier(s) infecté(s): 0
                    Fichier(s) infecté(s): 2

                    Processus mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Module(s) mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Clé(s) du Registre infectée(s):
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4a3f62a9-afeb-4543-ae4d-dc2442444e64} (Trojan.Vundo.H) -> No action taken.
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\opnononh (Trojan.Vundo.H) -> No action taken.
                    HKEY_CLASSES_ROOT\CLSID\{4a3f62a9-afeb-4543-ae4d-dc2442444e64} (Trojan.Vundo.H) -> No action taken.

                    Valeur(s) du Registre infectée(s):
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\rhc5uaj0erjm (Rogue.AntivirusXP2008) -> No action taken.
                    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Cognac (Trojan.FakeAlert) -> No action taken.

                    Elément(s) de données du Registre infecté(s):
                    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders (Broken.SecurityProviders) -> Bad: (msapsspc.dll schannel.dll digest.dll msnsspc.dll) Good: (msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll) -> No action taken.
                    HKEY_CLASSES_ROOT\scrfile\shell\open\command\ (Broken.OpenCommand) -> Bad: ("%1" %*) Good: ("%1" /S) -> No action taken.

                    Dossier(s) infecté(s):
                    (Aucun élément nuisible détecté)

                    Fichier(s) infecté(s):
                    C:\WINNT\System32\opnonoNH.dll (Trojan.Vundo.H) -> No action taken.
                    C:\Documents and Settings\Administrateur\admin.exe (Trojan.Agent) -> No action taken.
                    1. Contributeur sécurité
                      Bien ;) Poste un nouveau rapport hijackthis

                      Ensuite, on va utiliser Combofix pour finir la désinfection. Attention, ce logiciel est très puissant, une mauvaise utilisation peut faire des dégâts...

                      Fais exactement ce qui suit :

                      Télécharge ComboFix (de sUBs) sur ton Bureau (et pas ailleurs !) :
                      Fais un clic droit sur ce lien et choisis "enregistrer la cible sous ... " : dans la fenêtre qui s'ouvre tape C-Fix, choisis le bureau comme destination et valide : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                      --------------------------------------------- [ ! ATTENTION ! ] ----------------------------------------------------------
                      !! déconnecte toi, ferme toutes tes applications en cours et DESACTIVE TOUTES TES DEFENCES (anti-virus, antispyware, pare-feu) le temps de la manipulation : en effet , activés, ils pourraient gêner fortement la procédure de recherche et de nettoyage de l'outil ( voir planter le PC )...Tu les réactiveras donc après !!

                      Dans ton cas, il s'agit d'Avast et du TeaTimer de Spybot (Lance Spybot --> clique sur Mode => coche Mode avancé => Outils => Résident => décoche la case Résident Tea Timer => ferme Spybot)

                      ---> Surtout, si tu rencontres des difficultés à ce niveau là, dis le moi avant de poursuivre...

                      Tuto ici : https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
                      ---------------------------------------------------------------------------------------------------------------------------------

                      Ensuite :
                      double-clique sur C-Fix.exe (= combofix.exe ) .

                      Appuie sur une touche pour démarrer le scan .

                      Attention : n'utilise pas ta souris ni ton clavier pendant que le programme tourne. Cela pourrait figer l'ordi ---> si un message d'erreur windows apparait à un moment : clique sur la croix rouge en haut à droite de la fenêtre pour la fermer

                      Le rapport sera crée dans: C:\Combofix.txt , poste le ici stp

                      --
                      Si on vous aide pour désinfecter votre ordinateur, 
                      ne partez pas quand les symptomes disparaissent,
                      attendez qu'on vous dise que l'infection a été éradiquée
                      1. Contributeur sécurité
                        Fais un clic droit sur l'icone d'avast près de l'horloge et clique sur "arrêter la protection résidente"

                        1. voila le scan de combofif jespère ne pas m'être planté
                          ComboFix 08-10-06.06 - Administrateur 08/10/2008 13:42:53.2 - [color=red][b]FAT32[/b][/color]x86
                          Microsoft Windows 2000 Professionnel 5.0.2195.2.1252.1.1036.18.115 [GMT 2:00]
                          Lancé depuis: C:\Documents and Settings\Administrateur\Bureau\C-Fix.exe

                          [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
                          .

