Virus MSN FACEBOOK

Bonjour,
Jusqu'à cette nuit 1h30 et depuis 9 h ce matin, je suis sur les forums de virus MSN depuis que ma fille a exécuté hier soir un programme reçu via un lien sur MSN. J'ai essayé tous les antivirus trouvés (MSN Cleaner, MSNFix, Avira antivir personal, Clean Virus MSN...) mais évidemment rien n'a fonctionné ! J'ai vu beaucoup de forums sur internet mais je ne suis pas calée en informatique et je ne sais pas quoi faire. Quelqu'un peut-il m'aider ? merci d'avance
Configuration: Windows XP Internet Explorer 7.0

42 réponses

Résumé de la discussion

Infection liée à un lien MSN provoquant des symptômes persistants et des tentatives de nettoyage infructueuses sur Windows XP et Internet Explorer 7, avec des alertes et des programmes indésirables. Des étapes fondées sur les processus actifs recommandent de terminer avguard.exe via le gestionnaire de tâches puis de relancer des outils de désinfection tels qu'AD-remover. D'autres solutions évoquent UsbFix pour répertorier et supprimer les éléments malveillants, nettoyer les fichiers temporaires et nettoyer le registre, avec un fichier de rapports et des suppressions programmées à prévoir. En complément, des rapports HijackThis et UsbFix détaillent des clés Run et des BHO suspects, ainsi que des programmes accédant au réseau, montrant l'importance d'une approche en plusieurs outils.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Désinstalle boonty game via ajout/suppression de programmes.

    Le reste est clean, on peut passer au nettoyage :

    -+-+-+-> CCleaner <-+-+-+-

    [x] Télécharge CCleaner à cette adresse : https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

    [X] Choisis " french " pour l'installation.

    [x] /!\ Important : Décoche " Ajouter la barre d'outil Yahoo toolbar ! /!\

    [x] Lance le, dans la partie " nettoyeur " clique sur " analyser " à droite puis ensuite sur " nettoyer "

    [x] Clique sur l'onglet " Registre " puis " chercher les erreurs "

    [x] Clique sur " corriger les erreurs " puis un message de demandera si tu veux faire un backup, accepte en cliquant sur " oui " et enregistre le quelque part.

    [x] Clique enfin sur " Corriger toutes les erreurs séléctionnées "

    [x] Pense à renouveller l'opération assez souvent pour garder un pc propre.

    -+-+-+-> Tools Cleaner <-+-+-+-

    [o] Afin de supprimer tout les logiciels qui ont été utilisés pour ta désinfection,

    [o] Télécharge ToolsCleaner sur ton bureau à cette adresse : https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/

    [o] Double-clique sur « Toolscleaner.exe »

    [o] Clique sur "restauration" pour créer un point de restauration.

    [o] Puis clique sur « recherche »

    [o] Quand la recherche sera terminée, clique sur "suppression".

    [o] A la fin (il y aura des indications dans le cadre en-dessous), clique sur "quitter" et poste le rapport qui se trouve dans C:\Tcleaner.txt

    ---- Désactiver la restauration système ----

    XP : [x] Cliquer sur démarrer -> Puis clique droit sur " Poste de Travail "
    [x] Clique sur " Propriété "
    [x] Va dans l'onglet " Restauration du Système ", puis coche " Désactiver la restauration système "
    [x] Clique sur " Ok " , redémarre ton PC, rend toi encore une fois dans " Restauration du système "
    [x] Décoche " Désactiver la restauration système " puis clique sur " Ok "

    Vista : https://www.commentcamarche.net/faq/13214-vista-desactiver-reactiver-la-restauration-systeme-de-vista

    ---- Créer un point de restauration propre ----

    https://www.vulgarisation-informatique.com/creer-point-restauration.php
    0
    1. je ne trouve pas boonty game dans ajout/suppression de programmes !
      0
    2. Je n'ai pas trouvé boonty games, j'ai quand même fait la suite, voici le rapport (je dois arrêter pour aujourd'hui, je ne pourrai reprendre que demain soir s'il y a encore des manips à faire. Merci beaucoup et à+) :

      [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

      --> Recherche:

