VIRUS RECU SUR MSN - Page 2

Résolu
  1. Contributeur
    re,

    tu as du remarqué que je butte sur O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\%%%%%.exe

    peux etre une simple cle vu que tu ne trouve pas le fichier et msnfix non plus on va tenté ceci :

    a l´aide de hijack this coche et fix :

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\%%%%%.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)

    comment fixer :

    Tutoriel d´utilisation (video) : (Merci a Balltrap34 pour cette réalisation)

    -> http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

    puis

    regarde ceci concernant avast :

    antivir vs avast :

    -> http://forum.malekal.com/ftopic3528.php

    alors je te conseille de le desinstaller et d´installer antivir a la place

    Telecharge et instales l'antivirus Antivir Personal Edition Classic :

    ->https://www.malekal.com/avira-free-security-antivirus-gratuit/

    https://www.avira.com/en/prime

    http://mickael.barroux.free.fr/securite/antivir.php
    http://speedweb1.free.fr/frames2.php?page=tuto5
    <- tutoriel configuration du scanner...

    une fois antivir ouvert click surconfiguration et coche la case "expert mode" puis sur l´onglet scanner dans la fenetre du dessous tu va voir : rootkit search click sur le petit + pour deployer et coche la case a coté de ton disk dur
    puis click sur configuration en haut a droite; dans la nouvelle fenetre a gauche >scanner > coche "scan all files" et en dessous >scanner priority = High
    coche : allow stopping the scanner, comme cela tu peux faire une pause pendant le scan si tu le desir.
    puis sur la droite coche les case suivantes :
    scan boot sectors of selected drives
    scan master boot sectors
    scan memory
    search foe rootkit before scan
    decoche :
    ignore off line files
    toujours a gauche > scan > deploie > heuristique > macrovirus heuristic = coché et en dessous > win32 heuristic la case coché et high detection level

    Je te dis tous ca car j´aimerais que tu performes un scan entier de ta machine a l´aide d´antivir avec les reglages stipulés ci dessus et que tu post le rapport généré ici stp

    @+
    0
    1. AntiVir PersonalEdition Classic
      Report file date: lundi 7 avril 2008 21:19

      Scanning for 835736 virus strains and unwanted programs.

      Licensed to: Avira AntiVir PersonalEdition Classic
      Serial number: 0000149996-ADJIE-0001
      Platform: Windows XP
      Windows version: (Service Pack 2) [5.1.2600]
      Username: SYSTEM
      Computer name: CHAZÉ

      Version information:
      BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
      AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 12:16:29
      AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 11:23:51
      LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 14:32:47
      LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 11:35:20
      ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 13:27:15
      ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 13:26:55
      ANTIVIR2.VDF : 7.0.0.1 2048 Bytes 13/09/2007 13:27:04
      ANTIVIR3.VDF : 7.0.0.2 2048 Bytes 13/09/2007 13:27:13
      AVEWIN32.DLL : 7.6.0.15 2806272 Bytes 17/09/2007 16:43:56
      AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
      AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 06:39:17
      AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
      AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 07:46:00
      AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 06:17:06
      AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 11:26:33
      AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 06:10:18
      NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
      RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 11:38:13
      RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 11:50:37
      SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 08:37:21

      Configuration settings for the scan:
      Jobname..........................: Complete system scan
      Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
      Logging..........................: low
      Primary action...................: interactive
      Secondary action.................: ignore
      Scan master boot sector..........: on
      Scan boot sector.................: on
      Boot sectors.....................: D:,
      Scan memory......................: on
      Process scan.....................: on
      Scan registry....................: on
      Search for rootkits..............: on
      Scan all files...................: All files
      Scan archives....................: on
      Recursion depth..................: 20
      Smart extensions.................: on
      Macro heuristic..................: on
      File heuristic...................: high

      Start of the scan: lundi 7 avril 2008 21:19

      Starting search for hidden objects.
      '40202' objects were checked, '0' hidden objects were found.

