Virus msn...

Bonjour,
Voila, je crois avoir attrapé un virus msn je ne sais pas où (sa devait arriver sans antivirus...) et il essaye de se transmettre à tout mes contacts en leur demandant de cliquer sur un lien... Alors si quelqu'un pourrait me conseiller un logiciel ou la démarche à suivre pour éliminer ce virus une bonne fois pour toute... merci beaucoup d'avance!!!
Configuration: Windows XP
Internet Explorer 6.0

65 réponses

Résumé de la discussion

Une suspicion de virus MSN qui se propage par un lien est évoquée sur un système Windows XP équipé d'Internet Explorer 6.0 et sans antivirus actif. Les échanges intègrent des analyses techniques à l'aide d'outils comme MSNFix et HijackThis, avec des rapports détaillant fichiers, dossiers et processus susceptibles d'être liés à l'infection. Des éléments des réponses évoquent des composants McAfee et d'autres services Windows, ce qui peut orienter vers un nettoyage approfondi et des vérifications du démarrage. En cas de doute persistant, des vérifications complémentaires en mode sans échec et une évaluation croisée des éléments du registre et des services pourraient préciser l'état réel.

Bobot (l’IA à votre service)
  1. Déjà, télécharge et lance adaware et/ou spyware bot. Ensuite, effectue un scan antivirus en ligne (symantec, kaperski, avast, tu as le choix, ils le proposent presque tous). Et pour finir, une fois ton PC dévérollé, installe un antivirus et un firewall (zone alarm, ça marche bien et c'est gratuit).
    1. Contributeur sécurité
      Salut,
      pas d'antivirus ???!!! c'est comme prendre l'autoroute sans frein sur sa bagnole ... ;)

      Commencs ce-ci :
      A-Télécharges et installes le logiciel HijackThis :

      ici :ftp://ftp.commentcamarche.com/download/HJTInstall.exe
      ou ici : http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe

      1-Cliquer sur le setup pour lancer l'installe : laisses toi guider et ne modifies pas les paramètres d'instalation .
      A la fin tu doit avoir un raccouci sur ton bureau et aussi un cheminement comme : "C:\ programme file\Trend Micro\HijackThis\HijackThis.exe " .

      Important :
      Renommer le prg HijackThis :
      Rends toi sur ton PC ici "C:\ programme file\Trend Micro\HijackThis\HijackThis.exe"<---cliques droit sur ce dernier et choisis "renommer" : tapes monjack et valide .

      tuto pour utilisation
      Regardes ici, c'est parfaitement expliqué en images :
      http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

      2-!!Déconnectes toi et fermes toute tes applications en cours !!

      Cliques sur le raccourci du bureau,
      Fais un scan monjack (ou HijackThis renommé) en cliquant sur : "Do a system scan and save a logfile"

      ---> Postes le rapport généré pour analyse ...

      ***********************************************************

      Puis enchaine directement par ce-ci :
      B -Télécharges MSNFix.zip (de !aur3n7) :
      http://sosvirus.changelog.fr/MSNFix.zip
      ---> décompresses-le sur le Bureau et pas ailluers ( = extraire tout ).

      Impératif : Démarrer en mode sans echec :
      Comment aller en Mode sans échec
      1) Redémarres ton ordi
      2) Tapotes la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
      3) Tu verras un écran avec options de démarrage apparaître
      4) Choisis la première option : Sans Échec, et valide avec "Entrée"
      5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
      (attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreur ...)

      Lances le fichier MSNFix.bat qui se trouve dans le dossier MSNfix, sur le bureau.
      - Exécute l'option R (recherche).
      - Si l'infection est détectée, exécute l'option N (nettoyage) .
      ---> Une fois finit, sauvegardes ce rapport sur ton bureau .