      C:\cleannavi.txt: trouvé !
      C:\MsnCleaner.txt: trouvé !
      C:\UsbFix.txt: trouvé !
      C:\UsbFix: trouvé !
      C:\Rsit: trouvé !
      C:\Documents and Settings\Kévin\Bureau\MSNCleaner.exe: trouvé !
      C:\Documents and Settings\Kévin\Bureau\catchme.log: trouvé !
      C:\Documents and Settings\Kévin\Bureau\Tout\Mes documents\Images\MSNCleaner.zip: trouvé !
      C:\Documents and Settings\Kévin\Bureau\Tout\Mes documents\Images\Msnfix.zip: trouvé !
      C:\Documents and Settings\Kévin\Bureau\Tout\Mes documents\Images\MsnFix: trouvé !
      C:\Documents and Settings\Kévin\Bureau\Tout\Mes documents\Images\MSNFix\MsnFix: trouvé !
      C:\Documents and Settings\Kévin\Bureau\Tout\Mes documents\Images\MSNFix\MSNFix\incl\catchme.exe: trouvé !
      C:\Documents and Settings\Kévin\Local Settings\Temp\Répertoire temporaire 1 pour MSNFix.zip\MsnFix: trouvé !
      C:\Program Files\Navilog1: trouvé !
      C:\Program Files\Ad-remover: trouvé !
      C:\Program Files\Navilog1\Navilog1.bat: trouvé !
      C:\Program Files\Navilog1\catchme.exe: trouvé !
      C:\Program Files\trend micro\HijackThis.exe: trouvé !
      C:\Program Files\trend micro\hijackthis.log: trouvé !
      C:\WINDOWS\msnfix.txt: trouvé !
      C:\WINDOWS\Downloaded Program Files\*.msnfix: trouvé !
      C:\WINDOWS\system32\*.msnfix: trouvé !

      ---------------------------------
      --> Suppression:

      C:\Documents and Settings\Kévin\Bureau\MSNCleaner.exe: supprimé !
      C:\Documents and Settings\Kévin\Bureau\Tout\Mes documents\Images\MSNCleaner.zip: supprimé !
      C:\Documents and Settings\Kévin\Bureau\Tout\Mes documents\Images\Msnfix.zip: supprimé !
      C:\Documents and Settings\Kévin\Bureau\Tout\Mes documents\Images\MSNFix\MSNFix\incl\catchme.exe: supprimé !
      C:\Program Files\Navilog1\Navilog1.bat: supprimé !
      C:\Program Files\Navilog1\catchme.exe: supprimé !
      C:\Program Files\trend micro\HijackThis.exe: supprimé !
      C:\cleannavi.txt: supprimé !
      C:\MsnCleaner.txt: supprimé !
      C:\UsbFix.txt: supprimé !
      C:\Documents and Settings\Kévin\Bureau\catchme.log: supprimé !
      C:\Program Files\trend micro\hijackthis.log: supprimé !
      C:\WINDOWS\msnfix.txt: supprimé !
      C:\WINDOWS\Downloaded Program Files\*.msnfix: ERREUR DE SUPPRESSION !!
      C:\WINDOWS\system32\*.msnfix: ERREUR DE SUPPRESSION !!
      C:\UsbFix: supprimé !
      C:\Rsit: supprimé !
      C:\Documents and Settings\Kévin\Bureau\Tout\Mes documents\Images\MsnFix: supprimé !
      C:\Documents and Settings\Kévin\Local Settings\Temp\Répertoire temporaire 1 pour MSNFix.zip\MsnFix: supprimé !
      C:\Program Files\Navilog1: supprimé !
      C:\Program Files\Ad-remover: supprimé !
      0
  2. Contributeur sécurité
    C'est ok. Refais un rapport RSIT
    0
    1. Et encore un !!!

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by Isabelle BROQUEREAU at 2009-10-10 19:00:50
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 106 GB (70%) free of 153 GB
      Total RAM: 767 MB (41% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:00:52, on 10/10/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\Microsoft LifeCam\MSCamS32.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\EA Games\Need for Speed Undercover\PB\PnkBstrA.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\wscntfy.exe
      C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
      C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
      C:\WINDOWS\vVX1000.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Documents and Settings\Isabelle BROQUEREAU\Local Settings\Temporary Internet Files\Content.IE5\RL8MZG2Y\RSIT[1].exe
      C:\Program Files\trend micro\Isabelle BROQUEREAU.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
      O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
      O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
      O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
      O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
      O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
      O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
      O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
      O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - C:\Program Files\EA Games\Need for Speed Undercover\PB\PnkBstrA.exe
      0
  3. Contributeur sécurité
    Ben ça ne craint pas, des miliers de rapports sont postés chaque jours avec les noms et prénoms de personnes dedans, et ça intéresse personne lol

    Donc rien à craindre pour ta sécurité, ici on s'occupe que de désinfecter, pas de faire de l'espionnage
    0
    1. je n'ai pas reçu ou trouvé de rapport, j'ai juste copié dans le presse papier les infos suivantes :
      C:\Documents and Settings\Kévin\Bureau\Tout\Mes documents\Images\MSNFix\MSNFix\incl\Hostsclean.exe Win32/Packed.Autoit.Gen application supprimé - mis en quarantaine
      C:\Documents and Settings\Kévin\Bureau\Tout\Mes documents\Images\MSNFix\MSNFix\incl\Process.exe Win32/PrcView application nettoyé par suppression - mis en quarantaine
      C:\Program Files\Ad-Remover\Process.com Win32/PrcView application nettoyé par suppression - mis en quarantaine
      C:\Program Files\Ad-Remover\QUARANTINE\PROGRA~1\SHOPPI~1\Uninst.exe.vir une variante probable de Win32/Adware.Agent application supprimé - mis en quarantaine
      C:\UsbFix\Tools\Kill_P.exe Win32/PrcView application nettoyé par suppression - mis en quarantaine
      C'est bon ?
      0
  4. Contributeur sécurité
    Pour le nom et prénom, oui, si c'est bien ceux-ci :

