Pubs qui s ouvre toute seul

Résolu
Bonjour,
Voila j ai un petit probléme j ai toujours des pages internets qui s ouvre se sont des pubs j aimerai bien voir sa disparaitre si quelqu un peut m aider merci
je vous poste mon rapports HijackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:15:02, on 02/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\ezNTSvc.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\HP_Administrateur\Bureau\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://fr.search.yahoo.com/?fr=cb-hp06
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
O4 - HKLM\..\Run: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus
O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [MsgCenterExe] "C:\Program Files\Fichiers communs\Real\Update_OB\RealOneMessageCenter.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [e8d826b9] rundll32.exe "C:\WINDOWS\system32\upwiwkuv.dll",b
O4 - HKLM\..\Run: [BMebeb1525] Rundll32.exe "C:\WINDOWS\system32\ovmnwkwj.dll",s
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.05\AMVConverter\grab.html
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.05\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://www.securitoo.com/ols/fscax.cab
O20 - AppInit_DLLs: zzagxy.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\WINDOWS\system32\ezNTSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 8309 bytes
Configuration: Windows XP
Internet Explorer 6.0

39 réponses

Résumé de la discussion

Une suspicion d'infection entraîne des pages publicitaires intempestives et nécessite une désinfection du système, notamment en s'appuyant sur des rapports HijackThis pour identifier les éléments indésirables. Plusieurs réponses préconisent une désinfection manuelle avec des outils comme HijackThis et SmitFraudFix, puis l'exécution de corrections ciblées sur les clés de registre et les programmes au démarrage pour neutraliser les mouchards publicitaires. Des échanges évoquent aussi des nettoyages complémentaires avec Ad-Aware, la suppression d'anciennes versions Java, et la suppression de fichiers et raccourcis indésirables repérés par des outils comme Navilog1 ou SmitFraudFix. En parallèle, des conseils portent sur la nécessité de maintenir le système à jour, d'éliminer les programmes auto-démarrés indésirables et d'effectuer des analyses régulières pour éviter une reprise.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Salut !!

    commence par faire ceci stp :

    Option 1 - Recherche :

    ▶ télécharge smitfraudfix et enregistre le sur le bureau

    (c est le numéro 2 en bas de la page) :

    ▶ Ensuite double clique sur smitfraudfix puis exécuter

    ▶ Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.

    (attention : N utilises pas l option 2 si je ne te l ai pas demandé !!)

    ▶ copier/coller le rapport dans la réponse.

    Un tutoriel sonore et animé est à ta disposition sur le site.

    (Attention : "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool".
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains,
    cet utilitaire pourrait arrêter des logiciels de sécurité.)
    -1
    1. bonjour voici mon rapport

      SmitFraudFix v2.356

      Rapport fait à 13:30:04,78, 02/10/2008
      Executé à partir de C:\Documents and Settings\HP_Administrateur\Bureau\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode normal

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\arservice.exe
      C:\WINDOWS\eHome\ehRecvr.exe
      C:\WINDOWS\eHome\ehSched.exe
      C:\WINDOWS\system32\ezNTSvc.exe
      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\WINDOWS\system32\Rundll32.exe
      C:\documents and settings\hp_administrateur\local settings\application data\aeymagq.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Documents and Settings\HP_Administrateur\Bureau\SmitfraudFix\Policies.exe
      C:\WINDOWS\system32\cmd.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Administrateur

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Administrateur\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\HP_ADM~1\Favoris

      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="Ma page d'accueil"

      »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      o4Patch
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      AntiXPVSTFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "LoadAppInit_DLLs"=dword:00000001
      "AppInit_DLLs"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "Userinit"="C:\\WINDOWS\\SYSTEM32\\Userinit.exe,"
      "Windows Shell (ezShellStart)"="C:\\WINDOWS\\system32\\userinit.exe,"
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» RK

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: Realtek RTL8139/810x Family Fast Ethernet NIC - Miniport d'ordonnancement de paquets
      DNS Server Search Order: 16.92.3.242
      DNS Server Search Order: 16.92.3.243
      DNS Server Search Order: 16.81.3.243
      DNS Server Search Order: 16.118.3.243

