Virus msn

Bonjour,
j'ai le virus msn, j'ai fait msnfix, je m'y connais très peu en informatique et donc je vous envoie le rapport d'erreurs:
MSNFix 1.509

C:\Documents and Settings\Julien\Bureau\MSNFix
Fix exécuté le 19/09/2007 - 17:11:11,85 By Julien
mode normal

************************ Recherche les fichiers présents

... C:\WINDOWS\IMG-1681.zip
... C:\WINDOWS\IMG-4666.zip
... C:\WINDOWS\IMG-7753.zip

************************ MSNCHK ***** /!\ beta test /!\

************************ Recherche les dossiers présents

Aucun dossier trouvé

************************ Suppression des fichiers

.. OK ... C:\WINDOWS\IMG-1681.zip
.. OK ... C:\WINDOWS\IMG-4666.zip
.. OK ... C:\WINDOWS\IMG-7753.zip

************************ Nettoyage du registre

************************ Fichiers suspects

/!\ ces fichiers nécessitent un avis expérimenté avant toute intervention

[C:\WINDOWS\system32\DieuxDuStade.scr] 205D917A3BAC2E27A2D889D698004D27

[color=#FF0000][b]==>[/b][/color] SVP merci d'envoyer le fichier [b] C:\DOCUME~1\Julien\Bureau\Upload_Me.zip [/b] sur http://upload.changelog.fr

Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 19092007_17140810.zip

------------------------------------------------------------------------
Auteur : !aur3n7 Contact: https://www.ionos.fr/
------------------------------------------------------------------------

--------------------------------------------- END ---------------------------------------------

En vous remerciant d'avance de votre aide...
Configuration: Windows XP
Firefox 2.0.0.7

18 réponses

  1. Webmaster
    essaye ceci :
    virus msn album photo zip
    0
    1. Contributeur sécurité
      Bonjour,

      en particulier, supprime tout ce que tu as concernant MSNFix et recommence.

      Tu as utilisé la version 509. Il existe au moins la 520.

      Bonne suite.
      0
      1. Ces dernières versions on les trouve où svp?Merci bcp.
        0
        1. Contributeur sécurité
          Re,

          tu cliques sur le lien donné par Jeff,

          tu as une ligne "téléchargez MSNFix" et un lien en dessous.

          Tu cliques sur ce lien, tu vas avoir la dernière version automatiquement.

          @+
          0
          1. Voili, voilou:
            MSNFix 1.509

            C:\Documents and Settings\Julien\Bureau\MSNFix
            Fix exécuté le 27/09/2007 - 19:12:17,62 By Julien
            mode normal

            ************************ Recherche les fichiers présents

            ... C:\WINDOWS\IMG-1194.zip

            ************************ MSNCHK ***** /!\ beta test /!\

            ************************ Recherche les dossiers présents

            Aucun dossier trouvé

            ************************ Suppression des fichiers

            .. OK ... C:\WINDOWS\IMG-1194.zip

            ************************ Nettoyage du registre

            ************************ Fichiers suspects

            /!\ ces fichiers nécessitent un avis expérimenté avant toute intervention

            [C:\WINDOWS\system32\DieuxDuStade.scr] 205D917A3BAC2E27A2D889D698004D27
            [C:\WINDOWS\system32\DieuxDuStade.scr] 205D917A3BAC2E27A2D889D698004D27

            [color=#FF0000][b]==>[/b][/color] SVP merci d'envoyer le fichier [b] C:\DOCUME~1\Julien\Bureau\Upload_Me.zip [/b] sur http://upload.changelog.fr

            Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 27092007_19273812.zip

            ------------------------------------------------------------------------
            Auteur : !aur3n7 Contact: https://www.ionos.fr/
            ------------------------------------------------------------------------

            --------------------------------------------- END ---------------------------------------------
            0
            1. Contributeur sécurité
              Re,

              NON, je viens de le faire sur mon ordi, j'ai la 521, pas la 509.

              Le lien :

              Télécharge MSNFix.zip (de !aur3n7) sur ton bureau:
              http://sosvirus.changelog.fr/MSNFix.zip

              Décompresse-le (clic droit >> Extraire ici) et place les fichiers dans C:\MSNFix (très important).