      The scan of running processes will be started
      Scan process 'avscan.exe' - '1' Module(s) have been scanned
      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
      Scan process 'avguard.exe' - '1' Module(s) have been scanned
      Scan process 'sched.exe' - '1' Module(s) have been scanned
      Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
      Scan process 'alg.exe' - '1' Module(s) have been scanned
      Scan process 'iPodService.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'CDAC11BA.EXE' - '1' Module(s) have been scanned
      Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
      Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
      Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
      Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
      Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
      Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
      Scan process 'E_S10IC2.EXE' - '1' Module(s) have been scanned
      Scan process 'mixer.exe' - '1' Module(s) have been scanned
      Scan process 'shwicon2k.exe' - '1' Module(s) have been scanned
      Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
      Scan process 'kbd.exe' - '1' Module(s) have been scanned
      Scan process 'hphmon05.exe' - '1' Module(s) have been scanned
      Scan process 'hpwuSchd.exe' - '1' Module(s) have been scanned
      Scan process 'HpqCmon.exe' - '1' Module(s) have been scanned
      Scan process 'hpsysdrv.exe' - '1' Module(s) have been scanned
      Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
      Scan process 'aawservice.exe' - '1' Module(s) have been scanned
      Scan process 'explorer.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'lsass.exe' - '1' Module(s) have been scanned
      Scan process 'services.exe' - '1' Module(s) have been scanned
      Scan process 'winlogon.exe' - '1' Module(s) have been scanned
      Scan process 'csrss.exe' - '1' Module(s) have been scanned
      Scan process 'smss.exe' - '1' Module(s) have been scanned
      37 processes with 37 modules were scanned

      Starting master boot sector scan:
      Master boot sector HD0
      [NOTE] No virus was found!
      Master boot sector HD1
      [NOTE] No virus was found!
      [WARNING] The boot sector file could not be read!
      [WARNING] Error code: 0x0015
      Master boot sector HD2
      [NOTE] No virus was found!
      [WARNING] The boot sector file could not be read!
      [WARNING] Error code: 0x0015
      Master boot sector HD3
      [NOTE] No virus was found!
      [WARNING] The boot sector file could not be read!
      [WARNING] Error code: 0x0015
      Master boot sector HD4
      [NOTE] No virus was found!
      [WARNING] The boot sector file could not be read!
      [WARNING] Error code: 0x0015

      Start scanning boot sectors:
      Boot sector 'C:\'
      [NOTE] No virus was found!
      Boot sector 'D:\'
      [NOTE] No virus was found!

      Starting to scan the registry.
      The registry was scanned ( '45' files ).

      Starting the file scan:

      Begin scan in 'C:\' <HP_PAVILION>
      C:\hiberfil.sys
      [WARNING] The file could not be opened!
      C:\pagefile.sys
      [WARNING] The file could not be opened!
      C:\QooBox\Quarantine\catchme2008-04-07_190039,14.zip
      [0] Archive type: ZIP
      --> Documents and Settings/Propriétaire/Bureau/catchme.zip
      [1] Archive type: ZIP
      --> %%0e+000xe
      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
      [INFO] The file was moved to '486e7b38.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0002143.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '482a7b0f.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0002144.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '482a7b12.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0007163.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '482a7b17.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0008172.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '482a7b1b.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0009169.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '482a7b1d.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0010167.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '482a7b21.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0011169.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO] The file was moved to '482a7b23.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0011172.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '482a7b26.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0011238.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '482a7b29.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0012238.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '482a7b2c.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0012282.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '482a7b2f.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0012322.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO] The file was moved to '482a7b31.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0012325.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '482a7b33.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0013324.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '482a7b38.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0014323.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '482a7b3b.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0015323.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '482a7b3e.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0015380.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '482a7b40.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP2\A0015613.exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '482a7b4b.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP2\A0015644.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [INFO] The file was moved to '482a7b4e.qua'!
      C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP70\A0023594.exe
      [DETECTION] Is the Trojan horse TR/Trash.Gen
      [INFO] The file was moved to '482a7c28.qua'!
      C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\81MBGTAZ\84785_winsgh[1].exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '48317ea4.qua'!
      C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KX6NG9IB\84785_winsgh[1].exe
      [DETECTION] Contains suspicious code HEUR/Crypted
      [INFO] The file was moved to '48317ea9.qua'!
      Begin scan in 'D:\' <HP_RECOVERY>