    Run by Isabelle BROQUEREAU at 2009-10-10 14:25:09

    Concernant le reste, aucune informations personelle.
    0
    1. En quoi ça peut craindre ?
      0
  5. Contributeur sécurité
    Oui, c'est pour ça qu'il faut avoir un PC bien protégé , et surtout faire attention aux sites qu'on visite, mais je te passerais plusieurs liens à la fin de la désinfection pour t'informer et proteger ton PC
    0
    1. Le scan n'est qu'à 43 % ...
      A part ça, avec toutes les infos que je balance sur ce forum depuis ce matin, il y a des riques pour moi par rapport à la sécurité de mon ordi ou autres (nom et prénom figurant dans les rapports...) ?
      0
  6. Contributeur sécurité
    C'est aussi possible qu'ils aient été téléchargés " involontairement " , si vous avez confiance en votre fils laissez lui l'accès à l'ordi, de plus, il faudrait qu'il soit " calé " en informatique pour connaître l'existence de tels programmes.

    Continuez avec le scan en ligne de nod32
    0
    1. Il n'est pas calé du tout (la preuve c'est que c'est moi qui me dépatouille de tout ce m.... depuis ce matin), mais le problème c'est qu'en faisant pas grand chose sur internet on peut quand même courir de gros risques !
      le scan est en cours...
      0
  7. Contributeur sécurité
    Ce sont des programmes malveillants, des malwares, mais ils ont été supprimés par malwarebyte's.
    0
    1. Je pense que c'est des trucs qui se téléchargent involontairement, il croit trouver une musique et c'est carrément autre chose qui se pointe ! A part leur supprimer l'accès à l'ordi je ne sais pas trop quoi faire !!!
      0
  8. "Quelqu'un télécharge des programmes de hack sur emule .. lol.. " c'est quoi ces trucs parce que mon fils (emule c'est lui, chacun ses défauts... !!!) à part de la musique... ?
    0
    1. Contributeur sécurité

      C:\Program Files\eMule\Incoming\Password Cracker.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
      C:\Program Files\eMule\Incoming\sdbot with NetBIOS Spread.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
      C:\Program Files\eMule\Incoming\Sub7 2.3 Private.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
      C:\Program Files\eMule\Incoming\Website Hacker.exe (Trojan.Downloader) -> Quarantined and deleted successfully.


      Quelqu'un télécharge des programmes de hack sur emule .. lol..

      Fais ceci maintenant :

      -+-+-+-> ESET Nod32 Scan en Ligne <-+-+-+-

      [x] Rends toi sur ce site : https://www.eset.com/

      /!\ Il faut que tu utilises internet explorer pour faire l'analyse en ligne /!\

      [x] Coche " Oui, j'accepte.... " puis cliques sur " Start ".

      [x] Attend un peu le chargement de la page, puis clique sur le bandeau jaune en haut de
      l'écran " Ce site nécessite.... OnlineScanner.cab... "

      -> Clique sur " Installer le contrôle ActiveX "
      -> Confirme ensuite en cliquant sur " Installer " dans la petite fenêtre qui s'ouvre.

      [x] Clique sur paramètre avancé, puis coche " Rechercher les applications potentiellement dangereuses " , vérifie que les deux premieres cases sont elles aussi cochées.

      [x] Le scanner se mettra à jour, celà peut prendre un certain temps

      [x] L'analyse va ensuite s'effectuer.

      [x] Copie/Colle le rapport dans ton prochain message. ( C:\ESET\...\log.txt )
      0
      1. Malwarebytes' Anti-Malware 1.41
        Version de la base de données: 2936
        Windows 5.1.2600 Service Pack 3

        10/10/2009 17:23:40
        mbam-log-2009-10-10 (17-23-40).txt

        Type de recherche: Examen complet (C:\|)
        Eléments examinés: 229934
        Temps écoulé: 1 hour(s), 9 minute(s), 16 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 1
        Valeur(s) du Registre infectée(s): 0
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 24
        Fichier(s) infecté(s): 63

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.

