Win32:agent-lwp

Résolu
Bonjour,

Je suis au prise avec le virus suivant : win32:agent-lwp et je ne suis pas capable de l'effacer. J'ai vu sur le forum qu'il faut utiliser hijackthis, mais je n'ai auncune idee comment utiliser ce programme... Je suis plutot nul en info! Si quelqu'un peut m'aider, cela sera grandement apprecier!!

merci
Configuration: Windows XP
Internet Explorer 7.0

26 réponses

Résumé de la discussion

Désinfection d'un malware Windows, notamment win32:agent-lwp, et l'usage de HijackThis comme outil de diagnostic occupent le cœur des échanges, avec des explications destinées à des utilisateurs non avertis. Plusieurs intervenants proposent des solutions étape par étape, notamment ToolCleaner2, CCleaner, et des méthodes de nettoyage des quarantaines, tout en ajoutant des recommandations de sécurité pour prévenir les infections futures. D'autres conseils évoquent la gestion de la restauration système, des mises à jour logicielles et l'utilisation d'un pare-feu, tout en évoquant l'importance de rapports et de vérifications après chaque étape. En parallèle, des références et ressources complémentaires sont partagées pour assurer une meilleure sécurité, notamment des guides sur les mises à jour, les pare-feu et les analyses post nettoyage.

Bobot (l’IA à votre service)
  1. Ok!!

    A force de fouiller on trouve!! voici mon rapport.

    Logfile of HijackThis v1.99.1
    Scan saved at 12:09:32 AM, on 10/6/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16512)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
    C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
    C:\WINDOWS\LBTWiz.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
    C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
    C:\Program Files\Alwil Software\Avast4\ashChest.exe
    C:\DOCUME~1\fred\LOCALS~1\Temp\Répertoire temporaire 1 pour hijackthis_199[1].zip\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.rds.ca/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.compaq.com/1Q00CDT/040C/bl8.asp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.bing.com/spresults.aspx
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.compaq.com/1Q00CDT/040C/bl7.asp
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [HPLJ Config] C:\Program Files\Hewlett-Packard\hp LaserJet 1150_1300\SetConfig.exe -c Network -p hpLaserJet1150 -pn "hp LaserJet 1150 PCL 5e" -n 0 -l 1036 -sl 120000
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [LBTWiz.exe] C:\WINDOWS\LBTWiz.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20040428/qtinstall.info.apple.com/saba/fr/win/QuickTimeInstaller.exe
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\WINDOWS\system32\HPZipm12.exe (file missing)
    0
    1. Contributeur sécurité
      Bonjour Fred

      Oups...tu as utilisé HijackThis 1.99.1 et tres mal "installé"

      Pour pouvoir utiliser les sauvegardes créées par HijackThis, il faut que le programme HijackThis soit installé dans un dossier qui lui est réservé et non dans un dossier temporaire.Si tu laisses HJT tel qu'il est actuellement, sur le Bureau, pas de sauvegardes (backup) aisément exploitables , donc plus aucune possibilité de faire "marche arrière".

      Je te conseille d'enregistrer la page en sélectionnant toutes les lignes puis de copier cette sélection dans un fichier texte sur ton PC pour pouvoir appliquer la procedure correctement.


      1) Desinstallation de ta version 1.99.1 mal installée


      Lancer hjt "Open misc tools section" avec la fleche a droite descendre jusqu' a "uninstall HijackThis&exit puis supprimer le dossier Hjt qui se trouve dans C:\Documents and settings\fred\Localsettings1\Temp\Répertoire temporaire 1 pour hijackthis_199[1].zip\HijackThis.exe

      Poue cela il te faudra pour cela avoir acces au fichiers cachés :

      Poste de travail/outils/options des dossiers/affichage
      Coche afficher les dossiers cachés,
      Deccoche masquer les extension des fichiers dont le type est connus ainsi que masquer les fichiers protégés du syteme d exploitation
      > Tu vas recevoir un message qui te dit que cela peut endommager le système,
      n'en tiens pas compte. valide par oui
      Refait la manip inverse par la suite pour eviter de faire des betises

      2) HijackThis 2.0.2 de Trend micro

      Telecharge hijackthis

      Installe

      Accepte la license qui va apparaitre par " I agree"

      Puis click sur le raccourci sur ton bureau.
      Puis clique sur "Do a system scan and save a logfile"

      Ferme hijackThis et fait un copier-coller du log entier sauvegarde le sur ton bureau .