                          ((((((((((((((((((((((((((((( Fichiers créés du 2008-09-08 au 2008-10-08 ))))))))))))))))))))))))))))))))))))
                          .

                          2008-10-08 13:46 . 08-10-08 13:46 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_1fc.dat
                          2008-10-02 17:24 . 08-10-02 17:24 <DIR> d-------- C:\FOUND.001
                          2008-10-02 16:18 . 08-10-07 21:43 643,132 ---h----- C:\WINNT\ShellIconCache
                          2008-10-01 15:22 . 08-10-02 16:06 3,344 --a------ C:\WINNT\system32\tmp.reg
                          2008-09-30 20:17 . 08-09-30 20:17 <DIR> d-------- C:\FOUND.000
                          2008-09-29 09:55 . 08-09-29 09:55 <DIR> d-------- C:\Program Files\Trend Micro
                          2008-09-24 19:04 . 08-09-24 19:04 <DIR> d-------- C:\Program Files\NetDuster

                          .
                          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          2008-09-19 10:26 82,944 ----a-w C:\WINNT\system32\o4Patch.exe
                          2008-09-19 10:26 82,944 ----a-w C:\WINNT\system32\IEDFix.C.exe
                          2008-09-09 22:04 38,528 ----a-w C:\WINNT\system32\drivers\mbamswissarmy.sys
                          2008-09-09 22:03 17,200 ----a-w C:\WINNT\system32\drivers\mbam.sys
                          2008-09-08 21:38 88,576 ----a-w C:\WINNT\system32\AntiXPVSTFix.exe
                          2008-09-02 14:51 86,528 ----a-w C:\WINNT\system32\VACFix.exe
                          2008-08-18 14:51 --------- d-----w C:\Program Files\RogueRemover FREE
                          2008-08-18 10:19 82,432 ----a-w C:\WINNT\system32\404Fix.exe
                          2008-07-03 06:41 62,910 ----a-w C:\Program Files\Uninstall.exe
                          2008-07-03 06:41 0 ----a-w C:\Program Files\uninstall.dat
                          2006-08-17 07:35 271 ---h--w C:\Program Files\desktop.ini
                          2006-08-17 07:35 22,115 ---h--w C:\Program Files\folder.htt
                          2001-05-07 15:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
                          .

                          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          .
                          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                          REGEDIT4

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "SuperCopier.exe"="C:\Program Files\SuperCopier\SuperCopier.exe" [03-04-25 00:03 683520]
                          "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [07-09-04 23:40 6856704]
                          "internat.exe"="internat.exe" [01-05-07 17:00 20752 C:\WINNT\system32\internat.exe]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "NvCplDaemon"="NvQTwk" [X]
                          "tourpath"="regedit" [X]
                          "Smapp"="C:\Program Files\Analog Devices\SoundMAX\Smtray.exe" [01-10-12 15:45 69632]
                          "ConfigSafe"="C:\CFGSAFE\NTFSCLUP.EXE" [01-05-18 15:17 40960]
                          "CSScheduleCheck"="C:\CFGSAFE\SCHWIZEX.EXE" [01-05-03 16:03 65536]
                          "lxcrmon.exe"="C:\Program Files\Lexmark 2400 Series\lxcrmon.exe" [06-03-06 18:48 286720]
                          "EzPrint"="C:\Program Files\Lexmark 2400 Series\ezprint.exe" [06-02-07 06:10 98304]
                          "FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [06-02-02 09:11 290816]
                          "LXCRCATS"="C:\WINNT\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll" [06-02-24 12:54 65536]
                          "NeroFilterCheck"="C:\WINNT\system32\NeroCheck.exe" [01-07-09 10:50 155648]
                          "ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [04-04-17 12:41 196608]
                          "ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [04-04-13 06:07 69632]
                          "msnappau"="C:\Program Files\MSN Apps\Updater\[u]0[/u]1.03.0000.1005\fr\msnappau.exe" [04-08-13 17:41 86016]
                          "Synchronization Manager"="mobsync.exe" [01-05-07 17:00 111888 C:\WINNT\system32\mobsync.exe]
                          "Promon.exe"="Promon.exe" [01-03-13 11:49 31232 C:\WINNT\system32\PROMON.EXE]
                          "LoadQM"="loadqm.exe" [00-05-03 17:23 7536 C:\WINNT\loadqm.exe]