      Description: Realtek RTL8139/810x Family Fast Ethernet NIC - Miniport d'ordonnancement de paquets
      DNS Server Search Order: 212.27.40.240
      DNS Server Search Order: 212.27.40.241

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
      HKLM\SYSTEM\CCS\Services\Tcpip\..\{C62C7E65-EA76-49AD-9CAC-A4A52A73B5AB}: DhcpNameServer=212.27.40.240 212.27.40.241
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{C62C7E65-EA76-49AD-9CAC-A4A52A73B5AB}: DhcpNameServer=212.27.40.240 212.27.40.241
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{C62C7E65-EA76-49AD-9CAC-A4A52A73B5AB}: DhcpNameServer=212.27.40.240 212.27.40.241
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241

      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

      »»»»»»»»»»»»»»»»»»»»»»»» Fin
      0
      1. Contributeur sécurité
        ok maintenant :

        Option 2 - Nettoyage :

        ▶ Redémarrer l'ordinateur en mode sans échec (tapoter rapidement la touche F8 au démarrage du pc pour obtenir le menu des options avancées).

        ▶ Double cliquer sur smitfraudfix

        ▶ Sélectionner 2 pour supprimer les fichiers responsables de l'infection.

        ▶ A la question Voulez-vous nettoyer le registre ? répondre O (oui) afin de débloquer le fond d'écran et supprimer les clés de démarrage automatique de l'infection.

        Le fix déterminera si le fichier wininet.dll est infecté. A la question Corriger le fichier infecté ? répondre O (oui) pour remplacer le fichier corrompu.

        ▶ Enregistre le rapport sur ton bureau

        ▶ Redémarrer en mode normal et poster le rapport.

        ensuite :

        ▶ Télécharger malwarebytes

        ▶ Voici un tuto pour bien l installer et bien l utiliser :

        https://www.androidworld.fr/

        aide toi bien du tuto pour supprimer correctement ce qu il aura trouvé

        Après l analyse, redémarrer le pc et poste le rapport !!

        Et refais un nouveau rapport hijackthis stp
        -1
        1. un petit soucis quand j allume mon pc en mode sans eches je n ai pas les logiciels nécessaire a cette application suis je obligé de le faire en mode sans échecs ? auparavant j avais eu ce soucis et je n avais pas démarer en mode sans echecs alor que faire ?
          0
          1. Contributeur sécurité
            tu dois absolument le faire en mode sans échec...

            est ce que tu démarres bien en mode sans échec avec la session administrateur ??

            et est ce que c est parce que tu as trop d icones sur ton bureau que tu ne vois pas celui de smitfraudfix ??
            -1
            1. ui ui je démare bien en mode sans échecs sur le session administrateur et ui j ai peut étre bocoup d icone car j en ai pas bocoup d afficher par raport a ce que j ai
              0
              1. Contributeur sécurité
                alors en mode normal, créé des dossiers et glisses le plus possible d icones dans les dossiers pour libérer de la place sur ton bureau...mais évidement ne mets pas smitfraudfix dans un dossier ;-)

                ensuite redémarre en mode sans échec et essayes stp
                -1
                1. voila c est fait je redemérra en mode sans échecs
                  0
                  1. voila c est fait en faite j ai 2 session administrateurs et je prenais la session administrateur a la place de hp administrateur voila pk sa ne marchait pas sinon je fait ce que vous m avait dit de faire voici le rapport

                    SmitFraudFix v2.356

                    Rapport fait à 14:12:27,32, 02/10/2008
                    Executé à partir de C:\Documents and Settings\HP_Administrateur\Bureau\SmitfraudFix
                    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                    Le type du système de fichiers est NTFS
                    Fix executé en mode sans echec

                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                    127.0.0.1 localhost

                    »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                    VACFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                    S!Ri's WS2Fix: LSP not Found.