        Valeur(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        C:\Documents and Settings\Dom\Application Data\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Dom\Application Data\ShoppingReport\cs (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Dom\Application Data\ShoppingReport\cs\db (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Dom\Application Data\ShoppingReport\cs\dwld (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Dom\Application Data\ShoppingReport\cs\report (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Dom\Application Data\ShoppingReport\cs\res2 (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Isabelle BROQUEREAU\Application Data\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Isabelle BROQUEREAU\Application Data\ShoppingReport\cs (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Isabelle BROQUEREAU\Application Data\ShoppingReport\cs\db (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Isabelle BROQUEREAU\Application Data\ShoppingReport\cs\dwld (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Isabelle BROQUEREAU\Application Data\ShoppingReport\cs\report (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Isabelle BROQUEREAU\Application Data\ShoppingReport\cs\res1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Kévin\Application Data\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Kévin\Application Data\ShoppingReport\cs (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Kévin\Application Data\ShoppingReport\cs\db (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Kévin\Application Data\ShoppingReport\cs\dwld (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Kévin\Application Data\ShoppingReport\cs\report (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Kévin\Application Data\ShoppingReport\cs\res1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Mathilde\Application Data\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Mathilde\Application Data\ShoppingReport\cs (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Mathilde\Application Data\ShoppingReport\cs\db (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Mathilde\Application Data\ShoppingReport\cs\dwld (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Mathilde\Application Data\ShoppingReport\cs\report (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Mathilde\Application Data\ShoppingReport\cs\res2 (Adware.ShopperReports) -> Quarantined and deleted successfully.

        Fichier(s) infecté(s):
        C:\Documents and Settings\Kévin\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000a47 (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Mathilde\Local Settings\Temporary Internet Files\Content.IE5\DFL99GOG\IMG00098714911567251832-JPG[1].EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Mathilde\Local Settings\Temporary Internet Files\Content.IE5\G42MEA5M\mp[1].exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Mathilde\Local Settings\Temporary Internet Files\Content.IE5\G42MEA5M\mp[2].exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\Navilog1\gnc.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\ICQ Hacker.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\AOL Instant Messenger (AIM) Hacker.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\AOL Password Cracker.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\Brutus FTP Cracker.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\Counter-Strike KeyGen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\DCOM Exploit.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\DivX 5.0 Pro KeyGen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\FTP Cracker.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\Half-Life 2 Downloader.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\Hotmail Cracker.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\Hotmail Hacker.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\Norton Anti-Virus 2005 Enterprise Crack.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\Password Cracker.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\sdbot with NetBIOS Spread.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\Sub7 2.3 Private.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\UT 2003 KeyGen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\Website Hacker.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\Windows 2003 Advanced Server KeyGen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\Windows Password Cracker.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\IP Nuker.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\Keylogger.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\L0pht 4.0 Windows Password Cracker.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\Microsoft Visual Basic KeyGen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\Microsoft Visual C++ KeyGen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\Microsoft Visual Studio KeyGen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\MSN Password Cracker.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\NetBIOS Cracker.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Program Files\eMule\Incoming\NetBIOS Hacker.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{893339F0-235C-40B2-B98B-C41A3ECA6EC3}\RP424\A0120804.com (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\_OTMoveIt\MovedFiles\10102009_135941\WINDOWS\msnsmgr.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Dom\Application Data\ShoppingReport\cs\Config.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Dom\Application Data\ShoppingReport\cs\db\Aliases.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Dom\Application Data\ShoppingReport\cs\db\Sites.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Dom\Application Data\ShoppingReport\cs\dwld\WhiteList.xip (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Dom\Application Data\ShoppingReport\cs\report\aggr_storage.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Dom\Application Data\ShoppingReport\cs\report\send_storage.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Dom\Application Data\ShoppingReport\cs\res2\WhiteList.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Isabelle BROQUEREAU\Application Data\ShoppingReport\cs\Config.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Isabelle BROQUEREAU\Application Data\ShoppingReport\cs\db\Aliases.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Isabelle BROQUEREAU\Application Data\ShoppingReport\cs\db\Sites.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Isabelle BROQUEREAU\Application Data\ShoppingReport\cs\dwld\WhiteList.xip (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Isabelle BROQUEREAU\Application Data\ShoppingReport\cs\report\aggr_storage.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Isabelle BROQUEREAU\Application Data\ShoppingReport\cs\report\send_storage.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Isabelle BROQUEREAU\Application Data\ShoppingReport\cs\res1\WhiteList.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Kévin\Application Data\ShoppingReport\cs\Config.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Kévin\Application Data\ShoppingReport\cs\db\Aliases.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Kévin\Application Data\ShoppingReport\cs\db\Sites.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Kévin\Application Data\ShoppingReport\cs\dwld\WhiteList.xip (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Kévin\Application Data\ShoppingReport\cs\report\aggr_storage.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Kévin\Application Data\ShoppingReport\cs\report\send_storage.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Kévin\Application Data\ShoppingReport\cs\res1\WhiteList.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Mathilde\Application Data\ShoppingReport\cs\Config.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Mathilde\Application Data\ShoppingReport\cs\db\Aliases.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Mathilde\Application Data\ShoppingReport\cs\db\Sites.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Mathilde\Application Data\ShoppingReport\cs\dwld\WhiteList.xip (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Mathilde\Application Data\ShoppingReport\cs\report\aggr_storage.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Mathilde\Application Data\ShoppingReport\cs\report\send_storage.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Mathilde\Application Data\ShoppingReport\cs\res2\WhiteList.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
        0
        1. Contributeur sécurité
          Pourtant ton PC était bien vérolé, pas de " graves " infection mais beaucoup de petites.