      3) Cleanzip


      * Télécharge clean zip de Malekal_Morte http://www.malekal.com/download/clean.zip

      * Décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier clean.
      * Ouvre le dossier Clean qui se trouve sur ton bureau.
      * Double-clique sur clean.cmd.
      Une fenêtre noire va apparaître,

      choisis l'option 1

      4) Rapports

      Poste le rapport qui se trouve ici C:\rapport_clean.txt ainsi que le rapport HijackThis que tu as sauvegardé sur ton bureau.

      @+
      0
      1. Super Detaille!!

        C'est vraiment sympa de ta part, j'espere que j'ai bien fait les rapports!! Je t'envoie tout ca et je vais me coucher, il est tard ici (1:20 am) je viendrai voir de main matin!!

        Encore merci pour tout c'est super.

        Sat 10/06/2007 a 1:18:19.56

        *** Recherche des fichiers dans C:
        C:\StubInstaller.exe FOUND

        *** Recherche des fichiers dans C:\WINDOWS\
        C:\WINDOWS\usnsvc.exe FOUND

        *** Recherche des fichiers dans C:\WINDOWS\system32

        *** Recherche des fichiers dans C:\Program Files
        *** Fin du rapport !

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 1:13:33 AM, on 10/6/2007
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16512)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\LEXBCES.EXE
        C:\WINDOWS\system32\LEXPPS.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\CTsvcCDA.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Canon\CAL\CALMAIN.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\QuickTime\qttask.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
        C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
        C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
        C:\WINDOWS\LBTWiz.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.rds.ca/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.compaq.com/1Q00CDT/040C/bl8.asp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.bing.com/spresults.aspx
        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.compaq.com/1Q00CDT/040C/bl7.asp
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [HPLJ Config] C:\Program Files\Hewlett-Packard\hp LaserJet 1150_1300\SetConfig.exe -c Network -p hpLaserJet1150 -pn "hp LaserJet 1150 PCL 5e" -n 0 -l 1036 -sl 120000
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
        O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [LBTWiz.exe] C:\WINDOWS\LBTWiz.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20040428/qtinstall.info.apple.com/saba/fr/win/QuickTimeInstaller.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
        O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
        O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\WINDOWS\system32\HPZipm12.exe (file missing)
        0
        1. Contributeur sécurité
          Re

          Merci fred ;)

          Canada , Quebec ? car chez nous en France c est pire il est 07h30 , et je suis loin d etre couché lol

          Je te prepare une procedure pour que tu es de quoi faire au reveil ;)

          @+
          0
          1. Contributeur sécurité
            Rebonjour Fred

            Rien de special dans ton log Hijackthis, une cochonnerie dans celui de clean, allez au boulot ;)

            Je te conseille d'enregistrer la page en sélectionnant toutes les lignes puis de copier cette sélection dans un fichier texte sur ton PC pour pouvoir appliquer la procedure correctement.
            (Note: tu n'auras pas accès à Internet à partir du moment ou te redemarrera en mode sans echec)
            Il faut exécuter toutes les étapes, sans interruption, dans l'ordre exact indiqué ci-dessous.
            Si un élément te paraît obscur, demande des explications avant de commencer la désinfection


            1) Telecharge
            -- CCleaner Basic v2.01.507

            https://www.ccleaner.com/ccleaner/download

            Installe puis lance CCleaner puis Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures".
            Par la suite, laisse-le avec ses réglages par défaut.
            Fermer le programme pour l instant.

            --la version d'essai d'AVG Anti-Spyware 7.5 depuis http://www.grisoft.com/doc/downloads-products/ww/crp/0?prd=triasw
            Installe la puis...Lancer AVG Anti-Spyware.
            Cliquer sur le menu Mise à jour.
            Dans le paragraphe Mise à jour manuelle, cliquer sur le bouton Commencer la mise à jour.
            Attendre la fin de cette mise à jour puis fermer le programme.
            Ne pas lancer d'analyse maintenant


            2) Redemarre en mode sans echec


            Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuyer sur la touche [F8] ou [F5] jusqu'à l'affichage du menu des options avancées de Windows.
            Sélectionner "Mode sans échec" et appuyer sur [Entrée]
            Il te faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.