                    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                    GenericRenosFix by S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                    IEDFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                    404Fix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

                    AntiXPVSTFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» RK

                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{C62C7E65-EA76-49AD-9CAC-A4A52A73B5AB}: DhcpNameServer=212.27.40.240 212.27.40.241
                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{C62C7E65-EA76-49AD-9CAC-A4A52A73B5AB}: DhcpNameServer=212.27.40.240 212.27.40.241
                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{C62C7E65-EA76-49AD-9CAC-A4A52A73B5AB}: DhcpNameServer=212.27.40.240 212.27.40.241
                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
                    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241

                    »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    "System"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                    Nettoyage terminé.

                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Fin
                    0
                    1. Contributeur sécurité
                      ok maintenant fais malwarebytes stp

                      aide toi bien du tuto pour supprimer correctement ce qu il aura trouvé
                      -1
                      1. Contributeur sécurité
                        artimor : c est quoi que pour un site ca ??!!
                        -1
                        1. dsl de l attente mes le logiciel fonctionne encore sa fait un peu peu plus de 40 min qu il inspecte mon pc il a trouvé 82 fichiés infectés je poste le rapport des que finit
                          0
                          1. Contributeur sécurité
                            ok pas de problèmes et laisse le bien finir...

                            et je le répète : aide toi bien de mon tuto pour supprimer correctement ce qu il aura trouvé

                            je le redis parce que la plupart du temps on le fait mal :s
                            -1
                            1. ui pas de probléme le tuto est ouvert la j attend juste qu il finit
                              0
                              1. voila l examen est fini il a trouvé 108 fichié infecté j ai suivi le tuto il me demande de reboot le pc est ce bon ?
                                voila le rapport

                                Malwarebytes' Anti-Malware 1.28
                                Version de la base de données: 1226
                                Windows 5.1.2600 Service Pack 2

                                02/10/2008 15:21:09
                                mbam-log-2008-10-02 (15-21-09).txt

                                Type de recherche: Examen complet (C:\|D:\|)
                                Eléments examinés: 166987
                                Temps écoulé: 49 minute(s), 1 second(s)

                                Processus mémoire infecté(s): 0
                                Module(s) mémoire infecté(s): 3
                                Clé(s) du Registre infectée(s): 20
                                Valeur(s) du Registre infectée(s): 2
                                Elément(s) de données du Registre infecté(s): 2
                                Dossier(s) infecté(s): 2
                                Fichier(s) infecté(s): 77

                                Processus mémoire infecté(s):
                                (Aucun élément nuisible détecté)

                                Module(s) mémoire infecté(s):
                                C:\WINDOWS\system32\tuvWnLeC.dll (Trojan.Vundo.H) -> Delete on reboot.
                                C:\WINDOWS\system32\efcATNHA.dll (Trojan.Vundo.H) -> Delete on reboot.
                                C:\WINDOWS\system32\zzagxy.dll (Trojan.Vundo.H) -> Delete on reboot.

                                Clé(s) du Registre infectée(s):
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{114a72af-007e-461d-89ff-864728c749c5} (Trojan.Vundo.H) -> Delete on reboot.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\efcatnha (Trojan.Vundo.H) -> Delete on reboot.
                                HKEY_CLASSES_ROOT\CLSID\{114a72af-007e-461d-89ff-864728c749c5} (Trojan.Vundo.H) -> Delete on reboot.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{69d483aa-441c-4272-b68d-1b2ba1e8a5a0} (Trojan.Vundo.H) -> Delete on reboot.
                                HKEY_CLASSES_ROOT\CLSID\{69d483aa-441c-4272-b68d-1b2ba1e8a5a0} (Trojan.Vundo.H) -> Delete on reboot.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4443e27-3821-445b-954e-66eea67b113d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                HKEY_CLASSES_ROOT\CLSID\{a4443e27-3821-445b-954e-66eea67b113d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\UpMedia (Adware.SmartShopper) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\MediaHoldings (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\InternetGameBox.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.

                                Valeur(s) du Registre infectée(s):
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{114a72af-007e-461d-89ff-864728c749c5} (Trojan.Vundo.H) -> Delete on reboot.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bmebeb1525 (Trojan.Agent) -> Delete on reboot.