          Laisse tomber spybot on s'en occupera après c'est pas très important, fais le scan malwarebyte's
          0
          1. Contributeur sécurité
            On arrive au bout ;)

            Le PC se porte mieux ?

            ----------------
            Désinstalle Spybot, puis :

            -+-+-+-> Malwarebyte's Anti-Malware <-+-+-+-

            [x] Télécharge Malwarebyte's anti-malware (MBAM) à cette adresse : http://www.malwarebytes.org/mbam/program/mbam-setup.exe

            [x] Installe le.

            [x] Met le à jour.

            [x] Coche bien tout les éléments trouvés et supprime les !

            [x] Un tutoriel pour son utilisation est disponible ici : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

            [x] Suis les indications données sur le lien précédent puis copie/colle le rapport généré dans ton prochain message
            0
            1. En fait, depuis hier soir, on avait juste msn qui ne fonctionnait pas bien et qui envoyait des messages à ceux qui étaient sur msn avec mes enfants, et qui coupait régulièrement. Le reste allait bien jusque là...
              Je ne trouve pas Spybot dans ajouter ou supprimer programmes ?
              0
          2. Contributeur sécurité
            -+-+-+-> Hijackthis <-+-+-+-

            [x] Lance hijackthis ( C:\Program Files\Trend Micro\Hijackthis.exe )

            [x] Clique sur " None of the above, just start the program " puis sur " Scan "

            [x] Coche les lignes en gras ci dessous :


            O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
            O3 - Toolbar: (no name) - {CEDDA62B-5FBE-4AB2-AE2E-5E069F444444} - (no file)
            O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [Windows Rundll Center] msnsmgr.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
            O8 - Extra context menu item: Add to AMV Video Converter... - C:\Program Files\MP3 Player Utilities 4.24\AMVConverter\grab.html
            O16 - DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} (JordanUploader Class) - http://photoservice.fujicolor.eu/ips-opdata/objects/jordan.cab
            O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)


            [x] Clique ensuite sur " Fix checked "

            ------------

            Désinstalle proprement avast à l'aide de l'outil de désinstallation : https://www.avast.com/fr-fr/uninstall-utility

            ------------

            Reposte ensuite un log RSIT
            0
            1. Désolée c'est un peu long mais je m'y perds un peu (et j'ai les nerfs qui lâchent)...

              Logfile of random's system information tool 1.06 (written by random/random)
              Run by Isabelle BROQUEREAU at 2009-10-10 15:05:38
              Microsoft Windows XP Édition familiale Service Pack 3
              System drive C: has 106 GB (70%) free of 153 GB
              Total RAM: 767 MB (46% free)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 15:05:44, on 10/10/2009
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v8.00 (8.00.6001.18702)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir Desktop\sched.exe
              C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
              C:\Program Files\Microsoft LifeCam\MSCamS32.exe
              C:\WINDOWS\system32\nvsvc32.exe
              C:\Program Files\EA Games\Need for Speed Undercover\PB\PnkBstrA.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\wscntfy.exe
              C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
              C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
              C:\WINDOWS\vVX1000.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
              C:\WINDOWS\system32\RUNDLL32.EXE
              C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
              C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
              C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\WINDOWS\system32\wuauclt.exe
              c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Windows Live\Messenger\usnsvc.exe
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\Documents and Settings\Isabelle BROQUEREAU\Local Settings\Temporary Internet Files\Content.IE5\RL8MZG2Y\RSIT[1].exe
              C:\Program Files\trend micro\Isabelle BROQUEREAU.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
              O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
              O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
              O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
              O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
              O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
              O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
              O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
              O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
              O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
              O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
              O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
              O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
              O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - C:\Program Files\EA Games\Need for Speed Undercover\PB\PnkBstrA.exe
              0
          3. Logfile of random's system information tool 1.06 (written by random/random)
            Run by Isabelle BROQUEREAU at 2009-10-10 14:25:09
            Microsoft Windows XP Édition familiale Service Pack 3
            System drive C: has 106 GB (70%) free of 153 GB
            Total RAM: 767 MB (39% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 14:25:20, on 10/10/2009
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v8.00 (8.00.6001.18702)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Avira\AntiVir Desktop\sched.exe
            C:\Program Files\Avira\AntiVir Desktop\avguard.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\Program Files\Microsoft LifeCam\MSCamS32.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\Program Files\EA Games\Need for Speed Undercover\PB\PnkBstrA.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
            C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\WINDOWS\ALCXMNTR.EXE
            C:\WINDOWS\vVX1000.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
            C:\WINDOWS\system32\RUNDLL32.EXE
            C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
            C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
            C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Documents and Settings\Isabelle BROQUEREAU\Local Settings\Temporary Internet Files\Content.IE5\RL8MZG2Y\RSIT[1].exe
            C:\Program Files\trend micro\Isabelle BROQUEREAU.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
            O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
            O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
            O3 - Toolbar: (no name) - {CEDDA62B-5FBE-4AB2-AE2E-5E069F444444} - (no file)
            O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
            O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
            O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
            O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
            O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
            O4 - HKLM\..\Run: [Windows Rundll Center] msnsmgr.exe
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
            O8 - Extra context menu item: Add to AMV Video Converter... - C:\Program Files\MP3 Player Utilities 4.24\AMVConverter\grab.html
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} (JordanUploader Class) - http://photoservice.fujicolor.eu/ips-opdata/objects/jordan.cab
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
            O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
            O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
            O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
            O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - C:\Program Files\EA Games\Need for Speed Undercover\PB\PnkBstrA.exe
            0
            1. Contributeur sécurité
              Refais un log RSIT, on a presque terminé
              0
              1. ========== REGISTRY ==========
                Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\msnsmgr.exe not found.