              Double cliquer sur le fichier MSNFix.bat.
              - Exécutez l'option R.
              -- Si l'infection est détectée, un message l'indiquera et il suffira de presser une touche pour lancer le nettoyage

              Note :
              Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal

              - Le rapport sera enregistré dans le même dossier que MSNFix sous forme date_heure.txt

              @+
              0
              1. Bonjour,
                voila un nouvel essai :

                MSNFix 1.530

                C:\MSNFix\MSNFix
                Fix exécuté le 30/09/2007 - 21:17:54,84 By Julien
                mode normal

                ************************ Recherche les fichiers présents

                ... C:\WINDOWS\cookies.ini
                ... C:\WINDOWS\system\explorer.exe
                ... C:\WINDOWS\IMG-0724.zip
                ... C:\WINDOWS\IMG-2481.zip
                ... C:\WINDOWS\IMG-2686.zip
                ... C:\WINDOWS\IMG-4038.zip
                ... C:\WINDOWS\IMG-5511.zip
                ... C:\WINDOWS\IMG-6217.zip

                ************************ MSNCHK ***** /!\ beta test /!\

                ************************ Recherche les dossiers présents

                Aucun dossier trouvé

                ************************ Suppression des fichiers

                .. OK ... C:\WINDOWS\cookies.ini
                /!\ ... C:\WINDOWS\system\explorer.exe
                .. OK ... C:\WINDOWS\IMG-0724.zip
                .. OK ... C:\WINDOWS\IMG-2481.zip
                .. OK ... C:\WINDOWS\IMG-2686.zip
                .. OK ... C:\WINDOWS\IMG-4038.zip
                .. OK ... C:\WINDOWS\IMG-5511.zip
                .. OK ... C:\WINDOWS\IMG-6217.zip

                ************************ Nettoyage du registre

                Les fichiers encore présents seront supprimés au prochain redémarrage

                ************************ Suppression des fichiers

                .. OK ... C:\WINDOWS\system\explorer.exe

                ************************ Fichiers suspects

                /!\ ces fichiers nécessitent un avis expérimenté avant toute intervention

                [C:\WINDOWS\system32\QTJava.zip] F6FB16B48A4DB0CCF6401A39DD8A5BF9
                [C:\FLIPART.EXE] 6314C248995C2FA500112020B7F625DD
                [C:\GETDRIVE.EXE] EB8A9B9FADCBA69C49DD45489B660E04

                [color=#FF0000][b]==>[/b][/color] SVP merci d'envoyer le fichier [b] C:\DOCUME~1\Julien\Bureau\Upload_Me.zip [/b] sur http://upload.changelog.fr

                Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 30092007_21273387.zip

                ------------------------------------------------------------------------
                Auteur : !aur3n7 Contact: https://www.ionos.fr/
                ------------------------------------------------------------------------

                --------------------------------------------- END ---------------------------------------------

                MERCI !!!
                0
                1. - encore un autre pour la route.....
                  MSNFix 1.530

                  C:\MSNFix\MSNFix
                  Fix exécuté le 30/09/2007 - 21:34:58,62 By Julien
                  mode normal

                  ************************ Recherche les fichiers présents

                  Aucun Fichier trouvé

                  ************************ Recherche les dossiers présents

                  Aucun dossier trouvé

                  ************************ Fichiers suspects

                  /!\ ces fichiers nécessitent un avis expérimenté avant toute intervention

                  [C:\WINDOWS\system32\QTJava.zip] F6FB16B48A4DB0CCF6401A39DD8A5BF9
                  [C:\FLIPART.EXE] 6314C248995C2FA500112020B7F625DD
                  [C:\GETDRIVE.EXE] EB8A9B9FADCBA69C49DD45489B660E04

                  [color=#FF0000][b]==>[/b][/color] SVP merci d'envoyer le fichier [b] C:\DOCUME~1\Julien\Bureau\Upload_Me.zip [/b] sur http://upload.changelog.fr

                  ------------------------------------------------------------------------
                  Auteur : !aur3n7 Contact: https://www.ionos.fr/
                  ------------------------------------------------------------------------

                  --------------------------------------------- END ---------------------------------------------
                  0
                  1. Contributeur sécurité
                    Bonsoir,

                    Clique sur ce lien

                    http://upload.changelog.fr/

                    clique sur parcourir et cherche C:\DOCUME~1\Julien\Bureau\Upload_Me.zip (DOCUME = documents and setting)

                    Ensuite,

                    Clique sur ce lien
                    http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
                    pour télécharger le fichier d'installation d'HijackThis.