                          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                          "internat.exe"="internat.exe" [01-05-07 17:00 20752 C:\WINNT\system32\internat.exe]

                          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
                          "^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [01-05-07 17:00 190224]

                          C:\Documents and Settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
                          Outil de d‚tection de support Picture Motion Browser.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-05-26 229376]

                          C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                          Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nwprovau]
                          01-05-07 17:00 141072 C:\WINNT\system32\nwprovau.dll

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                          "aux"= mmdrv.dll
                          "vidc.I420"= i420vfw.dll
                          "msacm.divxa32"= divxa32.acm
                          "vidc.DIV3"= DivXc32.dll
                          "vidc.DIV4"= DivXc32f.dll
                          "vidc.3ivx"= 3ivxVfWCodec.dll
                          "vidc.VP40"= vp4vfw.dll
                          "vidc.VP50"= vp5vfw.dll
                          "vidc.yv12"= yv12vfw.dll
                          "vidc.ffds"= ffdshow.ax

                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                          Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

                          [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                          "AntiVirusDisableNotify"="0x00000000"
                          "UpdatesDisableNotify"="0x00000000"

                          R0 SONYPVM1;Sony Memory Stick Driver(SONYPVM1);C:\WINNT\System32\DRIVERS\SONYPVM1.SYS [00-05-27 04:37 28224]
                          R1 aswSP;avast! Self Protection;C:\WINNT\System32\drivers\aswSP.sys [08-07-19 16:35 78416]
                          R2 aswMon;avast! Standard Shield Support;C:\WINNT\System32\drivers\aswMon.sys [08-01-17 18:34 93264]
                          R2 DbgMsg;Debug Message;C:\WINNT\System32\Drivers\DbgMsg.sys [04-08-23 11:16 18240]
                          R2 LXCRCustomerConnect;LXCRCustomerConnect;C:\WINNT\System32\spool\DRIVERS\W32X86\3\\LXCRserv.exe [06-02-24 12:55 61440]
                          S0 ufltipks;ufltipks;C:\WINNT\System32\drivers\zkeog.sys [ ]
                          .
                          Contenu du dossier 'Tâches planifiées'

                          2008-08-04 C:\WINNT\Tasks\Image planifiée.job
                          - C:\CFGSAFE\SCHWIZEX.EXE [01-05-03 16:03 ]
                          .
                          .
                          ------- Examen supplémentaire -------
                          .
                          FireFox -: Profile - C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\d2hjaqpr.default\
                          FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.aliceadsl.fr/
                          .

                          **************************************************************************

                          catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2008-10-08 13:47:00
                          Windows 5.0.2195 Service Pack 2 FAT NTAPI

                          Recherche de processus cachés ...

                          Recherche d'éléments en démarrage automatique cachés ...

                          HKLM\Software\Microsoft\Windows\CurrentVersion\Run
                          LXCRCATS = rundll32 C:\WINNT\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

                          Recherche de fichiers cachés ...