                OTMoveIt3 by OldTimer - Version 1.0.7.0 log created on 10102009_142054
                0
                1. Contributeur sécurité
                  -+-+-+-> OTMoveIt <-+-+-+-

                  [x] Double-clique sur OTMoveIt.exe.

                  [x] Assure toi que la case Unregister Dll's and Ocx's soit bien cochée.

                  [x] Copie le texte en gras ci dessous et colle le dans le cadre de gauche de OTMoveIt nommé Paste List of Files/Folders to be moved



                  :reg
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "msnsmgr.exe"=-



                  [x] Clique sur MoveIt! pour lancer la suppression.

                  [x] Si OTMoveIt propose de redémarrer ton PC, accepte.

                  [x] Lorsque un résultat apparaît dans le cadre Results, clique sur Exit.

                  [x] Dans ta future réponse, envoie le rapport de OTMoveIt situé sous C:\_OTMoveIt\MovedFiles
                  0
                  1. ========================= SF 1.0.0.3 - C_XX | 14:12:11,04

                    Valeur(s) recherchée(s):

                    msnsmgr

                    ========================= Fichier(s)/Dossier(s):

                    "C:\_OTMoveIt\MovedFiles\10102009_135941\WINDOWS\msnsmgr.exe"
                    MD5: e19fbce5b32d4b328bec377b9fdb7be4 | -rahs---- | 09/10/2009 19:22
                    .

                    ========================= Registre:

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "Windows Rundll Center"="msnsmgr.exe"

                    ========================= E.O.F | 14:14:53,65
                    0
                    1. Contributeur sécurité
                      Bien !

                      Refais ceci maintenant :

                      Télécharge SF.exe de C_XX . http://sd-1.archive-host.com/membres/up/16506160323759868/SF.exe

                      *Double clique sur SF.exe ("éxécuter en tant qu'administrateur pour vista) .

                      *Une fenetre Cmd va s'ouvrir .

                      *Tape msnsmgr dans cette fenetre et "entrée" .

                      *Patiente pendant la recherche .

                      *Une fenetre avec un log .txt va s'afficher .

                      *Copie/colle ce rapport dans ta prochaine réponse .
                      0
                      1. Contributeur sécurité
                        -+-+-+-> USBfix - Nettoyage <-+-+-+-

                        [x] Relance USBfix mais cette fois ci choisis l'option 2

                        /!\ N'oublie pas de laisser tes médias amovibles branchés sur ton PC /!\

                        [x] Patiente pendant que l'outil travaille.

                        [x] Ton PC redémarrera, puis USBfix analysera tes médias amovibles.

                        [x] Poste le rapport situé sous C:\USBfix.txt

                        -+-+-+-> OTMoveIt <-+-+-+-

                        [x] Télécharge OTMoveIt (de Old_Timer) à cette adresse : https://www.luanagames.com/index.fr.html sur ton Bureau.

                        [x] Double-clique sur OTMoveIt.exe.

                        [x] Assure toi que la case Unregister Dll's and Ocx's soit bien cochée.

                        [x] Copie le texte en gras ci dessous et colle le dans le cadre de gauche de OTMoveIt nommé Paste List of Files/Folders to be moved


                        :processes
                        explorer.exe

                        :reg
                        [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
                        "C:\WINDOWS\msnsmgr.exe"=-

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "Windows Rundll Center"=-

                        :files
                        C:\WINDOWS\msnsmgr.exe

                        :commands
                        [emptytemp]
                        [purity]
                        [start explorer]



                        [x] Clique sur MoveIt! pour lancer la suppression.

