Raprort hijackthis

Bonjour à tous .
voila j'ai scanné mon Pc avec Avast et Malwarbytes Anti-malwayres voici mon rapport hijackthis . Je préfere demander un avis experimenté si jamais il y a des lignes à supprimer.
Voila merci d'avance.

Logfile of HijackThis v1.99.1
Scan saved at 17:39:26, on 04/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Cegetel\C-BOX\Wizard\Agent_WiFi.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://french.eazel.com/index.php?rvs=hompag
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
O4 - HKCU\..\Run: [TVAgent WiFi] C:\Program Files\Cegetel\C-BOX\Wizard\Agent_WiFi.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [WINSOS VERIFY] "C:\Program Files\WINSOS\WINSOS.EXE" MINI
O4 - HKCU\..\Run: [Netlog 24] C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Power Manager (PowerManager) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe (file missing)
Configuration: Windows XP
Firefox 2.0.0.13

15 réponses

  1. Contributeur
    salut,

    meme si tu surf avec firefox fais la mise a jour windows pour avoir internet explorer 7.0

    https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70

    puis

    regarde ce tutorial pour mettre ta console java a jour :

    https://www.malekal.com/maintenir-java-adobe-reader-et-le-player-flash-a-jour/

    telecharge autoruns :

    https://www.clubic.com/telecharger-fiche15501-microsoft-autoruns.html

    tu le dézip sur ton bureau dans un dossier lui etant dedié

    puis click sur autoruns.exe

    dams la fenetre du programme click sur l´ongle services

    puis repere :

    Power Manager

    click droit dessus > delete.

    puis

    regarde ceci concernant avast :

    antivir vs avast :

    -> http://forum.malekal.com/ftopic3528.php

    alors je te conseille de le desinstaller et d´installer antivir a la place

    Telecharge et instales l'antivirus Antivir Personal Edition Classic :

    ->https://www.malekal.com/avira-free-security-antivirus-gratuit/

    https://www.avira.com/en/prime

    http://mickael.barroux.free.fr/securite/antivir.php
    http://speedweb1.free.fr/frames2.php?page=tuto5
    <- tutoriel configuration du scanner...

    une fois antivir ouvert click surconfiguration et coche la case "expert mode" puis sur l´onglet scanner dans la fenetre du dessous tu va voir : rootkit search click sur le petit + pour deployer et coche la case a coté de ton disk dur
    puis click sur configuration en haut a droite; dans la nouvelle fenetre a gauche >scanner > coche "scan all files" et en dessous >scanner priority = High
    coche : allow stopping the scanner, comme cela tu peux faire une pause pendant le scan si tu le desir.
    puis sur la droite coche les case suivantes :
    scan boot sectors of selected drives
    scan master boot sectors
    scan memory
    search foe rootkit before scan
    decoche :
    ignore off line files
    toujours a gauche > scan > deploie > heuristique > macrovirus heuristic = coché et en dessous > win32 heuristic la case coché et high detection level

    Je te dis tous ca car j´aimerais que tu performes un scan entier de ta machine a l´aide d´antivir avec les reglages stipulés ci dessus et que tu post le rapport généré ici stp

    ps : fais le scan en mode sans echec :

    Comment redémarrer en mode sans echec?

    Tu redemarre le pc et tapote la touche F8 des le début de l allumage sans t´arrêter.
    Une fenêtre sur fond noir va s’ouvrir, tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
    Une fois sur le bureau si il n y a pas toutes les couleurs et autres c´est normal!
    Ps : si F8 ne marche pas utilise la touche F5.

    -> Tuto : http://forum.telecharger.01net.com/forum/high-tech/SECURITE/Securite/redemarrer-mode-echec-sujet_1526_1.htm

    @+
    1. bonjour et merci g!rly...donc voici le rapport antivir

      ntiVir PersonalEdition Classic
      Report file date: vendredi 4 avril 2008 21:30

      Scanning for 1181183 virus strains and unwanted programs.