            3) Cleanzip

            * Ouvre le dossier Clean qui se trouve sur ton bureau.
            * Double-clique sur clean.cmd.
            Une fenêtre noire va apparaître,

            choisis l'option 2.

            Poste le rapport qui se trouve ici C:\rapport_clean.txt

            4) Lance HijackThis.

            Ferme toutes les autres fenetres, tous les autres programmes.Pas de connection internet.

            Clique sur Scan et coche les lignes suivantes, Clique sur Fix Checked puis clique sur OK

            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')


            5) Lance AVG Anti-Spyware 7.5

            --Reglages

            Cliquer sur le menu Analyse (de la barre d'outils).
            Cliquer sur l'onglet Paramètres.
            Dans Comment réagir? cliquer sur Actions recommandées et choisir Quarantaine.
            Dans Comment faire l'analyse ? et dans Programmes potentiellement dangereux, vérifier que toutes les cases soient cochées.
            Dans Rapports cocher "générer un rapport aprés chaque analyse"

            -- Scan
            Dans l'onglet Analyse
            Cliquer sur Analyse complète du système.
            Important : Ne pas ouvrir de fenêtre, ne pas lancer de programme pendant l'exécution de AVG Anti-Spyware, car cela pourrait interférer avec le processus de recherche.
            Tres important : A la fin de l'analyse, clique sur " Appliquer toutes les actions"
            Ensuite.
            Cliquer sur "Enregistrer le rapport". Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.
            (C:\Programfiles\AVG Antispyware 7.5\Reports )
            Puis fermer AVG Anti-Spyware.

            6) Lance CCleaner
            Puis dans le menu Nettoyeur
            Cliquer sur Analyse (laisser travailler cela peut durer longtemps la 1ere fois)
            cliquer sur le bouton Lancer le nettoyage.
            Fais cela plusieurs fois d affilé puis ferme CCleaner

            7) Rapports

            Redemarre en mode normal et genere un nouvel HijackThis que tu posteras en reponse ainsi que le rapport d AVG antispyware 7.5

            Bon courage, @+
            ------------------------------------------------------------

            A lire et a méditer ++ car avec Avast, tu n es pas très bien protégé:

            Comparatif avast VS Antivir :

            http://forum.malekal.com/ftopic3528.php

            Si tu te décides a installer Antivir, désinstalle avast d abord et une fois antivir installé paramètre le comme indiqué ici :

            http://speedweb1.free.fr/frames2.php?page=tuto5

            Puis fait les mises a jours de ce celui ci via click droit sur le « parapluie rouge » dans la barre des taches en bas a dt et « start up date ».Laisse finir le processus, redémarre en mode sans échec, puis fait un scan avec Antivir, mets en quarantine tout de qu il trouve et poste le rapport en réponse.

            Voila cela est dit ! :-)
            0
            1. Salut Sioux!!

              Tu es vraiment genial!! Je vais suivre tes procedure a la lettre!! Je devrai par contre le faire en debut de semaine car je quitte pour la ville de Quebec ce matin, et oui je suis du canada et je vie a Montreal, je passe le week-end de l'action de grace avec de la famille

              Je te recontacte plus tard pour te laisser savoir si tout c'est bien passe

              Bonne fin de semaine a toi!!
              0
              1. Contributeur sécurité
                Salut Fred

                Merci de ta gentillesse, bon week end et a bientot , donc.

                @+
                0
                1. Salut Sioux!!

                  Bon!! J'ai suivi tes procedure a la lettre, mais avast detecte tjrs les virus.... Je t'envoi tou de meme les rapport que tu m'as demande. J'espere que j'ai bien faite les procedure!! Je n'ai pas vue dans highjackthis la ligne suivante dans la procedure numero 4 de ta liste : O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') mais maintenant elle sort dans le nouveau rapport...

                  Merci encore une fois de ton aide!!