      Redémarres ton PC ( = retour au mode normal ),
      et postes moi ce rapport accompagné d'un nouveau rapport hijackthis ( fait en mode normal ) dans ta prochaine réponse pour analyse ...
      1. ouais ou sinon tu regarde l'autre topic....mais avant tout installe toi un anti virus! avast et gratuit et performant!
        1. Ok merci beaucoup je vais essayer la démarche et envoyer le rapport. Ah oui en fait mon antivirus a expiré c'est pour ça... (Oups :-s)
          1. allez bonne chance! parce que c'est pas toujours facile en enlevez ces petites merdes!
            1. Ok merci du conseil j'irai installer avast dès que ce truc aura été éradiqué ;-) Alors voila le rapport:

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 10:44:24, on 30/06/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
              C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
              C:\WINDOWS\system32\spoolsv.exe
              c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\WINDOWS\System32\GEARSec.exe
              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              C:\Program Files\Dell Network Assistant\hnm_svc.exe
              C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
              c:\program files\mcafee.com\agent\mcdetect.exe
              c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
              C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
              C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\wscntfy.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Windows Live\Messenger\usnsvc.exe
              C:\WINDOWS\explorer.exe
              C:\Program Files\Windows Media Player\wmplayer.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Trend Micro\HijackThis\monjack.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
              O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
              O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
              O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
              O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
              O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
              O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
              O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
              O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
              O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
              O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
              O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
              O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
              1. Contributeur sécurité
                Note : avant d'instaler Avast , il faudra désntaler proprement mcAfee et Norton ! ... mais on vera cela tout à l'heure ^^

                tout de suite : fais la manipe que je t'ai donné avec MSNFix et postes les rapports demandés ...
                1. Voila le rapport mais je ne crois pas qu'il ai trouvé d'infection...

                  MSNFix 1.728

                  C:\Documents and Settings\Nico.MON-ORDI\Bureau\MSNFix\MSNFix
                  Fix exécuté le 30/06/2008 - 10:58:14,87 By Nico
                  mode sans échec

                  ************************ Recherche les fichiers présents

                  Aucun Fichier trouvé

                  ************************ Recherche les dossiers présents

                  Aucun dossier trouvé

                  ************************ Fichiers suspects

                  Aucun Fichier trouvé

                  ************************ HKLM\...\Winlogon\Userinit

                  Userinit = C:\WINDOWS\system32\userinit.exe,

                  Important : http://msnfix.changelog.fr/index.php/2008/05/18/32-alerte

                  ------------------------------------------------------------------------
                  Auteur : !aur3n7 Contact: https://www.ionos.fr/
                  ------------------------------------------------------------------------

                  --------------------------------------------- END

                  ---------------------------------------------

                  Et le rapport Hijackthis

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 11:06:15, on 30/06/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                  C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                  C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZENG09.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\WINDOWS\System32\GEARSec.exe
                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  C:\Program Files\Dell Network Assistant\hnm_svc.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                  c:\program files\mcafee.com\agent\mcdetect.exe
                  c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
                  C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
                  C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\wscntfy.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\Program Files\Trend Micro\HijackThis\monjack.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                  O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
                  O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"

                  /background
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE

                  LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE

                  RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program

                  Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program

                  Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                  O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program

                  Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                  O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program

                  Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                  O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program

                  Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program

                  Files\Dell Network Assistant\hnm_svc.exe
                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation -

                  C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program

                  Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers

                  communs\logishrd\lvmvfm\LVPrcSrv.exe
                  O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program

                  files\mcafee.com\agent\mcdetect.exe
                  O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. -

                  c:\PROGRA~1\mcafee.com\vso\mcshield.exe
                  O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc -

                  c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
                  O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc -

                  C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
                  O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation -

                  C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
                  O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. -

                  C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
                  1. Contributeur sécurité
                    Rein ... bizard ...

                    Fais ce-ci :

                    Télécharges SDFix sur ton bureau :
                    http://downloads.andymanchesta.com/RemovalTools/SDFix.exe.

                    --->Double clique sur SDFix.exe et choisis "Install" .