                    Enregistre HJTInstall.exe sur ton bureau.

                    Double-clique sur HJTInstall.exe pour lancer le programme

                    Par défaut, il s'installera là :
                    C:\Program Files\Trend Micro\HijackThis

                    Accepte la license en cliquant sur le bouton "I Accept"

                    Choisis l'option "Do a system scan and save a log file"

                    Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note

                    Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

                    Colle le rapport que tu viens de copier sur ce forum

                    Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement

                    Tutoriaux : http://pageperso.aol.fr/balltrap34/demohijack.htm (ne fixe rien pour le moment !!)
                    http://cybersecurite.xooit.com/t138-HijackThis-2-0-2.htm

                    @+
                    0
                    1. Bonsoir,
                      voila ce que ça donne:

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 23:12:33, on 30/09/2007
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                      C:\WINDOWS\system32\slserv.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\WINDOWS\SOUNDMAN.EXE
                      C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                      C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
                      C:\Program Files\Packard Bell EverSafe\TrayControl.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                      C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
                      C:\Program Files\Winamp\winampa.exe
                      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\APPS\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
                      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
                      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
                      C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
                      C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
                      C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                      C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
                      C:\Program Files\Microsoft Works\WkDStore.exe
                      C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
                      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                      O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                      O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                      O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                      O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
                      O4 - HKLM\..\Run: [NovaNet-WEB Tray Control] C:\Program Files\Packard Bell EverSafe\TrayControl.exe
                      O4 - HKLM\..\Run: [CleanEasyImg] c:\apps\easydvd\cleanall.exe
                      O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                      O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
                      O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
                      O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                      O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\uyewdbpl.dll",sitypnow
                      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                      O4 - Global Startup: Contrôleur de calendrier Ulead.lnk = C:\APPS\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
                      O4 - Global Startup: hp psc 1000 series.lnk = ?
                      O4 - Global Startup: hpoddt01.exe.lnk = ?
                      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                      O4 - Global Startup: Packard Bell EverSafe Tray Control.lnk = C:\Program Files\Packard Bell EverSafe\TrayControl.exe
                      O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
                      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                      O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?7e8acba26b6d44d583a32d3d59958217
                      O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?7e8acba26b6d44d583a32d3d59958217
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                      O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://julienbabillotjb.spaces.live.com/PhotoUpload/MsnPUpld.cab
                      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                      O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
                      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                      O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                      O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                      0
                      1. Re-bonsoir,
                        j'ai refait un scan HijackThis après un scan avast:

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 23:51:37, on 30/09/2007
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                        C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                        C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                        C:\WINDOWS\system32\slserv.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\WINDOWS\SOUNDMAN.EXE
                        C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                        C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
                        C:\Program Files\Packard Bell EverSafe\TrayControl.exe
                        C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                        C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
                        C:\Program Files\Winamp\winampa.exe
                        C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        C:\APPS\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
                        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
                        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
                        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
                        C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
                        C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
                        C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                        O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                        O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                        O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                        O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
                        O4 - HKLM\..\Run: [NovaNet-WEB Tray Control] C:\Program Files\Packard Bell EverSafe\TrayControl.exe
                        O4 - HKLM\..\Run: [CleanEasyImg] c:\apps\easydvd\cleanall.exe
                        O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                        O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
                        O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
                        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                        O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\uyewdbpl.dll",sitypnow
                        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                        O4 - Global Startup: Contrôleur de calendrier Ulead.lnk = C:\APPS\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
                        O4 - Global Startup: hp psc 1000 series.lnk = ?
                        O4 - Global Startup: hpoddt01.exe.lnk = ?
                        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                        O4 - Global Startup: Packard Bell EverSafe Tray Control.lnk = C:\Program Files\Packard Bell EverSafe\TrayControl.exe
                        O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
                        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                        O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?7e8acba26b6d44d583a32d3d59958217
                        O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?7e8acba26b6d44d583a32d3d59958217
                        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                        O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://julienbabillotjb.spaces.live.com/PhotoUpload/MsnPUpld.cab
                        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                        O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                        O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
                        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                        O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                        O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                        O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                        0
                        1. Contributeur sécurité
                          Bonjour,