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 10:28:31 PM, on 10/9/2007
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16512)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\LEXBCES.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\system32\LEXPPS.EXE
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
                  C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
                  C:\WINDOWS\LBTWiz.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  C:\WINDOWS\system32\CTsvcCDA.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Canon\CAL\CALMAIN.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.rds.ca/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.compaq.com/1Q00CDT/040C/bl8.asp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.bing.com/spresults.aspx
                  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.compaq.com/1Q00CDT/040C/bl7.asp
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                  O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                  O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                  O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
                  O4 - HKLM\..\Run: [HPLJ Config] C:\Program Files\Hewlett-Packard\hp LaserJet 1150_1300\SetConfig.exe -c Network -p hpLaserJet1150 -pn "hp LaserJet 1150 PCL 5e" -n 0 -l 1036 -sl 120000
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
                  O4 - HKLM\..\Run: [LBTWiz.exe] C:\WINDOWS\LBTWiz.exe
                  O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')
                  O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                  O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                  O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                  O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20040428/qtinstall.info.apple.com/saba/fr/win/QuickTimeInstaller.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                  O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                  O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\WINDOWS\system32\HPZipm12.exe (file missing)
                  0
                  1. Contributeur sécurité
                    Salut Fred

                    Bien joué ;-)

                    * A propos de mais avast detecte tjrs les virus....

                    ---> ou ? lesquels ? j ai besoin de leurs noms et leur emplacements, va voir dans le visualisateur d evenements d avast via son icone dans la barre des taches stp.

                    * Je regarde ton log HijackThis et te tiens au courant.

                    * Pour ce qu a trouvé AVG 7.5 , des ptites choses dans la restauration que nous "ecraserons" en fin de desinfection seulement et essentiellement des cookies qu il va falloir apprendre a mieux gerer

                    Avec I.E outils/options/ onglet confidentialité/avancés/
                    *Cocher ignorer gestion automatique des cookies
                    *Cocher accepter cookies interne et refuser cookies tierce puis appliquer et ok

                    Avec Firefox outils/options/vie privée
                    *conserver les cookies --> jusqu a la fermeture de Firefox sur PC Astuces">Firefox
                    *dans parametres , cocher cookies
                    *puis cocher "toujours effacer mes informations personnelles a la fermeture de Firefox puis valider par ok
                    Sinon, pour FF, il y a des extensions pour cela (au moins 4 a C) --> https://www.hugedomains.com/domain_profile.cfm?d=geckozone&e=org#C

                    @+
                    0
                    1. Ok!!

                      Je suis entrain d'installer Antivir... Aussitot que j'ai fini je le fait scanner pour savoir ou sont les virus...

                      Je te reviens dans pas trop long!!

                      merci
                      0
                      1. Contributeur sécurité
                        Hello fred,

                        Bonne initiative , je vois que tu as "médité" depuis mon post 5.

                        Ces tests http://forum.malekal.com/ftopic3528.php sont , il est vrai convainquant ++ pour quelqu un de raisonnable.

                        N oublie pas de faire les mises a jours d Antivir avant de lancer le scan en mode sans echec.

                        @+
                        0
                        1. Salut Sioux!!!

                          Je t'accorde que les test de comparaison entre avast et antivir etait tres convaincant!! J'ai fait mes mises a jour de antivir avant de faire mon scan dans le mode sans echec. J'ai aussi fait les correctif au sujet des cookies.

                          Je te fait parvenir le rapport de antivir, dit moi ce que tu en pense!!

                          Cordialement, Fred.

                          AntiVir PersonalEdition Classic
                          Report file date: Tuesday, October 09, 2007 23:59

                          Scanning for 870384 virus strains and unwanted programs.

                          Licensed to: Avira AntiVir PersonalEdition Classic
                          Serial number: 0000149996-ADJIE-0001
                          Platform: Windows XP
                          Windows version: (Service Pack 2) [5.1.2600]
                          Username: fred
                          Computer name: ENTREPOTPC

                          Version information:
                          BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                          AVSCAN.EXE : 7.0.6.1 290856 Bytes 10/10/2007 04:32:46
                          AVSCAN.DLL : 7.0.6.0 49192 Bytes 10/10/2007 04:32:46
                          LUKE.DLL : 7.0.5.3 147496 Bytes 10/10/2007 04:32:46
                          LUKERES.DLL : 7.0.6.1 10280 Bytes 10/10/2007 04:32:46
                          ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 04:32:53
                          ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 04:32:54
                          ANTIVIR2.VDF : 7.0.0.57 446464 Bytes 07/10/2007 04:32:54
                          ANTIVIR3.VDF : 7.0.0.68 38912 Bytes 09/10/2007 04:32:54
                          AVEWIN32.DLL : 7.6.0.20 2753024 Bytes 10/10/2007 04:32:56
                          AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 16:36:26
                          AVPREF.DLL : 7.0.2.2 25640 Bytes 10/10/2007 04:32:46
                          AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 19:16:24
                          AVPACK32.DLL : 7.3.0.15 360488 Bytes 10/10/2007 04:32:56
                          AVREG.DLL : 7.0.1.6 30760 Bytes 10/10/2007 04:32:46
                          AVARKT.DLL : 1.0.0.20 278568 Bytes 10/10/2007 04:32:45
                          AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 10/10/2007 04:32:45
                          NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 17:09:42
                          RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 10/10/2007 04:32:25
                          RCTEXT.DLL : 7.0.62.0 86056 Bytes 10/10/2007 04:32:25
                          SQLITE3.DLL : 3.3.17.1 339968 Bytes 10/10/2007 04:32:47