      End of the scan: lundi 7 avril 2008 22:12
      Used time: 53:17 min

      The scan has been done completely.

      5142 Scanning directories
      340065 Files were scanned
      2 viruses and/or unwanted programs were found
      21 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      23 files were moved to quarantine
      0 files were renamed
      2 Files cannot be scanned
      340063 Files not concerned
      18327 Archives were scanned
      2 Warnings
      0 Notes
      40202 Objects were scanned with rootkit scan
      0 Hidden objects were found
      0
  2. Contributeur
    ok

    post le rapport hijack this stp

    @+
    0
    1. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 17:07:26, on 08/04/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\windows\system\hpsysdrv.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd.exe
      C:\WINDOWS\System32\hphmon05.exe
      C:\HP\KBD\KBD.EXE
      C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\Multimedia Card Reader\shwicon2k.exe
      C:\WINDOWS\Mixer.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\internet explorer\iexplore.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
      O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
      O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
      O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe"
      O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
      O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
      O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
      O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
      O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
      O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
      O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C64 Series" /O5 "LPT1:" /M "Stylus C64"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\%%%%%.exe
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
      O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [WINSOS VERIFY] "C:\Program Files\Winsos\WINSOS.EXE" MINI
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
      O4 - Global Startup: customize__IE.lnk = C:\hp\region\customizeIe.wsf
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
      O4 - Global Startup: MsnFixer.lnk = ?
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
      0
  3. oula oué !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!ya du menage pr my G!rly et toi ^^

    je suis c' topic car ca fini bien ^^

    bises
    0
    1. Contributeur
      salut mary851,

      fais les mises a jour suivantes :

      tu surf avec internet explorer 6.0 = failles de securitées importantes

      alors fais les mises a jour windows : tu veux la version 7.0

      https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70

      et pourquoi ne pas surfer avec firefox? = plus sur, tout en gardant ie 7.0 pour les mises a jour windows car impossible a effectuer sous firefox

      http://www.mozilla-europe.org/fr/

      plugins : ad block plus, no script ect...

      https://www.hugedomains.com/domain_profile.cfm?d=geckozone&e=org

      ta version de acrobat reader n´est pas a jour, tu veux la version 8.1 derniere en date alors desinstale ta version par le panneau de configuration / ajoue et suppression de programme

      et instale la derniere :

      https://get2.adobe.com/reader/otherversions/

      ou oublie completement acrobat reader et instales foxit plus léger a la place:

      https://www.clubic.com/telecharger-fiche13808-foxit-reader.html

      reviens apres avec un nouveau rapport hijack this stp

      @+
      0
      1. Où en sont les virus??

        Le rapport :
        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 18:49:28, on 08/04/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16608)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        C:\windows\system\hpsysdrv.exe
        C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
        C:\Program Files\HP\HP Software Update\HPWuSchd.exe
        C:\WINDOWS\System32\hphmon05.exe
        C:\HP\KBD\KBD.EXE
        C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\Program Files\Multimedia Card Reader\shwicon2k.exe
        C:\WINDOWS\Mixer.exe
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\WINDOWS\system32\drivers\CDAC11BA.EXE
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
        O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
        O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
        O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe"
        O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
        O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
        O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
        O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
        O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
        O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
        O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C64 Series" /O5 "LPT1:" /M "Stylus C64"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\%%%%%.exe
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
        O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [WINSOS VERIFY] "C:\Program Files\Winsos\WINSOS.EXE" MINI
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
        O4 - Global Startup: customize__IE.lnk = C:\hp\region\customizeIe.wsf
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
        O4 - Global Startup: MsnFixer.lnk = ?
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
        0
      2. Est-ce que le virus est toujours d'actualité??? Je m'inquiète vraiment!!!
        0
    2. Contributeur
      mary851,

      cette cle me rend fou :

      O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\%%%%%.exe

      est ce que tu as customisé internet explorer ?