                          Scan terminé avec succès
                          Fichiers cachés: 0

                          **************************************************************************
                          .
                          ------------------------ Autres processus actifs ------------------------
                          .
                          SystemRoot\System32\smss.exe [136]
                          ??\C:\WINNT\system32\csrss.exe [164]
                          ??\C:\WINNT\system32\winlogon.exe [160]
                          C:\WINNT\system32\services.exe [212]
                          C:\WINNT\system32\lsass.exe [224]
                          C:\WINNT\system32\svchost.exe [392]
                          C:\WINNT\system32\spoolsv.exe [424]
                          C:\WINNT\System32\svchost.exe [528]
                          C:\WINNT\system32\regsvc.exe [664]
                          C:\WINNT\system32\stisvc.exe [696]
                          C:\WINNT\System32\WBEM\WinMgmt.exe [740]
                          C:\WINNT\System32\mspmspsv.exe [816]
                          C:\WINNT\system32\CF21644.exe [1160]
                          C:\WINNT\System32\Promon.exe [1416]
                          C:\Program Files\Analog Devices\SoundMAX\Smtray.exe [1476]
                          C:\Program Files\Lexmark 2400 Series\lxcrmon.exe [1512]
                          C:\Program Files\Lexmark 2400 Series\ezprint.exe [1520]
                          C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe [1488]
                          C:\Program Files\MSN Apps\Updater\[u]0[/u]1.03.0000.1005\fr\msnappau.exe [1524]
                          C:\WINNT\System32\internat.exe [1528]
                          C:\Program Files\SuperCopier\SuperCopier.exe [1176]
                          C:\WINNT\System32\lxcrcoms.exe [1500]
                          C:\Program Files\MSN Messenger\MsnMsgr.Exe [608]
                          C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [284]
                          C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [1364]
                          C:\WINNT\System32\drwtsn32.exe [296]
                          C:\WINNT\explorer.exe [1400]
                          C:\C-Fix\catchme.cfexe [1504]
                          .
                          **************************************************************************
                          .
                          Heure de fin: 2008-10-08 13:49:44 - La machine a redémarré
                          ComboFix-quarantined-files.txt 2008-10-08 11:49:34
                          ComboFix2.txt 2008-10-08 11:15:20

                          Avant-CF: 4 827 873 280 octets libres
                          Après-CF: 4,810,113,024 octets libres

                          151
                          1. Contributeur sécurité
                            De la même façon en cliquant sur "activer la protection résidente"
                            Sinon je crois qu'il se réactive tout seul au redémarrage de l'ordinateur de toute façon.

                            Je vais regarder le rapport de Combofix.
                            1. salut,en fait l'icône avast n'apparait plus dans la barre en bas,donc je ne sais pas comment faire pour réactiver et il ne s'est pas mis en route lors du démarrage de l'ordi car lorsque je vais dans msn messenger ,pour voir mes mails,ça m'indique que ce n'est plus sécurisé,pareil lorque je veux aller sur internet.
                              1. Contributeur sécurité
                                Poste un nouveau rapport hijackthis stp

                                Pour Avast, si tu es d'accord, je vais te conseiller de changer d'antivirus pour un autre plus efficace. Si tu ne veux pas, je t'aiderai à faire réapparaitre l'icone d'avast.

                                1. oui je suis d'accord pour un nouvel antivirus car là c'est galère voivi le nouveau rapport hijakthis