                        [x] Si OTMoveIt propose de redémarrer ton PC, accepte.

                        [x] Lorsque un résultat apparaît dans le cadre Results, clique sur Exit.

                        [x] Dans ta future réponse, envoie le rapport de OTMoveIt situé sous C:\_OTMoveIt\MovedFiles
                        0
                        1. ############################## | UsbFix V6.040 |

                          User : Isabelle BROQUEREAU (Administrateurs) # BROQUERE-96ESK2
                          Update on 10/10/2009 by Chiquitine29, C_XX & Chimay8
                          Start at: 13:53:23 | 10/10/2009
                          Website : http://pagesperso-orange.fr/NosTools/index.html

                          AMD Athlon(tm) XP 2600+
                          Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                          Internet Explorer 8.0.6001.18702
                          Windows Firewall Status : Enabled
                          AV : AntiVir Desktop 9.0.1.26 [ (!) Disabled | (!) Outdated ]
                          AV : avast! antivirus 4.8.1351 [VPS 091009-0] 4.8.1351 [ Enabled | Updated ]

                          A:\ -> Lecteur de disquettes 3 ½ pouces
                          C:\ -> Disque fixe local # 149,04 Go (103,59 Go free) [Disque dur] # NTFS
                          D:\ -> Disque amovible
                          E:\ -> Disque amovible
                          F:\ -> Disque amovible
                          G:\ -> Disque amovible
                          H:\ -> Disque CD-ROM
                          I:\ -> Disque CD-ROM

                          ############################## | Processus actifs |

                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\logonui.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Alwil Software\Avast4\setup\avast.setup
                          C:\Program Files\Avira\AntiVir Desktop\sched.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                          C:\Program Files\Microsoft LifeCam\MSCamS32.exe
                          C:\WINDOWS\system32\nvsvc32.exe
                          C:\Program Files\EA Games\Need for Speed Undercover\PB\PnkBstrA.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\WINDOWS\system32\wbem\wmiprvse.exe
                          C:\WINDOWS\System32\alg.exe

                          ################## | Fichiers # Dossiers infectieux |

                          ################## | Registre # Clés Run infectieuses |

                          ################## | Registre # Mountpoints2 |

                          Supprimé ! HKCU\...\Explorer\MountPoints2\J\Shell\AutoRun\Command
                          Supprimé ! HKCU\...\Explorer\MountPoints2\{064d94b7-b3a2-11dc-a6f3-0007cb0000ff}\Shell\Auto\Command
                          Supprimé ! HKCU\...\Explorer\MountPoints2\{0863f5bc-df28-11dd-a88d-0007cb0000ff}\Shell\AutoRun\Command
                          Supprimé ! HKCU\...\Explorer\MountPoints2\{7082dbda-8169-11dd-a81d-0007cb0000ff}\Shell\Auto\Command

