Rapport hijack this (virus win 32 )

Bonjour,

j ai le virus win 32 attraper sur msn,a l aide!
voila le rapport hijak this?
qui peu m 'aider?
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:52:53, on 13/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Eraser\eraser.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\MLANIE~1\LOCALS~1\Temp\Répertoire temporaire 5 pour HiJackThis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\MLANIE~1\LOCALS~1\Temp\Répertoire temporaire 1 pour catchme.zip\services.exe
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Flash Media] C:\DOCUME~1\MLANIE~1\LOCALS~1\Temp\Répertoire temporaire 1 pour catchme.zip\services.exe
O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://melkenza-sofiane.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://express.foto.com/NewUploader/ImageUploader4.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://melkenza-sofiane.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/...
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

--
End of file - 6474 bytes
Configuration: Windows XP
Internet Explorer 7.0

11 réponses

  1. suit les démarches de ce lien
    http://www.commentcamarche.net/faq/sujet 6781 virus msn album photo zip
    0
    1. voila le rapport de MSN fix

      MSNFix 1.682

      C:\Documents and Settings\M‚lanie\Bureau\MSNFix\MSNFix
      Fix exécuté le 13/03/2008 - 14:04:57,90 By M‚lanie
      mode normal

      ************************ Recherche les fichiers présents

      Aucun Fichier trouvé

      ************************ Recherche les dossiers présents

      Aucun dossier trouvé

      ************************ Fichiers suspects

      Aucun Fichier trouvé

      ************************ HKLM\...\Winlogon\Userinit

      Userinit = C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\MLANIE~1\LOCALS~1\Temp\Répertoire temporaire 1 pour catchme.zip\services.exe

      ------------------------------------------------------------------------
      Auteur : !aur3n7 Contact: https://www.ionos.fr/
      ------------------------------------------------------------------------

      --------------------------------------------- END
      0
      1. et le nouveau rapport hijack this

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 14:09:08, on 13/03/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16608)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\LEXBCES.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\LEXPPS.EXE
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\Eraser\eraser.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Google\Google Updater\GoogleUpdater.exe
        C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\WINDOWS\system32\SPOOL\DRIVERS\W32X86\3\LXBKPSWX.EXE
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\DOCUME~1\MLANIE~1\LOCALS~1\Temp\Répertoire temporaire 6 pour HiJackThis.zip\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\MLANIE~1\LOCALS~1\Temp\Répertoire temporaire 1 pour catchme.zip\services.exe
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
        O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
        O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [Flash Media] C:\DOCUME~1\MLANIE~1\LOCALS~1\Temp\Répertoire temporaire 1 pour catchme.zip\services.exe
        O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
        O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://melkenza-sofiane.spaces.live.com//PhotoUpload/MsnPUpld.cab
        O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://express.foto.com/NewUploader/ImageUploader4.cab
        O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://melkenza-sofiane.spaces.live.com/PhotoUpload/MsnPUpld.cab
        O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/...
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
        O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
        0
        1. maintenant le rapport MSN fix en mode sans echec :

          MSNFix 1.682

          C:\Documents and Settings\M‚lanie\Bureau\MSNFix\MSNFix
          Fix exécuté le 13/03/2008 - 14:15:00,78 By M‚lanie
          mode sans échec

          ************************ Recherche les fichiers présents

          ... C:\WINDOWS\system32\real.txt

          ************************ Recherche les dossiers présents

          Aucun dossier trouvé

          ************************ Suppression des fichiers

          .. OK ... C:\WINDOWS\system32\real.txt

          ************************ Nettoyage du registre

          ************************ Fichiers suspects

          Aucun Fichier trouvé

          Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 13032008_14161860.zip

          ************************ HKLM\...\Winlogon\Userinit

          Userinit = C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\MLANIE~1\LOCALS~1\Temp\Répertoire temporaire 1 pour catchme.zip\services.exe

          ------------------------------------------------------------------------
          Auteur : !aur3n7 Contact: https://www.ionos.fr/
          ------------------------------------------------------------------------

          --------------------------------------------- END ---------------------------------------------
          0
          1. Télécharger sur le bureau
            http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
            = Double-clic SDFix.
            = Clic Install
            ------
            = Redémarrer en mode Sans Échec (le démarrage peut prendre plusieurs minutes)
            Attention, pas d’accès à internet dans ce mode. Enregistrer ou imprimer les consignes. Relancer le Pc et tapoter la touche F8 ( ou F5, 2 ou 4 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
            Avec les touches « flèches », sélectionner Mode sans échec ==> entrée ==>nom utilisateur habituel
            --------
            = Double-clic sur le nouveau dossier SDFix qui est dans C:\
            = Double-clic RunThis
            = Presser Y
            = A l’invitation ==> appuyer sur une touche pour redémarrer
            = Redémarrage ( qui sera plus long ,car nettoyage en cours )
            Continuer si un message d’erreurs apparaît ,dans ce cas aller directement au rapport dans SDfix
            = apparition de Finished
            = Appuyer sur une touche
            = Dans SDFix , un rapport Report.

            et ensuite nettoie avec les logiciels qui te sont donnés sur le lien
            0
        2. voila j ai fait ce que tu m as dit,je te donne donc le rapport de SDfix :

          [b]SDFix: Version 1.156 [/b]

          Run by M‚lanie on 13/03/2008 at 14:52

          Microsoft Windows XP [version 5.1.2600]
          Running From: C:\SDFix

          [b]Checking Services [/b]:

          Restoring Windows Registry Values
          Restoring Windows Default Hosts File

          Rebooting

          [b]Checking Files [/b]:

          Trojan Files Found:

          C:\WINDOWS\system32\drivers\etc\BackupHosts.bak - Deleted
          C:\WINDOWS\system32\real.txt - Deleted

          Removing Temp Files

          [b]ADS Check [/b]:

          [b]Final Check [/b]:

          catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-03-13 14:59:50
          Windows 5.1.2600 Service Pack 2 NTFS

          scanning hidden processes ...