                          1) une référence inconnue. Fais ça :

                          Rends toi sur ce site :

                          https://www.virustotal.com/gui/

                          Clique sur parcourir et cherche ce fichier : C:\WINDOWS\system32\uyewdbpl.dll
                          Clique sur Send File.

                          Un rapport va s'élaborer ligne à ligne.

                          Attends la fin. Il doit comprendre la taille du fichier envoyé.

                          Sauvegarde le rapport avec le bloc-note.

                          Copie le dans ta réponse.

                          (Si tu ne le trouves pas, fais ça :

                          ========================================
                          ->Affiche tous les fichiers et dossiers :
                          clique sur démarrer/panneau de configuration (en affichage classique)/option des dossiers/affichage

                          [Coche] « afficher les dossiers et fichiers cachés »

                          [Décoche] la case « Masquer les fichiers protégés du système d'exploitation (recommandé) »

                          [Décoche] « masquer les extensions dont le type est connu »

                          Puis fais [appliquer] pour valider les changements.

                          Et [Ok]

                          Tu recocheras la case « Masquer les fichiers protégés du système d'exploitation (recommandé) » après l'envoi
                          ==========================================

                          2) Relance HijackThis cliques sur « scanner seulement » ou (« do a scan only »),
                          coche les cases devant ces lignes :

                          O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\uyewdbpl.dll",sitypnow

                          et ensuite ferme toutes les fenêtres actives autres que HijackThis!, navigateur inclus,
                          puis clique "Fix checked"( ou « fixer objet »). Ferme HijackThis!

                          3) Tu utilises toujours les services de Windows Live Photo Upload Control ?

                          @+

                          0
                          1. Bonjour,
                            désolé pour le temps de réponse... voila ce que ça donne:
                            1- voici le rapport:
                            Fichier uyewdbpl.dll reçu le 2007.10.11 11:36:15 (CET)
                            Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE
                            Résultat: 7/32 (21.88%)
                            en train de charger les informations du serveur...
                            Votre fichier est dans la file d'attente, en position: 3.
                            L'heure estimée de démarrage est entre 48 et 68 secondes.
                            Ne fermez pas la fenêtre avant la fin de l'analyse.
                            L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
                            Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
                            Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
                            les résultats seront affichés au fur et à mesure de leur génération.
                            Formaté Formaté
                            Impression des résultats Impression des résultats
                            Votre fichier a expiré ou n'existe pas.
                            Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

                            Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
                            Email:

                            Antivirus Version Dernière mise à jour Résultat
                            AhnLab-V3 2007.10.11.2 2007.10.11 -
                            AntiVir 7.6.0.20 2007.10.11 TR/Dldr.ConHook.Gen
                            Authentium 4.93.8 2007.10.09 -
                            Avast 4.7.1051.0 2007.10.10 -
                            AVG 7.5.0.488 2007.10.10 Lop
                            BitDefender 7.2 2007.10.11 -
                            CAT-QuickHeal 9.00 2007.10.10 -
                            ClamAV 0.91.2 2007.10.11 -
                            DrWeb 4.44.0.09170 2007.10.11 -
                            eSafe 7.0.15.0 2007.10.10 -
                            eTrust-Vet 31.2.5203 2007.10.11 -
                            Ewido 4.0 2007.10.10 -
                            FileAdvisor 1 2007.10.11 -
                            Fortinet 3.11.0.0 2007.10.11 -
                            F-Prot 4.3.2.48 2007.10.10 -
                            F-Secure 6.70.13030.0 2007.10.11 -
                            Ikarus T3.1.1.12 2007.10.11 -
                            Kaspersky 7.0.0.125 2007.10.11 -
                            McAfee 5138 2007.10.10 -
                            Microsoft 1.2908 2007.10.11 -
                            NOD32v2 2586 2007.10.11 -
                            Norman 5.80.02 2007.10.10 W32/Virtumonde.IAW
                            Panda 9.0.0.4 2007.10.10 Suspicious file
                            Prevx1 V2 2007.10.11 Trojan.Vundo
                            Rising 19.44.32.00 2007.10.11 -
                            Sophos 4.22.0 2007.10.11 Virtumundo
                            Sunbelt 2.2.907.0 2007.10.11 -
                            Symantec 10 2007.10.11 -
                            TheHacker 6.2.8.085 2007.10.11 -
                            VBA32 3.12.2.4 2007.10.10 -
                            VirusBuster 4.3.26:9 2007.10.10 -
                            Webwasher-Gateway 6.0.1 2007.10.11 Trojan.Dldr.ConHook.Gen
                            Information additionnelle
                            File size: 85056 bytes
                            MD5: 0d4b78a4c914c58d53815963f14fdb67
                            SHA1: 32483e4eed5934dacf49b75757aad92ae132edac
                            Prevx info: http://fileinfo.prevx.com/fileinfo.asp?PX5=60467F6F40E9F9374CBD01DFA9DB6A00FBCB0655

                            2- j'ai fais ce que tu m'as dit

                            3- a quoi correspondent "les service"s de Windows Live Photo Upload Control" ?

                            Je peux redémarrer msn ?
                            merci !
                            0
                            1. Contributeur sécurité
                              Bonjour,

                              supprime ta version actuelle de MSNFix.

                              Télécharge MSNFix.zip (de !aur3n7) sur ton bureau:
                              http://sosvirus.changelog.fr/MSNFix.zip

                              Décompresse-le (clic droit >> Extraire ici) et place les fichiers dans C:\MSNFix (très important).

                              Double cliquer sur le fichier MSNFix.bat.
                              - Exécutez l'option R.
                              -- Si l'infection est détectée, un message l'indiquera et il suffira de presser une touche pour lancer le nettoyage

                              Note :
                              Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal

                              - Le rapport sera enregistré dans le même dossier que MSNFix sous forme date_heure.txt

                              Tu postes le rapport. S'il n'y a rien, plus de problème avec MSN.

                              Pour Windows Live Photo Upload Control, tu as du utiliser un service d'envoi de photos pour tirage sur le NET. De toute manière, c'est un "contrôle active X". Si on le supprime et que tu en as besoin, on te redemendera de la télécharger.

                              On le supprimera (si tu es d'accord) au prochain tour.

                              Redémarre l'ordi et remets un log Hijackthis. Avec les infos que tu m'as donné, la suppression du fichier n'a pas du se faire correctement.
                              )
                              0
                              1. alors voici le rapport de msn fix - apparemment plus rien:

                                MSNFix 1.543

                                C:\MSNFix\MSNFix
                                Fix exécuté le 12/10/2007 - 11:12:56,00 By Julien
                                mode normal

                                ************************ Recherche les fichiers présents

                                Aucun Fichier trouvé

                                ************************ Recherche les dossiers présents

                                Aucun dossier trouvé

                                ************************ Fichiers suspects

                                /!\ ces fichiers nécessitent un avis expérimenté avant toute intervention

                                [C:\WINDOWS\system32\QTJava.zip] F6FB16B48A4DB0CCF6401A39DD8A5BF9
                                [C:\HijackThis.exe] E8269245566BE948F6A219135B434160

                                [color=#FF0000][b]==>[/b][/color] SVP merci d'envoyer le fichier [b] C:\DOCUME~1\Julien\Bureau\Upload_Me.zip [/b] sur http://upload.changelog.fr

                                ------------------------------------------------------------------------
                                Auteur : !aur3n7 Contact: https://www.ionos.fr/
                                ------------------------------------------------------------------------

                                --------------------------------------------- END ---------------------------------------------

                                et le log de Hijackthis:

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 11:29:34, on 12/10/2007
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                Boot mode: Normal

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                                C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                                C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                                C:\WINDOWS\system32\slserv.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                C:\Program Files\Winamp\winampa.exe
                                C:\WINDOWS\system32\wuauclt.exe
                                C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                C:\APPS\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
                                C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
                                C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
                                C:\Program Files\Packard Bell EverSafe\TrayControl.exe
                                C:\Program Files\Mozilla Firefox\firefox.exe
                                C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
                                C:\WINDOWS\system32\wuauclt.exe
                                C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
                                C:\HijackThis.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
                                R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                                O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                                O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                                O4 - Global Startup: Contrôleur de calendrier Ulead.lnk = C:\APPS\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
                                O4 - Global Startup: hp psc 1000 series.lnk = ?
                                O4 - Global Startup: hpoddt01.exe.lnk = ?
                                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                                O4 - Global Startup: Packard Bell EverSafe Tray Control.lnk = C:\Program Files\Packard Bell EverSafe\TrayControl.exe
                                O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
                                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?7e8acba26b6d44d583a32d3d59958217
                                O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?7e8acba26b6d44d583a32d3d59958217
                                O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                                O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                                O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                                O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                                O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
                                O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                                O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                                O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                                O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                0
                                1. Contributeur sécurité
                                  Re,

                                  il faut que je me réveille.

                                  Télécharge VundoFix.exe (par Atribune) sur ton Bureau.
                                  http://www.atribune.org/ccount/click.php?id=4
                                  Double-clique VundoFix.exe afin de le lancer.

                                  Clique sur le bouton Scan for Vundo.
                                  Lorsque le scan est complété, clique sur le bouton Remove Vundo.
                                  Une invite te demandera si tu veux supprimer les fichiers, clique YES
                                  Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers.
                                  Tu verras une invite qui t'annonce que ton PC va s'éteindre ("shutdown") ; clique OK
                                  Démarre ton PC à nouveau.
                                  Copie/colle le rapport (c:\vundofix.txt) dans ta réponse

                                  Double-clique VundoFix.exe afin de le lancer
                                  NE clique PAS sur le bouton Scan for Vundo
                                  Clique Droit dans la fenêtre blanche, choisis Add more files ?
                                  Rajoute dans la première ligne :

                                  C:\WINDOWS\system32\uyewdbpl.dll

                                  Clique successivement sur :
                                  - Add Files
                                  - Close Windows
                                  - Remove Vundo

                                  Si l'outil te demande de redémarrer, accepte.
                                  Copie/Colle ensuite le rapport C:\vundofix.txt

                                  Télécharge VirtumundoBegone sur le bureau:
                                  http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe

                                  Double clique ensuite sur VirtumundoBeGone.exe et suis les instructions.
                                  Une fois terminé, redémarre et poste le rapport VBG.TXT créé sur le bureau dans ta prochaine réponse avec un nouveau rapport HijackThis.
                                  0
                                  1. alors, voila
                                    le rapport vundo

                                    VundoFix V6.5.10

                                    Checking Java version...

                                    Sun Java not detected
                                    Scan started at 12:42:37 22/10/2007

                                    Listing files found while scanning....

                                    C:\windows\system32\lpbdweyu.ini
                                    C:\WINDOWS\system32\pmnolih.dll
                                    C:\windows\system32\uyewdbpl.dll

                                    Beginning removal...

                                    Attempting to delete C:\windows\system32\lpbdweyu.ini
                                    C:\windows\system32\lpbdweyu.ini Has been deleted!

                                    Attempting to delete C:\WINDOWS\system32\pmnolih.dll
                                    C:\WINDOWS\system32\pmnolih.dll Could not be deleted.

                                    Attempting to delete C:\windows\system32\uyewdbpl.dll
                                    C:\windows\system32\uyewdbpl.dll Has been deleted!

                                    Performing Repairs to the registry.
                                    Done!

                                    VundoFix V6.5.10

                                    Checking Java version...

                                    Sun Java not detected
                                    Scan started at 12:53:54 22/10/2007

                                    Listing files found while scanning....