                          ################## | Listing des fichiers présent |

                          [10/10/2009 13:22|--a------|4253] C:\Ad-Report-CLEAN[1].log
                          [10/10/2009 13:09|--a------|3713] C:\Ad-Report-SCAN[1].log
                          [18/12/2007 19:31|--a------|0] C:\AUTOEXEC.BAT
                          [19/12/2007 19:58|-rahs----|216] C:\boot.ini
                          [30/08/2002 14:00|-rahs----|4952] C:\Bootfont.bin
                          [10/10/2009 11:58|--a------|1541] C:\cleannavi.txt
                          [18/12/2007 19:31|--a------|0] C:\CONFIG.SYS
                          [10/10/2009 12:11|--a------|94644] C:\hpfr5700.log
                          [07/01/2009 19:32|--a------|921624] C:\img2-001.raw
                          [18/12/2007 19:31|-rahs----|0] C:\IO.SYS
                          [26/12/2007 12:12|--a------|2784] C:\LGSInst.Log
                          [18/12/2007 19:31|-rahs----|0] C:\MSDOS.SYS
                          [09/10/2009 22:50|--a------|117] C:\MSNCleaner.txt
                          [12/04/2004 17:17|--a------|77824] C:\NetAgent.dll
                          [19/12/2007 19:54|-rahs----|47564] C:\NTDETECT.COM
                          [27/09/2008 12:05|-rahs----|252240] C:\ntldr
                          [?|?|?] C:\pagefile.sys
                          [18/12/2007 23:29|--a------|18620376] C:\setupfre.exe
                          [10/10/2009 13:43|--a------|710] C:\SFlog.txt
                          [08/06/2009 15:54|--ah-----|268] C:\sqmdata00.sqm
                          [10/06/2009 22:18|--ah-----|268] C:\sqmdata01.sqm
                          [15/06/2009 10:47|--ah-----|268] C:\sqmdata02.sqm
                          [18/06/2009 11:58|--ah-----|268] C:\sqmdata03.sqm
                          [23/06/2009 15:47|--ah-----|268] C:\sqmdata04.sqm
                          [25/06/2009 20:05|--ah-----|268] C:\sqmdata05.sqm
                          [30/06/2009 11:41|--ah-----|268] C:\sqmdata06.sqm
                          [01/07/2009 16:11|--ah-----|268] C:\sqmdata07.sqm
                          [03/07/2009 11:01|--ah-----|268] C:\sqmdata08.sqm
                          [05/08/2009 18:18|--ah-----|268] C:\sqmdata09.sqm
                          [07/08/2009 10:58|--ah-----|268] C:\sqmdata10.sqm
                          [08/08/2009 11:48|--ah-----|268] C:\sqmdata11.sqm
                          [28/08/2009 22:30|--ah-----|268] C:\sqmdata12.sqm
                          [06/09/2009 20:11|--ah-----|268] C:\sqmdata13.sqm
                          [20/09/2009 22:51|--ah-----|268] C:\sqmdata14.sqm
                          [21/09/2009 09:59|--ah-----|268] C:\sqmdata15.sqm
                          [25/09/2009 10:34|--ah-----|268] C:\sqmdata16.sqm
                          [30/09/2009 21:45|--ah-----|268] C:\sqmdata17.sqm
                          [04/10/2009 20:20|--ah-----|268] C:\sqmdata18.sqm
                          [03/06/2009 22:26|--ah-----|268] C:\sqmdata19.sqm
                          [08/06/2009 15:54|--ah-----|244] C:\sqmnoopt00.sqm
                          [10/06/2009 22:18|--ah-----|244] C:\sqmnoopt01.sqm
                          [15/06/2009 10:47|--ah-----|244] C:\sqmnoopt02.sqm
                          [18/06/2009 11:58|--ah-----|244] C:\sqmnoopt03.sqm
                          [23/06/2009 15:47|--ah-----|244] C:\sqmnoopt04.sqm
                          [25/06/2009 20:05|--ah-----|244] C:\sqmnoopt05.sqm
                          [30/06/2009 11:41|--ah-----|244] C:\sqmnoopt06.sqm
                          [01/07/2009 16:11|--ah-----|244] C:\sqmnoopt07.sqm
                          [03/07/2009 11:01|--ah-----|244] C:\sqmnoopt08.sqm
                          [05/08/2009 18:18|--ah-----|244] C:\sqmnoopt09.sqm
                          [07/08/2009 10:58|--ah-----|244] C:\sqmnoopt10.sqm
                          [08/08/2009 11:48|--ah-----|244] C:\sqmnoopt11.sqm
                          [28/08/2009 22:30|--ah-----|244] C:\sqmnoopt12.sqm
                          [06/09/2009 20:11|--ah-----|244] C:\sqmnoopt13.sqm
                          [20/09/2009 22:51|--ah-----|244] C:\sqmnoopt14.sqm
                          [21/09/2009 09:59|--ah-----|244] C:\sqmnoopt15.sqm
                          [25/09/2009 10:34|--ah-----|244] C:\sqmnoopt16.sqm
                          [30/09/2009 21:45|--ah-----|244] C:\sqmnoopt17.sqm
                          [04/10/2009 20:20|--ah-----|244] C:\sqmnoopt18.sqm
                          [03/06/2009 22:25|--ah-----|244] C:\sqmnoopt19.sqm
                          [27/05/2009 11:20|--a------|536] C:\updatedatfix.log
                          [10/10/2009 13:57|--a------|5782] C:\UsbFix.txt

                          ################## | Vaccination |

                          # C:\autorun.inf -> Folder created by UsbFix.

                          ################## | ! Fin du rapport # UsbFix V6.040 ! |

                          ========== PROCESSES ==========
                          Process explorer.exe killed successfully.
                          ========== REGISTRY ==========
                          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\\C:\WINDOWS\msnsmgr.exe deleted successfully.
                          Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Windows Rundll Center not found.
                          ========== FILES ==========
                          C:\WINDOWS\msnsmgr.exe moved successfully.
                          ========== COMMANDS ==========
                          User's Temp folder emptied.
                          User's Temporary Internet Files folder emptied.
                          User's Internet Explorer cache folder emptied.
                          Local Service Temp folder emptied.
                          File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                          Local Service Temporary Internet Files folder emptied.
                          File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
                          File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5d0.dat scheduled to be deleted on reboot.
                          Windows Temp folder emptied.
                          Temp folders emptied.
                          Explorer started successfully

                          OTMoveIt3 by OldTimer - Version 1.0.7.0 log created on 10102009_135941

                          Files moved on Reboot...
                          C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat moved successfully.
                          File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
                          File C:\WINDOWS\temp\Perflib_Perfdata_5d0.dat not found!
                          0
                      • 1
                      • 2
                      • 3