      @+
      0
      1. ce qui veut dire?
        En tout cas, j'ai installé Internet Explorer que tu m'avais indiqué avant
        0
    3. Contributeur
      ok

      fais ceci :

      -> Redémarre en mode sans échec :

      Comment redémarrer en mode sans echec?

      Tu redemarre le pc et tapote la touche F8 des le début de l allumage sans t´arrêter.
      Une fenêtre sur fond noir va s’ouvrir, tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
      Une fois sur le bureau si il n y a pas toutes les couleurs et autres c´est normal!
      Ps : si F8 ne marche pas utilise la touche F5.

      -> Tuto : http://forum.telecharger.01net.com/forum/high-tech/SECURITE/Securite/redemarrer-mode-echec-sujet_1526_1.htm

      une fois en mode sans echec ouvre hijack this et coche et fix les lignes suivantes :

      O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\%%%%%.exe
      O4 - Global Startup: customize__IE.lnk = C:\hp\region\customizeIe.wsf

      repost un nouveau hijack this stp

      @+
      0
      1. hello my g!rly et si F8 et f5 ne marchait pas tiens!!! on fé quoi loool
        0
      2. Bonjour, ci-joint le rapport demandé :

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 09:13:28, on 09/04/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16608)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        C:\windows\system\hpsysdrv.exe
        C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
        C:\Program Files\HP\HP Software Update\HPWuSchd.exe
        C:\WINDOWS\System32\hphmon05.exe
        C:\HP\KBD\KBD.EXE
        C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\Program Files\Multimedia Card Reader\shwicon2k.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        C:\WINDOWS\Mixer.exe
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\WINDOWS\system32\drivers\CDAC11BA.EXE
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
        C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
        O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
        O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
        O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe"
        O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
        O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
        O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
        O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
        O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
        O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
        O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C64 Series" /O5 "LPT1:" /M "Stylus C64"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
        O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [WINSOS VERIFY] "C:\Program Files\Winsos\WINSOS.EXE" MINI
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
        O4 - Global Startup: MsnFixer.lnk = ?
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
        0
    4. Contributeur
      hi, msconfig my funnygirl`
      0
      1. jtape msconfig ds eecuter et dit alrs f8 et f5 merde que faire? mdr
        0
        1. Contributeur
          ok lol
          tout est expliqué sur lien
          o_Ö
          @´+
          0
          1. merci my best!
            0
        2. Contributeur
          salut mary,

          c´est bon cette fois ci, la cle a disparu ;-)

          maintenant instale un par feu pour plus de securité :

          Comodo 3 pro :

          http://www.commentcamarche.net/telecharger/telecharger 34055041 comodo firewall pro

          tuto : https://www.malekal.com/tutorial-comodo-firewall/

          ou

          Online armor :

          http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall

          tuto : https://www.malekal.com/tutorial-online-armor-free/

          rajoute aussi ceci :

          spywareblaster :

          http://www.brightfort.com/spywareblaster.html

          c´est un resident, il suffit de le mettre a jour de temps en temps car la version gratuite ne le fait pas toute seul , une fois installé et mis a jour tu mets toutes les protections sur "enable"

          tuto : https://www.malekal.com/tutorial-spywareblaster/

          puis fais ceci :