          C:\DOCUME~1\MLANIE~1\LOCALS~1\Temp\Répertoire temporaire 1 pour catchme.zip\services.exe [236] 0x82205818

          scanning hidden services & system hive ...

          scanning hidden registry entries ...

          scanning hidden files ...

          scan completed successfully
          hidden processes: 1
          hidden services: 0
          hidden files: 274

          [b]Remaining Services [/b]:

          Authorized Application Key Export:

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
          "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
          "C:\\WINDOWS\\system32\\LEXPPS.EXE"="C:\\WINDOWS\\system32\\LEXPPS.EXE:*:Disabled:LEXPPS.EXE"
          "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
          "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
          "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
          "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
          "C:\\DOCUME~1\\MLANIE~1\\LOCALS~1\\Temp\\services.exe"="C:\\DOCUME~1\\MLANIE~1\\LOCALS~1\\Temp\\services.exe:*:Enabled:Flash Media"
          "C:\\DOCUME~1\\MLANIE~1\\LOCALS~1\\Temp\\R‚pertoire temporaire 1 pour catchme.zip\\services.exe"="C:\\DOCUME~1\\MLANIE~1\\LOCALS~1\\Temp\\R‚pertoire temporaire 1 pour catchme.zip\\services.exe:*:Enabled:Flash Media"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
          "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
          "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
          "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

          [b]Remaining Files [/b]:

          File Backups: - C:\SDFix\backups\backups.zip

          [b]Files with Hidden Attributes [/b]:

          Wed 10 Dec 2003 193 A.SHR --- "C:\BOOT.BAK"
          Tue 20 Nov 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
          Sun 30 Dec 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
          Fri 7 Mar 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ad213d081e2675ef87a62c73b8abf209\BIT1.tmp"
          Tue 20 Nov 2007 4,348 ...H. --- "C:\Documents and Settings\Propri‚taire\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
          Sun 30 Dec 2007 20 A..H. --- "C:\Documents and Settings\Propri‚taire\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
          Tue 20 Nov 2007 400 ...H. --- "C:\Documents and Settings\Propri‚taire\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"
          Sun 30 Dec 2007 1,536 A..H. --- "C:\Documents and Settings\Propri‚taire\Mes documents\Ma musique\Sauvegarde de la licence\drmv2lic.bak"

          [b]Finished![/b]

          je fais quoi maintenant?
          0
          1. stp répond moi!
            j ai fais un scan avec spybot et il na rien trouver,par contre avast le detect encore....
            qu 'est ce que je fais?
            0
            1. si j ai pas de réponse je vais pas pouvoir continuer sans vous,vous m'etes indispensable!
              a l'aide!
              0
              1. SdFix
                = Double-clic SDFix.
                = Clic Install
                ------
                = Redémarrer en mode Sans Échec (le démarrage peut prendre plusieurs minutes)
                Attention, pas d’accès à internet dans ce mode. Enregistrer ou imprimer les consignes. Relancer le Pc et tapoter la touche F8 ( ou F5, 2 ou 4 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
                Avec les touches « flèches », sélectionner Mode sans échec ==> entrée ==>nom utilisateur habituel
                --------
                = Double-clic sur le nouveau dossier SDFix qui est dans C:\
                = Double-clic RunThis
                = Presser Y
                = A l’invitation ==> appuyer sur une touche pour redémarrer
                = Redémarrage ( qui sera plus long ,car nettoyage en cours )
                Continuer si un message d’erreurs apparaît ,dans ce cas aller directement au rapport dans SDfix
                = apparition de Finished
                = Appuyer sur une touche
                = Dans SDFix , un rapport Report.

                ===================================================================================
                que vous ayez utilisé MSNFIX ou SDFIX
                continuer avec ceci pour un nettoyage complet

                Télécharge
                http://download.piriform.com/ccsetup201.exe
                et installer ==> Sur la page qui offre plusieurs choix , ne laisser cochés que les 2 premiers :
                « ajouter un raccourci sur le bureau » et « ajouter un raccourci dans le menu démarrer »

                -----
                Télécharge :
                http://www.avgfrance.com/doc/31/fr/crp/0?prd=asw
                = Installer
                = Le lancer
                = Clic : Mise à jour et lancer la mise à jour
                ------
                = Redémarrer en mode Sans Échec (le démarrage peut prendre plusieurs minutes)
                Attention, pas d’accès à internet dans ce mode. Enregistrer ou imprimer les consignes.

                Relancer le Pc et tapoter la touche F8 ( ou F5 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
                Avec les touches « flèches », sélectionner Mode sans échec ==> entrée ==>nom utilisateur habituel
                -------
                Lancer Ccleaner ==> Analyse puis lancer le nettoyage
                ------------

                Lancer AVG Antispyware 7.5

                = Dans ANALYSE ( en forme de loupe )
                ==> Paramètres ==> sous COMMENT REAGIR==>clic sur Actions recommandées ==>Quarantaine
                ==> Clic : Analyse complète du système
                En fin de scan ( qui est assez long)
                ==> Clic Appliquer toutes les actions <== ceci Très important
                ==> Clic Sauvegarder rapport puis Enregistrer sous et choisir bureau

                -------
                NOTE : CCleaner est à conserver et à utiliser quotidiennement

                si le mode sans échec pose problème => faire en mode normal

                ========================= ================================

                redémarrer le PC et relancer MSN vous saurez ainsi si tout est supprimé
                0