                    Puis une fois l'instale faite ,redémarre en mode sans échec .
                    Comment aller en Mode sans échec :
                    1) Redémarre ton ordi
                    2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                    3) Tu verras un écran avec options de démarrage apparaître
                    4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                    5) Choisis ton compte habituel, et non Administrateur (si besoin ... )

                    Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
                    --->Tape Y pour lancer le script.
                    Le Fix supprime les services du virus et nettoie le registre, de ce fait un redémarrage est nécessaire , donc :
                    presses une touche pour redémarrer quand il te le sera demandé .

                    Le PC va mettre du temps avant de démarrer ( c'est normale ), après le chargement du Bureau presses une touche lorsque "Finished" s'affiche .

                    Le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier C:\SDFix sous le nom "Report.txt".
                    Postes ce dernier dans ta prochaine réponse accompagné d'un nouveau rapport Hijakcthis pour analyse ...
                    1. voiula au moins tu c'est a qui casser la gueule! ^^ a lui ---> !aur3n7
                      1. Voila ça a mis un peu de temps mais c'est terminé :-D

                        [b]SDFix: Version 1.199 [/b]
                        Run by Nico on 30/06/2008 at 11:27

                        Microsoft Windows XP [version 5.1.2600]
                        Running From: C:\SDFix

                        [b]Checking Services [/b]:

                        Restoring Default Security Values
                        Restoring Default Hosts File

                        Rebooting

                        [b]Checking Files [/b]:

                        Trojan Files Found:

                        C:\WINDOWS\SYSTEM32\TASKKILL.EXE - Deleted

                        Removing Temp Files

                        [b]ADS Check [/b]:

                        [b]Final Check [/b]:

                        catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                        Rootkit scan 2008-06-30 11:34:05
                        Windows 5.1.2600 Service Pack 2 NTFS

                        scanning hidden processes ...

                        scanning hidden services & system hive ...

                        scanning hidden registry entries ...

                        scanning hidden files ...

                        scan completed successfully
                        hidden processes: 0
                        hidden services: 0
                        hidden files: 0

                        [b]Remaining Services [/b]:

                        Authorized Application Key Export:

                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                        "C:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"="C:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe:*:Enabled:Zoo Tycoon 2 Executable"
                        "C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"="C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe:*:Enabled:Battlefield 2"
                        "C:\\Program Files\\EA GAMES\\Battlefield Vietnam\\bfvietnam.exe"="C:\\Program Files\\EA GAMES\\Battlefield Vietnam\\bfvietnam.exe:*:Disabled:bfvietnam"
                        "C:\\Program Files\\Eidos Interactive\\Hothouse Creations\\Gangsters 2\\Gangsters2.exe"="C:\\Program Files\\Eidos Interactive\\Hothouse Creations\\Gangsters 2\\Gangsters2.exe:*:Enabled:Gangsters 2"
                        "C:\\Program Files\\Cyanide\\GameCenter\\GameCenter.exe"="C:\\Program Files\\Cyanide\\GameCenter\\GameCenter.exe:*:Enabled:GameCenter"
                        "C:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"="C:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe:*:Enabled:BF1942"
                        "C:\\Program Files\\Cyanide\\Pro Cycling Manager 2007\\PCM.exe"="C:\\Program Files\\Cyanide\\Pro Cycling Manager 2007\\PCM.exe:*:Enabled:Pro Cycling Manager 2007"
                        "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
                        "C:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"="C:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe:*:Enabled:Company of Heroes - Opposing Fronts"
                        "C:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2.exe"="C:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2.exe:*:Enabled:Ghost Recon Advanced Warfighter© 2"
                        "C:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2_dedicated.exe"="C:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2_dedicated.exe:*:Enabled:Ghost Recon Advanced Warfighter© 2 Dedicated Server"
                        "C:\\Program Files\\Sierra Entertainment\\D‚mo World in Conflict\\wic.exe"="C:\\Program Files\\Sierra Entertainment\\D‚mo World in Conflict\\wic.exe:*:Enabled:D‚mo World in Conflict"
                        "C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
                        "C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
                        "C:\\Documents and Settings\\Nico.MON-ORDI\\Application Data\\Firaxis Games\\Sid Meier's Civilization 4 Demo\\Civilization4.exe"="C:\\Documents and Settings\\Nico.MON-ORDI\\Application Data\\Firaxis Games\\Sid Meier's Civilization 4 Demo\\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4 Demo"
                        "C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
                        "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"="C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4"
                        "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                        "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
                        "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"