                                Elément(s) de données du Registre infecté(s):
                                HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\tuvwnlec -> Quarantined and deleted successfully.
                                HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\tuvwnlec -> Delete on reboot.

                                Dossier(s) infecté(s):
                                C:\WINDOWS\system32\UpMedia (Adware.SmartShopper) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\wTR02 (Trojan.Agent) -> Quarantined and deleted successfully.

                                Fichier(s) infecté(s):
                                C:\WINDOWS\system32\efcATNHA.dll (Trojan.Vundo.H) -> Delete on reboot.
                                C:\WINDOWS\system32\tuvWnLeC.dll (Trojan.Vundo.H) -> Delete on reboot.
                                C:\WINDOWS\system32\CeLnWvut.ini (Trojan.Vundo.H) -> Delete on reboot.
                                C:\WINDOWS\system32\CeLnWvut.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\zzagxy.dll (Trojan.Vundo.H) -> Delete on reboot.
                                C:\WINDOWS\system32\brmewpsd.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\dspwemrb.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\lqqwohfm.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\mfhowqql.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\ugddgbra.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\arbgddgu.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\upwiwkuv.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\vukwiwpu.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\vtUnkjKc.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\cKjknUtv.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\aeymagq_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                                C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\aeymagq_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                                C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\aeymagq.dat (Adware.Navipromo.H) -> Delete on reboot.
                                C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\aeymagq.exe (Adware.Navipromo.H) -> Delete on reboot.
                                C:\Documents and Settings\HP_Administrateur\Local Settings\Temporary Internet Files\Content.IE5\GP674DEV\nd82m0[1] (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\Documents and Settings\HP_Administrateur\Local Settings\Temporary Internet Files\Content.IE5\I2J8KDL1\upd105320[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\Documents and Settings\HP_Administrateur\Local Settings\Temporary Internet Files\Content.IE5\SXEN456B\upd105320[1] (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\Documents and Settings\HP_Administrateur\Local Settings\Temporary Internet Files\Content.IE5\WPC5EKGS\nd82m0[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP467\A0140752.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP470\A0141904.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP471\A0144938.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP471\A0145958.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP472\A0150126.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\crhouoht.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\dktfmz.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\jtvjwp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\qkyyqubh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\qqswwcex.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\qxyjcndh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\afwpsamo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\ahyydckb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\atmcmq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\bcqiew.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\cbXponND.VIR (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\cgiberjs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\ckzboe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\dgktox.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\eclvcjoy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\ejompvef.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\glokmrrc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\juypvmdk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\kdjlcaql.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\kjmrsn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\lgqrmbpk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\ljJddEVL.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\mesahw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\mtmbtg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\nglubqjf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\nmmicfte.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\pbsxybas.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\pusdlrbm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\rgtame.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\royyyo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\rqemkmrv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\sjewls.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\skklwl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\uehwbddo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\vtUnmNFx.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\sglxlqjo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\wvUnNdAS.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\yaqpmq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\ymbwuf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\xjbzzj.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\xretny.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\Program Files\WinRAR\Default.SFX (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
                                C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\ovmnwkwj.dll (Trojan.Agent) -> Delete on reboot.
                                C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully.
                                C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\BMebeb1525.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
                                C:\WINDOWS\BMebeb1525.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
                                0
                                1. Contributeur sécurité
                                  ok...beau nettoyage :-D

                                  maintenant fais ceci stp :

                                  ▶ Télécharge sur le bureau Navilog1 (c est le numéro 1 en bas de la page)

                                  *Si ton antivirus s'affole , le désactiver
                                  sous vista : Clic-droit sur le raccourci Navilog1 présent sur le bureau et choisis "Exécuter en tant qu'administrateur
                                  sous XP : double-clic dessus pour l'installer et le lancer

                                  ▶ Quand installé
                                  ▶ taper F
                                  ▶ Appuyer sur une touche jusqu' arriver aux options
                                  ▶ Choisir Recherche ( = taper 1 )