                          Configuration settings for the scan:
                          Jobname..........................: Local Drives
                          Configuration file...............: c:\program files\antivir personaledition classic\alldrives.avp
                          Logging..........................: low
                          Primary action...................: interactive
                          Secondary action.................: ignore
                          Scan master boot sector..........: off
                          Scan boot sector.................: on
                          Boot sectors.....................: D:,
                          Scan memory......................: on
                          Process scan.....................: on
                          Scan registry....................: on
                          Search for rootkits..............: off
                          Scan all files...................: All files
                          Scan archives....................: on
                          Recursion depth..................: 20
                          Smart extensions.................: on
                          Deviating archive types..........: +BSD Mailbox, +Netscape/Mozilla Mailbox, +Eudora Mailbox, +Squid cache, +Pegasus Mailbox, +MS Outlook Mailbox,
                          Macro heuristic..................: on
                          File heuristic...................: high

                          Start of the scan: Tuesday, October 09, 2007 23:59

                          The scan of running processes will be started
                          Scan process 'avscan.exe' - '1' Module(s) have been scanned
                          Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                          Scan process 'explorer.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'guard.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'lsass.exe' - '1' Module(s) have been scanned
                          Scan process 'services.exe' - '1' Module(s) have been scanned
                          Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                          Scan process 'csrss.exe' - '1' Module(s) have been scanned
                          Scan process 'smss.exe' - '1' Module(s) have been scanned
                          12 processes with 12 modules were scanned

                          Start scanning boot sectors:
                          Boot sector 'C:\'
                          [NOTE] No virus was found!
                          Boot sector 'A:\'
                          [NOTE] In the drive 'A:\' no data medium is inserted!

                          Starting to scan the registry.
                          C:\WINDOWS\LBTWiz.exe
                          [DETECTION] Contains detection pattern of the worm WORM/SdBot.561152.2
                          [INFO] The file was moved to '47605ca2.qua'!
                          C:\WINDOWS\LBTWiz.exe
                          [DETECTION] Contains detection pattern of the worm WORM/SdBot.561152.2

                          The registry was scanned ( '24' files ).

                          Starting the file scan:

                          Begin scan in 'C:\'
                          C:\pagefile.sys
                          [WARNING] The file could not be opened!
                          C:\Documents and Settings\fred\Mes documents\Ma musique\05 Track 5.wma
                          [DETECTION] Is the Trojan horse TR/Wimad.A.Gen
                          [INFO] The file was moved to '472c5d57.qua'!
                          C:\Documents and Settings\fred\Mes documents\Ma musique\Track 9.wma
                          [DETECTION] Is the Trojan horse TR/Wimad.A.Gen
                          [INFO] The file was moved to '476d5da0.qua'!
                          C:\Program Files\Fichiers communs\Carlson\carlton
                          [DETECTION] Is the Trojan horse TR/Dialer.VUY.1
                          [INFO] The file was moved to '477ec391.qua'!
                          C:\WINDOWS\N039_jpg.zip
                          [0] Archive type: ZIP
                          --> www.N039_jpg-msn.com
                          [DETECTION] Contains detection pattern of the worm WORM/SdBot.566784
                          [INFO] The file was moved to '473fc798.qua'!
                          C:\WINDOWS\Nokia_19_jpg.zip
                          [0] Archive type: ZIP
                          --> www.Nokia_19_jpg-msn.com
                          [DETECTION] Contains detection pattern of the worm WORM/SdBot.561152.2
                          [INFO] The file was moved to '4777c7d8.qua'!
                          C:\WINDOWS\$NtUninstallKB824141$\user32.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB824141$\win32k.sys
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\accwiz.exe
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\crypt32.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\cryptsvc.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\hh.exe
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\hhsetup.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\itss.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\locator.exe
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\magnify.exe
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\migwiz.exe
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\mrxsmb.sys
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\msconv97.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\narrator.exe
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\newdev.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\ntdll.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\ntkrnlpa.exe
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\ntoskrnl.exe
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\ole32.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\osk.exe
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\pchshell.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\raspptp.sys
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\rpcrt4.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\rpcss.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\shell32.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\srrstr.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\srv.sys
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\user32.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\winsrv.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826939$\zipfldr.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826942$\dhcpcsvc.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826942$\ndis.sys
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826942$\ndisuio.sys
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826942$\netshell.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826942$\wzcdlg.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826942$\wzcsapi.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB826942$\wzcsvc.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB828028$\msasn1.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\dao360.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\expsrv.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\msexch40.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\msexcl40.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\msjet40.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\msjetoledb40.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\msjint40.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\msjter40.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\msjtes40.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\msltus40.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\mspbde40.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\msrd2x40.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\msrd3x40.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\msrepl40.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\mstext40.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\mswdat10.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\mswstr10.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\msxbde40.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallKB829558$\vbajet32.dll
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\$NtUninstallQ828026$\wmpcore.dll
                          [WARNING] The file could not be opened!
                          Begin scan in 'A:\'
                          Search path A:\ could not be opened!
                          Le périphérique n'est pas prêt.