      Licensed to: Avira AntiVir PersonalEdition Classic
      Serial number: 0000149996-ADJIE-0001
      Platform: Windows XP
      Windows version: (Service Pack 2) [5.1.2600]
      Username: SYSTEM
      Computer name: GRUP

      Version information:
      BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
      AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 12:16:29
      AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 11:23:51
      LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 14:32:47
      LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 11:35:20
      ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 13:27:15
      ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 19:02:35
      ANTIVIR2.VDF : 7.0.3.85 434176 Bytes 27/03/2008 19:02:35
      ANTIVIR3.VDF : 7.0.3.121 189952 Bytes 04/04/2008 19:02:35
      AVEWIN32.DLL : 7.6.0.81 3424768 Bytes 04/04/2008 19:02:36
      AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
      AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 06:39:17
      AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
      AVPACK32.DLL : 7.6.0.3 360488 Bytes 04/04/2008 19:02:36
      AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 06:17:06
      AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 11:26:33
      AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 06:10:18
      NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
      RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 11:38:13
      RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 11:50:37
      SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 08:37:21

      Configuration settings for the scan:
      Jobname..........................: Complete system scan
      Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
      Logging..........................: low
      Primary action...................: interactive
      Secondary action.................: ignore
      Scan master boot sector..........: off
      Scan boot sector.................: on
      Boot sectors.....................: C:,
      Scan memory......................: on
      Process scan.....................: on
      Scan registry....................: on
      Search for rootkits..............: off
      Scan all files...................: Intelligent file selection
      Scan archives....................: on
      Recursion depth..................: 20
      Smart extensions.................: on
      Macro heuristic..................: on
      File heuristic...................: medium

      Start of the scan: vendredi 4 avril 2008 21:30

      The scan of running processes will be started
      Scan process 'avconfig.exe' - '1' Module(s) have been scanned
      Scan process 'avscan.exe' - '1' Module(s) have been scanned
      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
      Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
      Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
      Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
      Scan process 'FxSvr2.exe' - '1' Module(s) have been scanned
      Scan process 'VeohClient.exe' - '1' Module(s) have been scanned
      Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
      Scan process 'Agent_WiFi.exe' - '1' Module(s) have been scanned
      Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
      Scan process 'PDVDServ.exe' - '1' Module(s) have been scanned
      Scan process 'reader_sl.exe' - '1' Module(s) have been scanned
      Scan process 'avgas.exe' - '1' Module(s) have been scanned
      Scan process 'realsched.exe' - '1' Module(s) have been scanned
      Scan process 'jusched.exe' - '1' Module(s) have been scanned
      Scan process 'LogiTray.exe' - '1' Module(s) have been scanned
      Scan process 'LVCOMSX.EXE' - '1' Module(s) have been scanned
      Scan process 'alg.exe' - '1' Module(s) have been scanned
      Scan process 'WMP54Gv4.exe' - '1' Module(s) have been scanned
      Scan process 'WLService.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'RichVideo.exe' - '1' Module(s) have been scanned
      Scan process 'guard.exe' - '1' Module(s) have been scanned
      Scan process 'sched.exe' - '1' Module(s) have been scanned
      Scan process 'explorer.exe' - '1' Module(s) have been scanned
      Scan process 'avguard.exe' - '1' Module(s) have been scanned
      Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'lsass.exe' - '1' Module(s) have been scanned
      Scan process 'services.exe' - '1' Module(s) have been scanned
      Scan process 'winlogon.exe' - '1' Module(s) have been scanned
      Scan process 'csrss.exe' - '1' Module(s) have been scanned
      Scan process 'smss.exe' - '1' Module(s) have been scanned
      39 processes with 39 modules were scanned

      Start scanning boot sectors:
      Boot sector 'C:\'
      [NOTE] No virus was found!

      Starting to scan the registry.
      The registry was scanned ( '18' files ).

      Starting the file scan:

      Begin scan in 'C:\'
      C:\hiberfil.sys
      [WARNING] The file could not be opened!
      C:\pagefile.sys
      [WARNING] The file could not be opened!
      C:\Documents and Settings\bryan\Local Settings\Temporary Internet Files\Content.IE5\OXABGPIZ\trace[2].htm
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Infected.WebPage.Gen
      [INFO] The file was moved to '4857862b.qua'!
      C:\System Volume Information\_restore{24A6B189-0F77-4883-B50E-BFC7F5E2529C}\RP451\A0103605.com
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
      [INFO] The file was moved to '48279909.qua'!
      C:\System Volume Information\_restore{24A6B189-0F77-4883-B50E-BFC7F5E2529C}\RP451\A0103612.com
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
      [INFO] The file was moved to '4827990a.qua'!
      C:\System Volume Information\_restore{24A6B189-0F77-4883-B50E-BFC7F5E2529C}\RP490\A0109364.exe
      [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
      [INFO] The file was moved to '482799bd.qua'!
      C:\WINDOWS\system32\drivers\sptd.sys
      [WARNING] The file could not be opened!

      End of the scan: vendredi 4 avril 2008 23:27
      Used time: 1:57:34 min

      The scan has been done completely.