                                  ▶ne pas utiliser les autres sans avis , il peut y avoir des processus légitimes

                                  ▶un rapport : fixnavi.txt dans ==> C:

                                  ▶le copier et le coller dans la réponse
                                  -1
                                  1. voici le rapport

                                    Search Navipromo version 3.6.6 commencé le 02/10/2008 à 15:32:23,92

                                    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                                    !!! Postez ce rapport sur le forum pour le faire analyser !!!
                                    !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                                    Outil exécuté depuis C:\Program Files\navilog1
                                    Session actuelle : "HP_Administrateur"

                                    Mise à jour le 29.09.2008 à 17h30 par IL-MAFIOSO

                                    Microsoft Windows XP [version 5.1.2600]
                                    Internet Explorer : 6.0.2900.2180
                                    Système de fichiers : NTFS

                                    Recherche executé en mode normal

                                    *** Recherche Programmes installés ***

                                    InternetGameBox

                                    *** Recherche dossiers dans "C:\WINDOWS" ***

                                    *** Recherche dossiers dans "C:\Program Files" ***

                                    *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

                                    *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

                                    *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                                    *** Recherche dossiers dans "C:\Documents and Settings\HP_Administrateur\applic~1" ***

                                    *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

                                    *** Recherche dossiers dans "C:\Documents and Settings\HP_Administrateur\locals~1\applic~1" ***

                                    *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

                                    *** Recherche dossiers dans "C:\Documents and Settings\HP_Administrateur\menudm~1\progra~1" ***

                                    ...\InternetGameBox trouvé !

                                    *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                                    pour + d'infos : http://www.gmer.net

                                    *** Recherche avec GenericNaviSearch ***
                                    !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                                    !!! A vérifier impérativement avant toute suppression manuelle !!!

                                    * Recherche dans "C:\WINDOWS\system32" *

                                    * Recherche dans "C:\Documents and Settings\HP_Administrateur\locals~1\applic~1" *

                                    * Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

                                    *** Recherche fichiers ***

                                    *** Recherche clés spécifiques dans le Registre ***

                                    HKEY_CURRENT_USER\Software\Lanconfig trouvé !

                                    *** Module de Recherche complémentaire ***
                                    (Recherche fichiers spécifiques)

                                    1)Recherche nouveaux fichiers Instant Access :

                                    2)Recherche Heuristique :

                                    * Dans "C:\WINDOWS\system32" :

                                    * Dans "C:\Documents and Settings\HP_Administrateur\locals~1\applic~1" :

                                    * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :

                                    3)Recherche Certificats :

                                    Certificat Egroup trouvé !
                                    Certificat Electronic-Group trouvé !
                                    Certificat Montorgueil absent !
                                    Certificat OOO-Favorit trouvé !
                                    Certificat Sunny-Day-Design-Ltd absent !

                                    4)Recherche fichiers connus :

                                    C:\WINDOWS\system32\DNnopXbc.ini2 trouvé ! infection Vundo possible non traitée par cet outil !

                                    *** Analyse terminée le 02/10/2008 à 15:42:04,64 ***
                                    0
                                    1. Contributeur sécurité
                                      ok maintenant :

                                      ▶ Relance navilog1

                                      ▶ Choisis cette fois option 2 taper 2

                                      note : le bureau disparaît

                                      ▶redémarrage du pc

                                      ▶ mettre le rapport dans la réponse

                                      ensuite refais un nouveau rapport hijackthis stp
                                      -1
                                      1. voici le rapport navilog je fait un scan hitajiks la

                                        Clean Navipromo version 3.6.6 commencé le 02/10/2008 à 15:48:21,31

                                        Outil exécuté depuis C:\Program Files\navilog1
                                        Session actuelle : "HP_Administrateur"

                                        Mise à jour le 29.09.2008 à 17h30 par IL-MAFIOSO

                                        Microsoft Windows XP [version 5.1.2600]
                                        Internet Explorer : 6.0.2900.2180
                                        Système de fichiers : NTFS