                                    No infected files were found.

                                    Beginning removal...

                                    Beginning removal...

                                    Performing Repairs to the registry.
                                    Done!

                                    le rapport VBG

                                    [10/22/2007, 19:11:42] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Julien\Bureau\VirtumundoBeGone.exe" )
                                    [10/22/2007, 19:11:45] - Detected System Information:
                                    [10/22/2007, 19:11:45] - Windows Version: 5.1.2600, Service Pack 2
                                    [10/22/2007, 19:11:45] - Current Username: Julien (Admin)
                                    [10/22/2007, 19:11:45] - Windows is in NORMAL mode.
                                    [10/22/2007, 19:11:45] - Searching for Browser Helper Objects:
                                    [10/22/2007, 19:11:45] - BHO 1: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)
                                    [10/22/2007, 19:11:45] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
                                    [10/22/2007, 19:11:45] - BHO 3: {23E483E6-B6D1-4FD3-A5B6-FA76B3F8CAA1} ()
                                    [10/22/2007, 19:11:45] - WARNING: BHO has no default name. Checking for Winlogon reference.
                                    [10/22/2007, 19:11:45] - Checking for HKLM\...\Winlogon\Notify\pmnnl
                                    [10/22/2007, 19:11:45] - Key not found: HKLM\...\Winlogon\Notify\pmnnl, continuing.
                                    [10/22/2007, 19:11:46] - BHO 4: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
                                    [10/22/2007, 19:11:46] - BHO 5: {549B5CA7-4A86-11D7-A4DF-000874180BB3} ()
                                    [10/22/2007, 19:11:46] - WARNING: BHO has no default name. Checking for Winlogon reference.
                                    [10/22/2007, 19:11:46] - No filename found. Continuing.
                                    [10/22/2007, 19:11:46] - BHO 6: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
                                    [10/22/2007, 19:11:46] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
                                    [10/22/2007, 19:11:46] - BHO 8: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
                                    [10/22/2007, 19:11:46] - BHO 9: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (Windows Live Toolbar Helper)
                                    [10/22/2007, 19:11:46] - BHO 10: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} ()
                                    [10/22/2007, 19:11:46] - WARNING: BHO has no default name. Checking for Winlogon reference.
                                    [10/22/2007, 19:11:46] - No filename found. Continuing.
                                    [10/22/2007, 19:11:46] - Finished Searching Browser Helper Objects
                                    [10/22/2007, 19:11:46] - Finishing up...
                                    [10/22/2007, 19:11:46] - Nothing found! Exiting...

                                    et le dernier
                                    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                                    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                                    O4 - Global Startup: Contrôleur de calendrier Ulead.lnk = C:\APPS\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
                                    O4 - Global Startup: hp psc 1000 series.lnk = ?
                                    O4 - Global Startup: hpoddt01.exe.lnk = ?
                                    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                                    O4 - Global Startup: Packard Bell EverSafe Tray Control.lnk = C:\Program Files\Packard Bell EverSafe\TrayControl.exe
                                    O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
                                    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?7e8acba26b6d44d583a32d3d59958217
                                    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?7e8acba26b6d44d583a32d3d59958217
                                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                                    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                                    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                    O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                                    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                                    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
                                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                                    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                                    O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                                    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                    0
                                    1. Contributeur sécurité
                                      Re,

                                      1) désactive le tea-timer de spybot pendant la suite de la désinfection.

                                      2) remets un rapport Hijackthis complet

                                      3) Clique sur ce lien :
                                      http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
                                      pour télécharger navilog1.exe.

                                      Choisis Enregistrer

                                      et enregistre-le sur ton bureau.

                                      Ensuite double clique sur navilog1.exe pour lancer l'installation.
                                      Une fois l'installation terminée, le fix s'exécutera automatiquement.
                                      (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

                                      Laisse-toi guider. Au menu principal, choisis 1 et valides.
                                      (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

                                      Patiente jusqu'au message :
                                      *** Analyse Termine le ..... ***
                                      Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
                                      Copie-colle l'intégralité dans une réponse. Referme le blocnote.
                                      Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
                                      0