voici enfin le bon rapport SmitfraudFix... LoOoL :
SDFix: Version 1.107
Run by Administrateur on 03/10/2007 at 00:41
Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\AURLIE~1\Bureau\navilog\SDFix\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Rebooting...
Normal Mode:
Checking Files:
No Trojan Files Found
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files:
---------------
Files with Hidden Attributes:
Fri 20 Aug 2004 1,667,584 ...H. --- "C:\Program Files\Messenger\msmsgs.exe"
Fri 20 Aug 2004 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe"
Thu 31 Mar 2005 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Wed 20 Mar 2002 348,160 A..H. --- "C:\Documents and Settings\All Users\Documents\Jeux PAS TOUCHE\Tony hawk pas touch\Mss32.dll"
Wed 20 Mar 2002 172,032 A..H. --- "C:\Documents and Settings\All Users\Documents\Jeux PAS TOUCHE\Tony hawk pas touch\Platform.dll"
Fri 29 Mar 2002 41,260 A..H. --- "C:\Documents and Settings\All Users\Documents\Jeux PAS TOUCHE\Tony hawk pas touch\RegSetup.exe"
Wed 20 Mar 2002 1,916,928 A..H. --- "C:\Documents and Settings\All Users\Documents\Jeux PAS TOUCHE\Tony hawk pas touch\Skate3.exe"
Wed 20 Mar 2002 233,472 A..H. --- "C:\Documents and Settings\All Users\Documents\Jeux PAS TOUCHE\Tony hawk pas touch\THPS3Setup.exe"
Fri 29 Mar 2002 5,524,585 A..H. --- "C:\Documents and Settings\All Users\Documents\Jeux PAS TOUCHE\Tony hawk pas touch\unpack.exe"
Mon 22 Oct 2001 23,552 A..H. --- "C:\Documents and Settings\All Users\Documents\Jeux PAS TOUCHE\Tony hawk pas touch\Extra\Getinfo.dll"
Wed 12 Sep 2001 131,072 A..H. --- "C:\Documents and Settings\All Users\Documents\Jeux PAS TOUCHE\Tony hawk pas touch\Extra\register.exe"
Mon 22 Oct 2001 84,480 A..H. --- "C:\Documents and Settings\All Users\Documents\Jeux PAS TOUCHE\Tony hawk pas touch\Extra\Sysinfo.exe"
Mon 22 Oct 2001 38,912 A..H. --- "C:\Documents and Settings\All Users\Documents\Jeux PAS TOUCHE\Tony hawk pas touch\Extra\Sysinv.dll"
Fri 28 Sep 2001 164,864 A..H. --- "C:\Documents and Settings\All Users\Documents\Jeux PAS TOUCHE\Tony hawk pas touch\Uninstall\UNWISE.EXE"
Wed 20 Mar 2002 348,160 A..H. --- "C:\Documents and Settings\All Users\Documents\Jeux PAS TOUCHE\Tony hawk pas touch\Data\MILES\Mss32.dll"
Thu 31 Mar 2005 4,348 ...H. --- "C:\Documents and Settings\All Users\Documents\Ma musique\A trier\Artiste inconnu\Sauvegarde de la licence\drmv1key.bak"
Fri 1 Sep 2006 20 A..H. --- "C:\Documents and Settings\All Users\Documents\Ma musique\A trier\Artiste inconnu\Sauvegarde de la licence\drmv1lic.bak"
Fri 25 Aug 2006 488 A.SH. --- "C:\Documents and Settings\All Users\Documents\Ma musique\A trier\Artiste inconnu\Sauvegarde de la licence\drmv2key.bak"
Finished!
Et je finis par un petit Hijackthis:
Logfile of Trend Micro
HijackThis v2.0.2
Scan saved at 01:03:47, on 03/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\Aurélien\Bureau\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
format.packardbell.com...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
www.orange.fr...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
C:APPSIEofflinefr.htm...
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
www.supremetoolbar.com...
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE...
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} -
www.orange.fr... (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\PACSPT~1.EXE
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\RealVNC\WinVNC\winvnc.exe (file missing)
--
End of file - 5535 bytes
Qu'en pense Tu ?
Sinon, je vais pouvoir afficher ma honte, je suisdans une ecole d'ingénieur en electricité et programmation. Mon domaine est plus l'electricité mais j'ai les bases de prog. Et je ne comprends pas comment tu sais quels Fix utiliser et surtout comment lire les rapports d'Hijackthis.... En totu cas chapeau l'artiste !
Aurélien