          Désactive ta restauration système:
          pour cela :
          Click droit sur poste de travail, dans l´arborescence sur propriétés;
          dans la nouvelle fenettre click sur l´onglet restauration système;
          coche la case désactiver la restauration systèm et applique.
          puis redemarre le pc et click droit sur poste de travail, dans l´arborescence sur propriétés;
          dans la nouvelle fenettre click sur l´onglet restauration systèm
          décoche la case désactiver la restauration systèm et applique.

          puis

          Télécharge ToolsCleaner sur ton bureau.
          --> http://www.commentcamarche.net/telecharger/telechargement 34055291 toolsclean(...)
          # Clique sur Recherche et laisse le scan agir ...
          # Clique sur Suppression pour finaliser.
          # Tu peux, si tu le souhaites, te servir des Options facultatives.
          # Clique sur Quitter pour obtenir le rapport.
          # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

          dis moi quoi

          @+
          0
          1. oups, j'ai supprimé le rapport!!!

            Y a-t-il toujours le virus msn???
            0
        3. Contributeur
          re,

          le virus msn est partie ;-)

          tu ne devrais plus avoir de soucis maintenant...

          @+
          0
          1. ok merci beaucoup!!
            dernière question : à quoi correspondent les 2 warnings qu'Antivir détecte toujours???
            0
        4. Contributeur
          Dis moi que sont ces warning ?
          @+
          0
          1. Je t'envoie le rapport dès qu'Antivir a terminé!
            0
        5. Contributeur
          ok tres bien

          @+
          0
          1. AntiVir PersonalEdition Classic
            Report file date: mercredi 9 avril 2008 15:52

            Scanning for 1188179 virus strains and unwanted programs.

            Licensed to: Avira AntiVir PersonalEdition Classic
            Serial number: 0000149996-ADJIE-0001
            Platform: Windows XP
            Windows version: (Service Pack 2) [5.1.2600]
            Username: SYSTEM
            Computer name: CHAZÉ

            Version information:
            BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
            AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 12:16:29
            AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 11:23:51
            LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 14:32:47
            LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 11:35:20
            ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 13:27:15
            ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 20:22:48
            ANTIVIR2.VDF : 7.0.3.127 649216 Bytes 07/04/2008 20:22:48
            ANTIVIR3.VDF : 7.0.3.135 57344 Bytes 08/04/2008 19:15:55
            AVEWIN32.DLL : 7.6.0.81 3424768 Bytes 07/04/2008 20:22:50
            AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
            AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 06:39:17
            AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
            AVPACK32.DLL : 7.6.0.3 360488 Bytes 07/04/2008 20:22:51
            AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 06:17:06
            AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 11:26:33
            AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 06:10:18
            NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
            RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 11:38:13
            RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 11:50:37
            SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 08:37:21

            Configuration settings for the scan:
            Jobname..........................: Complete system scan
            Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
            Logging..........................: low
            Primary action...................: interactive
            Secondary action.................: ignore
            Scan master boot sector..........: on
            Scan boot sector.................: on
            Boot sectors.....................: D:,
            Scan memory......................: on
            Process scan.....................: on
            Scan registry....................: on
            Search for rootkits..............: on
            Scan all files...................: All files
            Scan archives....................: on
            Recursion depth..................: 20
            Smart extensions.................: on
            Macro heuristic..................: on
            File heuristic...................: high