      7638 Scanning directories
      339281 Files were scanned
      3 viruses and/or unwanted programs were found
      1 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      4 files were moved to quarantine
      0 files were renamed
      3 Files cannot be scanned
      339278 Files not concerned
      2899 Archives were scanned
      3 Warnings
      0 Notes

      voila ... j'espere que ça pourra t'etre utile
      1. Contributeur
        salut bryan,

        ok pour le scan, il a detecté des trucs...

        post un nouveau rapport hijack this stp

        @+
        1. et voila le nouveau rapport Hijackthis

          Logfile of HijackThis v1.99.1
          Scan saved at 15:37:09, on 06/04/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16608)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
          C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\LVCOMSX.EXE
          C:\Program Files\Logitech\Video\LogiTray.exe
          C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Cegetel\C-BOX\Wizard\Agent_WiFi.exe
          C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
          C:\Program Files\Logitech\Video\FxSvr2.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://french.eazel.com/index.php?rvs=hompag
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
          O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
          O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
          O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
          O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
          O4 - HKCU\..\Run: [TVAgent WiFi] C:\Program Files\Cegetel\C-BOX\Wizard\Agent_WiFi.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
          O4 - HKCU\..\Run: [WINSOS VERIFY] "C:\Program Files\WINSOS\WINSOS.EXE" MINI
          O4 - HKCU\..\Run: [Netlog 24] C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe
          O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
          O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O11 - Options group: [INTERNATIONAL] International*
          O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
          O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
          O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Pacsptisvr.exe
          O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Sptisrv.exe
          O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
          O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe (file missing)
          1. Contributeur
            ok

            a l´aide de hijack this coche et fix les lignes ci dessous :

            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

            comment fixer :

            Tutoriel d´utilisation (video) : (Merci a Balltrap34 pour cette réalisation)

            -> http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

            passe ceci voir :

            Télécharge Clean:

            -> http://www.malekal.com/download/clean.zip

            -> Dézippe tout le contenu dans un dossier que tu auras cré au préalable (sur ton bureau par exemple). Double clic sur clean ou clean.cmd choisie l'option 1.

            Un rapport va s'ouvrir, copie et colle le contenu sur le forum.

            -> pour ceux ou celles qui auraient un doute sur comment deziper un fichier :

            http://www.tutopat.com/viewtopic.php?t=933&sid=34215b238376bfb22ef9e8eca9995914

            @+
            1. re bonjour ... j'ai fixé les lignes que tu m'as indiqué
              j'espere que je me trompe pas de rapport

              C:\WINDOWS\System32\d3d8caps.dat -->06/04/2008 16:33:28
              C:\WINDOWS\System32\CONFIG.NT -->04/04/2008 20:56:31
              C:\WINDOWS\System32\jupdate-1.6.0_05-b13.log -->04/04/2008 20:42:08
              C:\WINDOWS\System32\wpa.dbl -->04/04/2008 17:21:56
              C:\WINDOWS\System32\perfh00C.dat -->30/03/2008 04:54:07
              C:\WINDOWS\System32\perfh009.dat -->30/03/2008 04:54:07
              C:\WINDOWS\System32\perfc00C.dat -->30/03/2008 04:54:07
              C:\WINDOWS\System32\perfc009.dat -->30/03/2008 04:54:07
              C:\WINDOWS\System32\PerfStringBackup.INI -->30/03/2008 04:54:06
              C:\WINDOWS\System32\d3d9caps.dat -->26/03/2008 18:15:12
              C:\WINDOWS\System32\MRT.exe -->05/03/2008 18:30:54
              C:\WINDOWS\System32\javaws.exe -->22/02/2008 02:33:32
              C:\WINDOWS\System32\javacpl.cpl -->22/02/2008 02:33:31
              C:\WINDOWS\System32\javaw.exe -->22/02/2008 01:23:39
              C:\WINDOWS\System32\java.exe -->22/02/2008 01:23:35
              C:\WINDOWS\System32\FNTCACHE.DAT -->07/02/2008 04:16:33
              C:\WINDOWS\System32\pngfilt.dll -->11/01/2008 07:36:55
              C:\WINDOWS\System32\wrap_oal.dll -->23/12/2007 22:36:51
              C:\WINDOWS\System32\OpenAL32.dll -->23/12/2007 22:36:51
              C:\WINDOWS\System32\msxml4r.dll -->23/12/2007 21:22:29
              C:\WINDOWS\System32\pxhpinst.exe -->23/12/2007 21:20:57
              C:\WINDOWS\System32\dxtmsft.dll -->20/12/2007 00:53:23
              C:\WINDOWS\System32\TZLog.log -->12/12/2007 22:29:23
              C:\WINDOWS\System32\mshtml.dll -->08/12/2007 10:38:36
              C:\WINDOWS\System32\wininet.dll -->07/12/2007 04:08:34