                                        Mode suppression automatique
                                        avec prise en charge résultats Catchme et GNS

                                        Nettoyage exécuté au redémarrage de l'ordinateur

                                        *** fsbl1.txt non trouvé ***
                                        (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                                        *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                                        * Suppression dans "C:\WINDOWS\System32" *

                                        * Suppression dans "C:\Documents and Settings\HP_Administrateur\locals~1\applic~1" *

                                        * Suppression dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

                                        *** Suppression dossiers dans "C:\WINDOWS" ***

                                        *** Suppression dossiers dans "C:\Program Files" ***

                                        *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

                                        *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

                                        *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                                        *** Suppression dossiers dans "C:\Documents and Settings\HP_Administrateur\applic~1" ***

                                        *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

                                        *** Suppression dossiers dans "C:\Documents and Settings\HP_Administrateur\locals~1\applic~1" ***

                                        *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

                                        *** Suppression dossiers dans "C:\Documents and Settings\HP_Administrateur\menudm~1\progra~1" ***

                                        ...\InternetGamebox ...suppression...
                                        ...\InternetGamebox supprimé !

                                        *** Suppression fichiers ***

                                        *** Suppression fichiers temporaires ***

                                        Nettoyage contenu C:\WINDOWS\Temp effectué !
                                        Nettoyage contenu C:\Documents and Settings\HP_Administrateur\locals~1\Temp effectué !

                                        *** Traitement Recherche complémentaire ***
                                        (Recherche fichiers spécifiques)

                                        1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                                        2)Recherche, création sauvegardes et suppression Heuristique :

                                        * Dans "C:\WINDOWS\system32" *

                                        * Dans "C:\Documents and Settings\HP_Administrateur\locals~1\applic~1" *

                                        * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

                                        *** Sauvegarde du Registre vers dossier Safebackup ***

                                        sauvegarde du Registre réalisée avec succès !

                                        *** Nettoyage Registre ***

                                        Nettoyage Registre Ok

                                        *** Certificats ***

                                        Certificat Egroup supprimé !
                                        Certificat Electronic-Group supprimé !
                                        Certificat Montorgueil absent !
                                        Certificat OOO-Favorit supprimé !
                                        Certificat Sunny-Day-Design-Ltdt absent !

                                        *** Nettoyage terminé le 02/10/2008 à 15:52:15,26 ***
                                        0
                                        1. voila l autre rapport

                                          Logfile of Trend Micro HijackThis v2.0.2
                                          Scan saved at 15:53:52, on 02/10/2008
                                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                                          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                          Boot mode: Normal

                                          Running processes:
                                          C:\WINDOWS\System32\smss.exe
                                          C:\WINDOWS\system32\winlogon.exe
                                          C:\WINDOWS\system32\services.exe
                                          C:\WINDOWS\system32\lsass.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\Explorer.EXE
                                          C:\WINDOWS\system32\spoolsv.exe
                                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                          C:\WINDOWS\arservice.exe
                                          C:\WINDOWS\eHome\ehRecvr.exe
                                          C:\WINDOWS\eHome\ehSched.exe
                                          C:\WINDOWS\system32\ezNTSvc.exe
                                          C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                          C:\WINDOWS\system32\nvsvc32.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\system32\dllhost.exe
                                          C:\WINDOWS\system32\wscntfy.exe
                                          C:\WINDOWS\NOTEPAD.EXE
                                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                          C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                          C:\Documents and Settings\HP_Administrateur\Bureau\HiJackThis.exe

                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
                                          O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
                                          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                          O2 - BHO: (no name) - {68B627A7-20FF-46BB-AD7E-171F62B60595} - C:\WINDOWS\system32\cbXponND.dll (file missing)
                                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                          O4 - HKCU\..\Run: [aeymagq] "c:\documents and settings\hp_administrateur\local settings\application data\aeymagq.exe" aeymagq
                                          O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                          O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
                                          O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                                          O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                                          O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                                          O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
                                          O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                          O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                          O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\WINDOWS\system32\ezNTSvc.exe
                                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                          0
                                          • 1
                                          • 2