            Start of the scan: mercredi 9 avril 2008 15:52

            Starting search for hidden objects.
            Error in ARK lib

            The scan of running processes will be started
            Scan process 'avscan.exe' - '1' Module(s) have been scanned
            Scan process 'avcenter.exe' - '1' Module(s) have been scanned
            Scan process 'iexplore.exe' - '1' Module(s) have been scanned
            Scan process 'alg.exe' - '1' Module(s) have been scanned
            Scan process 'iPodService.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'CDAC11BA.EXE' - '1' Module(s) have been scanned
            Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
            Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
            Scan process 'sched.exe' - '1' Module(s) have been scanned
            Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
            Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
            Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
            Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
            Scan process 'avgnt.exe' - '1' Module(s) have been scanned
            Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
            Scan process 'E_S10IC2.EXE' - '1' Module(s) have been scanned
            Scan process 'mixer.exe' - '1' Module(s) have been scanned
            Scan process 'shwicon2k.exe' - '1' Module(s) have been scanned
            Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
            Scan process 'kbd.exe' - '1' Module(s) have been scanned
            Scan process 'hphmon05.exe' - '1' Module(s) have been scanned
            Scan process 'hpwuSchd.exe' - '1' Module(s) have been scanned
            Scan process 'HpqCmon.exe' - '1' Module(s) have been scanned
            Scan process 'hpsysdrv.exe' - '1' Module(s) have been scanned
            Scan process 'avguard.exe' - '1' Module(s) have been scanned
            Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
            Scan process 'aawservice.exe' - '1' Module(s) have been scanned
            Scan process 'explorer.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'lsass.exe' - '1' Module(s) have been scanned
            Scan process 'services.exe' - '1' Module(s) have been scanned
            Scan process 'winlogon.exe' - '1' Module(s) have been scanned
            Scan process 'csrss.exe' - '1' Module(s) have been scanned
            Scan process 'smss.exe' - '1' Module(s) have been scanned
            39 processes with 39 modules were scanned

            Starting master boot sector scan:
            Master boot sector HD0
            [NOTE] No virus was found!
            Master boot sector HD1
            [NOTE] No virus was found!
            [WARNING] The boot sector file could not be read!
            [WARNING] Error code: 0x0015
            Master boot sector HD2
            [NOTE] No virus was found!
            [WARNING] The boot sector file could not be read!
            [WARNING] Error code: 0x0015
            Master boot sector HD3
            [NOTE] No virus was found!
            [WARNING] The boot sector file could not be read!
            [WARNING] Error code: 0x0015
            Master boot sector HD4
            [NOTE] No virus was found!
            [WARNING] The boot sector file could not be read!
            [WARNING] Error code: 0x0015

            Start scanning boot sectors:
            Boot sector 'C:\'
            [NOTE] No virus was found!
            Boot sector 'D:\'
            [NOTE] No virus was found!

            Starting to scan the registry.
            The registry was scanned ( '44' files ).

            Starting the file scan:

            Begin scan in 'C:\' <HP_PAVILION>
            C:\hiberfil.sys
            [WARNING] The file could not be opened!
            C:\pagefile.sys
            [WARNING] The file could not be opened!
            Begin scan in 'D:\' <HP_RECOVERY>

            End of the scan: mercredi 9 avril 2008 16:41
            Used time: 48:31 min

            The scan has been done completely.

            4914 Scanning directories
            330751 Files were scanned
            0 viruses and/or unwanted programs were found
            0 Files were classified as suspicious:
            0 files were deleted
            0 files were repaired
            0 files were moved to quarantine
            0 files were renamed
            2 Files cannot be scanned
            330751 Files not concerned
            18308 Archives were scanned
            2 Warnings
            0 Notes
            26807 Objects were scanned with rootkit scan
            0 Hidden objects were found
            0
        6. Contributeur
          ok

          ces deux warning la;

          c´est relatif a la memoire de windows; windows utilise ces processus pour hiberner en quelque sorte, donc pas de panic ;D
          0
          1. je considère donc que mon oridnateur n'est plus infecté par le virus de msn et que tout va pour le mieux???
            0
        7. Contributeur
          oui ;D

          on peux maintenant se separer

          je te souhaite une bonne continuation

          bye`

          g!rly`
          0
          1. ok merci beaucoup!!!!!!
            0
        8. Contributeur
          De rien mary851,
          Bye`
          0
          1. alala merci my g!rly , ton aide reste précieuse^^
            0
        Précédent
        • 1
        • 2