                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                        "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                        "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

                        [b]Remaining Files [/b]:

                        File Backups: - C:\SDFix\backups\backups.zip

                        [b]Files with Hidden Attributes [/b]:

                        Fri 29 Jun 2007 88 ..SHR --- "C:\WINDOWS\system32\632A2D0069.sys"
                        Tue 3 Jul 2007 4,184 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
                        Sun 15 Apr 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
                        Sun 15 Apr 2007 401 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv15.bak"
                        Sat 1 Sep 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
                        Wed 7 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\BITD.tmp"
                        Sat 29 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\73e2e9ec90b2a8bdc65c191633d70158\BIT21.tmp"
                        Sat 29 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\a1feda554f795971fda237333f75243f\BIT20.tmp"
                        Sat 29 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\be055ba2b2ed973399d61482c6723317\BIT1F.tmp"
                        Sat 29 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d87fb8947e75ca18dc081689c7a9b0bf\BIT1E.tmp"
                        Wed 30 Apr 2008 3,040 ...HR --- "C:\Documents and Settings\Nico.MON-ORDI\Application Data\SecuROM\UserData\securom_v7_01.bak"
                        Sun 15 Apr 2007 4,348 A..H. --- "C:\Documents and Settings\Nico.MON-ORDI\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
                        Thu 16 Aug 2007 401 A..H. --- "C:\Documents and Settings\Nico.MON-ORDI\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
                        Sun 15 Apr 2007 312 A.SH. --- "C:\Documents and Settings\Nico.MON-ORDI\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"
                        Wed 5 Apr 2006 233,425 A..H. --- "C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Mods\MaxRigaMod\Assets\XML\Technologies\~WRL0002.tmp"
                        Sat 8 Jul 2006 35,674 A..H. --- "C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Mods\MaxRigaMod\Assets\XML\units\~WRL0002.tmp"

                        [b]Finished![/b]

                        et le rapport hijackThis:

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 11:39:40, on 30/06/2008
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                        C:\Program Files\Bonjour\mDNSResponder.exe
                        C:\WINDOWS\System32\GEARSec.exe
                        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        C:\Program Files\Dell Network Assistant\hnm_svc.exe
                        C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                        c:\program files\mcafee.com\agent\mcdetect.exe
                        c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
                        C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
                        C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\wscntfy.exe
                        C:\WINDOWS\system32\notepad.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Windows Live\Messenger\usnsvc.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Trend Micro\HijackThis\monjack.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                        O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
                        O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
                        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                        O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                        O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
                        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                        O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                        O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
                        O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
                        O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
                        O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
                        O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
                        O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
                        1. Contributeur sécurité
                          Bien ... Fais ce-ci maintenant :

                          Télécharges MalwareByte's :
                          ici ftp://ftp.commentcamarche.com/download/mbam-setup.exe
                          ou ici : http://www.malwarebytes.org/mbam.php

                          Installes le ( choisis bien "francais" ; ne modifies pas les paramètres d'installe ) et mets le à jour .

                          Potasses le tuto pour te familiariser avec le prg : https://forum.pcastuces.com/sujet.asp?f=31&s=3
                          ( cela dis, il est très simple d'utilisation ).

                          Impératif : redémarres en mode sans échec :
                          Comment aller en Mode sans échec
                          1) Redémarres ton ordi
                          2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                          3) Tu verras un écran avec options de démarrage apparaître
                          4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                          5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
                          (attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...)

                          Lances Malwarebyte's .

                          Fais un scan dit "complet" ( sélectionnes bien tout tes disks avant le scan ) et supprimes tout ce qu'il peut trouver :
                          --->une fois le scan terminé , click sur "résultat" : puis vérifies que tous les objets infectés soient validés, puis click sur " suppression " .