                          Begin scan in 'D:\'
                          Search path D:\ could not be opened!
                          Le périphérique n'est pas prêt.

                          End of the scan: Wednesday, October 10, 2007 08:05
                          Used time: 8:05:26 min

                          The scan has been done completely.

                          2914 Scanning directories
                          273583 Files were scanned
                          6 viruses and/or unwanted programs were found
                          0 Files were classified as suspicious:
                          0 files were deleted
                          0 files were repaired
                          6 files were moved to quarantine
                          0 files were renamed
                          61 Files cannot be scanned
                          273577 Files not concerned
                          7268 Archives were scanned
                          61 Warnings
                          0 Notes
                          0
                          1. Contributeur sécurité
                            Bonsoir Fred

                            Je vais regarder cela de plus pret ;-) et te dire par la suite ce que l on fait.

                            Mais n aurais tu pas toi aussi, comme beaucoup, reçu un zip de photos via msn ??

                            @ suivre

                            Edit je ne comprends pas pourquoi il n a pas peu scanner differents $NtUninstall dans C:\WINDOWS\ --> [WARNING] The file could not be opened!
                            0
                            1. Salut!!

                              Effectivement, ma femme ma dit a voir recu un fichier de ce genre, elle a ouvert un fichier ""photo"" mais il n'y avais rien. Je peux pas t'en dire plus puisque je n'utilise JAMAIS msn et ma femme est encore plus perdu que moi avec l'informatique!!!

                              Encore une fois, merci pour ton precieux temps!!

                              A bientot.
                              0
                              1. Contributeur sécurité
                                Resalut Fred

                                Avec plaisir, Fred ;-)

                                Ok.. --> zip msn = ver/virus "msn" on va devoir verifier mais je pense qu Antivir l a eradiqué, Avast n avait lui rien vu encore une fois...
                                (j ai beaucoup aimé Avast, mais c est du passé.. lol )

                                MSNFix.zip de !aur3n7

                                Téléchargez MSNFix.zip (de !aur3n7) sur votre bureau:
                                http://sosvirus.changelog.fr/MSNFix.zip
                                Décompressez-le (clic droit >> Extraire ici) et double cliquer sur le fichier MSNFix.bat.
                                - Exécutez l'option R.
                                -- Si l'infection est détectée, exécutez l'option N.
                                --- Sauvegardez ce rapport puis faites un copier/coller de ce rapport sur le forum ainsi qu un nouvel HijackThis.

                                Note :
                                Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal
                                Sauvegarder et fermer le rapport pour que Windows termine de se lancer normalement.:


                                @ suivre
                                0
                                1. Resalut.

                                  Je vais m'occuper de msn comme tu le demande

                                  A noter que antivir trouve plusieur virus qui sont localiser dans: c:/systeme volume information/_restore

                                  les noms sont : worm/sdbot.561152.2 et tr/dialer.us.1

                                  a tout de suite!
                                  0
                                  1. Contributeur sécurité
                                    Re

                                    Pour ce qui est dans la restauration, on " l ecrasera" en fin de nettoyage, t inquietes pas.