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 16:33:31, on 11/10/2008
                                  Platform: Windows 2000 SP2 (WinNT 5.00.2195)
                                  MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINNT\System32\smss.exe
                                  C:\WINNT\system32\winlogon.exe
                                  C:\WINNT\system32\services.exe
                                  C:\WINNT\system32\lsass.exe
                                  C:\WINNT\system32\svchost.exe
                                  C:\WINNT\system32\spoolsv.exe
                                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  C:\WINNT\System32\svchost.exe
                                  C:\WINNT\System32\NMSSvc.exe
                                  C:\WINNT\system32\regsvc.exe
                                  C:\WINNT\system32\stisvc.exe
                                  C:\WINNT\System32\WBEM\WinMgmt.exe
                                  C:\WINNT\System32\mspmspsv.exe
                                  C:\WINNT\Explorer.EXE
                                  C:\WINNT\System32\Promon.exe
                                  C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
                                  C:\Program Files\Lexmark 2400 Series\lxcrmon.exe
                                  C:\Program Files\Lexmark 2400 Series\ezprint.exe
                                  C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe
                                  C:\WINNT\System32\internat.exe
                                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  C:\Program Files\SuperCopier\SuperCopier.exe
                                  C:\Program Files\MSN Messenger\MsnMsgr.Exe
                                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  C:\WINNT\System32\lxcrcoms.exe
                                  C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                                  C:\WINNT\system32\msiexec.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
                                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
                                  O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                                  O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
                                  O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
                                  O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
                                  O4 - HKLM\..\Run: [tourpath] regedit /s c:\winnt\tour.reg
                                  O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
                                  O4 - HKLM\..\Run: [Promon.exe] Promon.exe
                                  O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
                                  O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\NTFSCLUP.EXE
                                  O4 - HKLM\..\Run: [CSScheduleCheck] C:\CFGSAFE\SCHWIZEX.EXE -CHECK
                                  O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe"
                                  O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe"
                                  O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
                                  O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINNT\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16
                                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
                                  O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                                  O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                                  O4 - HKLM\..\Run: [LoadQM] loadqm.exe
                                  O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe"
                                  O4 - HKCU\..\Run: [internat.exe] internat.exe
                                  O4 - HKCU\..\Run: [SuperCopier.exe] C:\Program Files\SuperCopier\SuperCopier.exe
                                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
                                  O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
                                  O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                                  O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                  O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
                                  O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
                                  O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk (file missing)
                                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O9 - Extra button: Alice ADSL - {0962BEEC-ABDA-4E1E-ADA4-4CB37F38290D} - https://portail.free.fr/ (file missing) (HKCU)
                                  O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
                                  O14 - IERESET.INF: START_PAGE_URL=https://portail.free.fr/
                                  O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
                                  O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
                                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
                                  O23 - Service: LXCRCustomerConnect - Unknown owner - C:\WINNT\System32\spool\DRIVERS\W32X86\3\\LXCRserv.exe
                                  O23 - Service: lxcr_device - - C:\WINNT\System32\lxcrcoms.exe
                                  O23 - Service: NMS Service (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
                                  1. salut,

                                    je vois que tu as été infecté par le virus antispyexpert en octobre dernier.
                                    me voila toucher a mon tour!
                                    je voulais savoir si la demarche que l'on ta donné a fonctionner?
                                    merci de me repondre au plus vite pour que je puisse faire de meme si cela a fonctionner!

                                    merci d'avance
                                  2. Contributeur sécurité
                                    @florentBonjour Florent,

                                    Merci d'ouvrir ton propre sujet pour obtenir une aide complète et personnalisée.
                                2. Contributeur sécurité
                                  Très bien, ton ordinateur n'est plus infecté !

                                  Avant de retourner surfer sur internet, il y a quelques petites choses que tu dois faire pour finir le nettoyage et améliorer sensiblement la sécurité de ton ordinateur, ça t'évitera peut-être de devoir revenir ici avec une nouvelle infection dans le futur ;) Mais sache qu'aucun logiciel de sécurité ne te protègera à 100%, ce qui fait la différence, c'est ta vigilance lorsque tu télécharges ou installes quelque chose : pour en savoir plus, je t'invite à bien lire la page indiquée tout en bas de ce message (6).

                                  1) Sécurise ton ordinateur

                                  - Anti-virus :
                                  Avast était un antivirus convenable il y a quelques années, mais il est dépassé aujourd'hui. Il existe d'autres antivirus gratuits plus efficaces (Antivir ou AVG)
                                  Menu démarrer --> Panneau de configuration --> ajout/suppression de programmes --> désinstalle Avast.
                                  Si ça ne fonctionne pas, consulte ce lien : Désinstallation d'Avast

                                  Si tu choisis Antivir pour le remplacer, tu peux trouver un tutoriel et un lien pour le télécharger ici.
                                  Note : cette version est en anglais, mais une pré-version en français est disponible en français ici