                          Redémarres ton PC ( mode normal ).

                          Postes le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes) accompagné d'un nouvel hijackthis ( fait en mode normal ) ...
                          1. Voila ça a pris du temps mais c'est fini, mais je ne crois pas qu'il ai detecté d'infection... (peut être a-t-elle été détruite?)

                            Malwarebytes' Anti-Malware 1.19
                            Version de la base de données: 907
                            Windows 5.1.2600 Service Pack 2

                            12:39:31 30/06/2008
                            mbam-log-6-30-2008 (12-39-31).txt

                            Type de recherche: Examen complet (C:\|)
                            Eléments examinés: 141369
                            Temps écoulé: 31 minute(s), 48 second(s)

                            Processus mémoire infecté(s): 0
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 0
                            Valeur(s) du Registre infectée(s): 0
                            Elément(s) de données du Registre infecté(s): 0
                            Dossier(s) infecté(s): 0
                            Fichier(s) infecté(s): 0

                            Processus mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Valeur(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Elément(s) de données du Registre infecté(s):
                            (Aucun élément nuisible détecté)

                            Dossier(s) infecté(s):
                            (Aucun élément nuisible détecté)

                            Fichier(s) infecté(s):
                            (Aucun élément nuisible détecté)

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 12:43:10, on 30/06/2008
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\Ati2evxx.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\Ati2evxx.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\WINDOWS\system32\spoolsv.exe
                            c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                            C:\Program Files\Bonjour\mDNSResponder.exe
                            C:\WINDOWS\System32\GEARSec.exe
                            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            C:\Program Files\Dell Network Assistant\hnm_svc.exe
                            C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                            c:\program files\mcafee.com\agent\mcdetect.exe
                            c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
                            C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
                            C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\Windows Live\Messenger\usnsvc.exe
                            C:\WINDOWS\system32\wscntfy.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\Program Files\Trend Micro\HijackThis\monjack.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                            O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
                            O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
                            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                            O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                            O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
                            O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                            O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                            O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
                            O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
                            O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
                            O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
                            O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
                            O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
                            1. Contributeur sécurité
                              Effectivement , rien du côter de Malwarebytes (tant mieux ^^ )

                              Fais ce-ci maintenant :

                              1- Télécharge clean.zip :
                              http://www.malekal.com/download/clean.zip
                              Décompresses-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier clean.

                              Impératif : Redémarres en mode sans échec :
                              Comment aller en Mode sans échec
                              1) Redémarre ton ordi
                              2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                              3) Tu verras un écran avec options de démarrage apparaître
                              4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                              5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
                              (PS : note bien ce que tu as à faire, car pas de connexion en mode sans échec ... ).

                              Ouvres le dossier Clean qui se trouve sur ton bureau.

                              Double-clic sur clean.cmd.
                              Une fenêtre noire va apparaître, suis les consignes.
                              Choisis l'option 2 et laisses faire ...

                              Une fois finit, redémarres ton PC ( retour en mode normal ).

                              Ensuite :
                              2-Télécharges : - CCleaner ( différent de "clean" ... )
                              https://www.pcastuces.com/logitheque/ccleaner.htm
                              Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corrigé ton registre .Lors de l'installation, avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 première.
                              Une fois le prg instalé et lancé, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures"( Par la suite, laisse-le avec ses réglages par défaut. C'est tout ).

                              Un tuto ( aide ):
                              http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

                              Utilisation:
                              vas dans "nettoyeur" : fait analyse puis nettoyage
                              et vas dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .

                              ( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )

                              Donc une fois cela fait , postes le rapport de "clean" qui se trouve ici C:\rapport_clean.txt et fais moi un petit topo sur l'état de santé de ton PC avant de poursuivre ....
                              1. D'accord je fais ça, mais qu'est ce que tu veux dire par un topo sur l'état de santé de mon PC?
                                • 1
                                • 2
                                • 3
                                • 4