                                    Mais ce que chope Antivir --> quarantine ou delete, no problemo que ce soit dans la resto ou ailleurs.

                                    @ +
                                    0
                                    1. Re bonjour.

                                      J'ai executer l"option R du programme, il a trouver une infection, mais aucune option N n"etait disponible, donc j"ai juste quitter le programme...

                                      Voici Highjackthis:

                                      Merci!

                                      Logfile of Trend Micro HijackThis v2.0.2
                                      Scan saved at 10:32:36 PM, on 10/10/2007
                                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                                      MSIE: Internet Explorer v7.00 (7.00.6000.16544)
                                      Boot mode: Normal

                                      Running processes:
                                      C:\WINDOWS\System32\smss.exe
                                      C:\WINDOWS\system32\winlogon.exe
                                      C:\WINDOWS\system32\services.exe
                                      C:\WINDOWS\system32\lsass.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\WINDOWS\system32\LEXBCES.EXE
                                      C:\WINDOWS\system32\LEXPPS.EXE
                                      C:\WINDOWS\system32\spoolsv.exe
                                      C:\WINDOWS\Explorer.EXE
                                      C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                      C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
                                      C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                      C:\WINDOWS\system32\CTsvcCDA.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\Program Files\Canon\CAL\CALMAIN.exe
                                      C:\WINDOWS\system32\ctfmon.exe
                                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                      C:\Program Files\AntiVir PersonalEdition Classic\avcenter.exe
                                      C:\Program Files\MSN Messenger\msnmsgr.exe
                                      C:\Program Files\Internet Explorer\iexplore.exe
                                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.rds.ca/
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.compaq.com/1Q00CDT/040C/bl8.asp
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.bing.com/spresults.aspx
                                      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.compaq.com/1Q00CDT/040C/bl7.asp
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                                      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                                      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                      O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
                                      O4 - HKLM\..\Run: [HPLJ Config] C:\Program Files\Hewlett-Packard\hp LaserJet 1150_1300\SetConfig.exe -c Network -p hpLaserJet1150 -pn "hp LaserJet 1150 PCL 5e" -n 0 -l 1036 -sl 120000
                                      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                                      O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
                                      O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')
                                      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                                      O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20040428/qtinstall.info.apple.com/saba/fr/win/QuickTimeInstaller.exe
                                      O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                                      O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                                      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                      O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                                      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
                                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                                      O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\WINDOWS\system32\HPZipm12.exe (file missing)
                                      0
                                      1. Contributeur sécurité
                                        re

                                        Pas d option N ni de rapport... aie cela m embete..

                                        Essaie quand meme de voir si tu peux trouver le rapport d MSNFix.

                                        C est peu etre du au fait qu Antivir est fait le menage, vide la quarantaine d Antivir et recommence avec MSNFix

                                        @ +
                                        0
                                        1. Salut Sioux!!

                                          J'ai reussi a faire le scan de msnfix, le voici:

                                          MSNFix 1.543

                                          C:\Documents and Settings\fred\Bureau\MSNFix\MSNFix
                                          Fix exécuté le Thu 10/11/2007 - 20:23:38.48 By fred
                                          mode normal

                                          ************************ Recherche les fichiers présents

                                          Aucun Fichier trouvé

                                          ************************ Recherche les dossiers présents

                                          Aucun dossier trouvé

                                          ************************ Fichiers suspects

                                          /!\ ces fichiers nécessitent un avis expérimenté avant toute intervention

                                          [C:\avgas-setup-7.5.1.43.exe] 717F4FE2F0A759765D8629D9380D2E72
                                          [C:\ccsetup201.exe] F055D43C0628CEFEC638B0445333F6A0

                                          [color=#FF0000][b]==>[/b][/color] SVP merci d'envoyer le fichier [b] C:\DOCUME~1\fred\Bureau\Upload_Me.zip [/b] sur http://upload.changelog.fr

                                          ------------------------------------------------------------------------
                                          Auteur : !aur3n7 Contact: https://www.ionos.fr/
                                          ------------------------------------------------------------------------

                                          --------------------------------------------- END ---------------------------------------------

                                          Par contre, j'ai eu de la misere avec mon ordi, j'ai du l'eteindre et depuis le redemarage antivir n'apparait plus dans ma barre d'outil en bas a droite....

                                          J'attend de tes nouvelles!!

                                          Merci
                                          0
                                          • 1
                                          • 2