              C:\WINDOWS\WindowsUpdate.log -->06/04/2008 16:00:09
              C:\WINDOWS\DirectX.log -->06/04/2008 07:20:53
              C:\WINDOWS\0.log -->05/04/2008 18:02:58
              C:\WINDOWS\wiadebug.log -->05/04/2008 18:02:21
              C:\WINDOWS\wiaservc.log -->05/04/2008 18:02:11
              C:\WINDOWS\bootstat.dat -->05/04/2008 18:01:57
              C:\WINDOWS\wmsetup.log -->05/04/2008 13:40:06
              C:\WINDOWS\KB938127-IE7.log -->05/04/2008 04:08:49
              C:\WINDOWS\SchedLgU.Txt -->04/04/2008 21:27:46
              C:\WINDOWS\ntbtlog.txt -->04/04/2008 21:23:01
              C:\WINDOWS\spupdsvc.log -->04/04/2008 20:34:20
              C:\WINDOWS\ie7_main.log -->04/04/2008 19:42:39
              C:\WINDOWS\tsoc.log -->04/04/2008 19:42:35
              C:\WINDOWS\tabletoc.log -->04/04/2008 19:42:35
              C:\WINDOWS\ocmsn.log -->04/04/2008 19:42:35

              C:\WINDOWS\System32\MRT.exe -->05/03/2008 18:30:54
              C:\WINDOWS\System32\javaws.exe -->22/02/2008 02:33:32
              C:\WINDOWS\System32\javaw.exe -->22/02/2008 01:23:39
              C:\WINDOWS\System32\java.exe -->22/02/2008 01:23:35
              C:\WINDOWS\System32\pxhpinst.exe -->23/12/2007 21:20:57
              C:\WINDOWS\System32\pngfilt.dll -->11/01/2008 07:36:55
              C:\WINDOWS\System32\wrap_oal.dll -->23/12/2007 22:36:51
              C:\WINDOWS\System32\OpenAL32.dll -->23/12/2007 22:36:51
              C:\WINDOWS\System32\msxml4r.dll -->23/12/2007 21:22:29
              C:\WINDOWS\System32\dxtmsft.dll -->20/12/2007 00:53:23
              C:\WINDOWS\System32\mshtml.dll -->08/12/2007 10:38:36
              C:\WINDOWS\System32\wininet.dll -->07/12/2007 04:08:34

              et voila ..
              1. Contributeur
                re,

                bon ca l´a pas fait, pas grave ;-(

                passe cet anti spyware :

                Fais un scan avec cet antispyware :

                Telecharge malwarebytes + tutoriel :

                -> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

                Tu l´instale; le programme va se mettre automatiquement a jour.

                Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

                Click maintenant sur l´onglet recherche et coche la case : "executer un examun complet".

                Puis click sur "rechercher".

                Laisse le scanner le pc...

                Si des elements on ete trouvés > click sur supprimer la selection.

                si il t´es demandé de redemarrer > click sur "yes".

                A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

                Copie et colle le rapport stp.

                @+
                1. Bonjour et voici le rapport

                  Malwarebytes' Anti-Malware 1.10
                  Version de la base de données: 595

                  Type de recherche: Examen complet (C:\|)
                  Eléments examinés: 133527
                  Temps écoulé: 4 hour(s), 17 minute(s), 3 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 0
                  Valeur(s) du Registre infectée(s): 0
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 0

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Valeur(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  bonne journée
                  1. Salut à toi g!rly !!!
                    Et bien beaucoup mieux grace à toi.
                    Un grand merci pour tes conseils et pour le temps que tu m'as consacré.
                    J'ai une autre question .
                    le week end dernier, sur Msn, j'étais avec mon amie qui habite aux USA. En me connectant en cam j'ai eu la surprise de tombé sur la cam d'une autre personne . j'ai arrété puis relancé et la tout c'est passé sans probleme. Mais je me suis demandé si il était possible que je me soye fait piraté mon Msn (ou elle ).
                    Y'a t-il une façon de le savoir ou est ce juste une erreur de connection?
                    Voila si jamais tu as une reponse
                    1. Contributeur
                      salut bryan,

                      cette histoire d´msn me parait suspecte en effet...

                      peut etre etait-ce du au service que nous avons supprimé ?!

                      Power Manager

                      sinon pour plus de sureté tu peux toujours changer ton mot de passe...

                      http://www.commentcamarche.net/faq/sujet 1204 comment changer mon mot de passe sous wlm msn

                      @+