                                  - Pare-feu :
                                  Tu n’as apparemment aucun pare-feu (sauf peut-être celui de Windows, qui est inefficace et ne filtre pas les connections sortantes utilisées par beaucoup d'infections...) : Télécharges-en un vrai. En gratuit, les plus simples sont ZoneAlarm, Kerio et Pc Tools. Tu peux t'aider des tuto suivants pour utiliser celui que tu choisiras :
                                  - Tutoriel PcTools
                                  - Tutoriel Kerio

                                  - Anti-spyware :
                                  * Installe Spyware Blaster : il ne prend pas de mémoire, c'est juste un logiciel qui vaccine ton pc contre certaines infections. Il faut le mettre à jour manuellement, tous les 10 jours environ, et activer toutes les protections (« Enable all protection »)
                                  * Garde Spybot, mets le à jour régulièrement et fais les vaccinations à chaque fois.
                                  * En complément, garde MalwareBytes pour son scan de nettoyage performant.

                                  - Pour naviguer sur internet plus en sécurité et à l’abri des publicités, je te conseille d’installer et d'utiliser le navigateur Firefox 3 avec l’extension « AdBlockPlus ». Tu peux trouver des explications ici

                                  - Il existe des mises à jour de Windows 2000 : tu utilises le Service Pack 2, il existe un SP4. Lance Windows Update et mets à jour ton ordinateur.

                                  - Internet Explorer n'est pas à jour, c'est une faille de sécurité.
                                  Même chose : Menu démarrer --> Windows update --> recherche et installe toutes les mises à jour importantes.

                                  - Adobe Reader n’est pas à jour, c’est une faille de sécurité. Désinstalle le en allant dans menu démarrer --> panneau de configuration --> ajout/suppression de programmes. Puis télécharge et installe la nouvelle version.

                                  2) Relance Hijackthis (pour la dernière fois), fais "scan system only" et coche ces lignes (pas dangereuses mains inutiles) :

                                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
                                  O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe"
                                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
                                  O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe"
                                  O4 - HKCU\..\Run: [internat.exe] internat.exe
                                  O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
                                  O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
                                  O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

                                  Si tu as bien mis à jour Adobe Reader comme je te l'ai recommandé, cette ligne devrait apparaitre, tu peux la cocher : O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

                                  Coche également toutes les lignes commençant par 016

                                  Ensuite, clique sur "Fix checked"

                                  3) Télécharge ToolsCleaner sur ton bureau pour nettoyer l'ordi de tous les outils qu'on a utilisé : ToolsCleaner
                                  Lance le, clique sur Recherche et laisse le scan se finir, puis clique sur Suppression pour nettoyer.
                                  Tu peux aussi supprimer les fichiers temporaires.
                                  Ensuite, supprime manuellement ToolsCleaner (mets le à la corbeille).
                                  S'il ne supprime pas tout (ex : Combofix), supprime manuellement ce qui reste.

                                  4) Télécharge et installe CCleaner (attention à l'installation, pense à DECOCHER l'installation de Yahoo toolbar discrètement proposé en plus de CCleaner).

                                  Lance CCleaner
                                  Option --> avancé --> décoche « effacer uniquement les fichiers plus vieux que 48h »
                                  Puis nettoyeur --> Analyse > Lancer le nettoyage, puis sur OK dans la fenêtre qui s' affiche.
                                  Relance le nettoyage une deuxième fois.

                                  Enfin, registre --> corrige toutes les erreurs, et recommence jusqu'à ce qu'il ne trouve plus d'erreurs.

                                  (Tu peux garder ce logiciel et l'utiliser régulièrement).

                                  5) Je t'invite enfin à visiter cette page qui t'apportera des information de prévention et de protection contre les infections (environ 15 minutes de lecture très instructive et utile):
                                  Prévention et sécurité sur internet

                                  6) Enfin, si tu n as pas d'autres problèmes, tu peux changer le statut du sujet en résolu : Aide

                                  Bonne lecture, bon courage, et n'hésite pas à poser des questions en cas de besoin ;)
                                  • 1
                                  • 2