Mon virus MSN persiste

Bonjour,
Voilà malgré avast puis antivir et spybot j'ai toujours mon virus sur MSN qui s'envoie automatiquement à tous mes correspondants. J'entends parler de SDFIX, MSNFIX mais j'aimerais bien qu'on me guide surtout pour analyser mes rapports. Si quelqu'un peut m'aider svp... Merci d'avance.
Configuration: Windows XP
Internet Explorer 6.0

10 réponses

  1. Contributeur sécurité
    Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

    _____________

    Mettre a jour java:
    https://www.malekal.com/maintenir-java-adobe-reader-et-le-player-flash-a-jour/
    _______________

    AVG antispyware
    https://www.01net.com/telecharger/
    http://free.grisoft.com/doc/download-free-anti-spyware/us/frt/0

    Tuto :
    http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html

    ->Relance AVG AS -> "Analyse" ->"Paramètres"

    Sous la question "Comment réagir ?" :

    -> clique sur "Actions recommandées" et choisis "Quarantaines"
    -> Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"

    Si un fichier est infecté en fin d'analyse

    ->Clique sur "Appliquer toutes les actions "

    ->Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous".

    ->Enregistre ce fichier texte sur ton bureau ensuite colle le rapport ici
    0
    1. coucou mon rapport hijack this est bon ? Je n'ose pas me reconnecter sur MSN au cas où... Merci pour votre réponse.
      0
      1. y-a-t-il quelque chose d'anormal dans mon rapport hijack this ? Merci d'avance.
        0
        1. Contributeur sécurité
          recolle un hijakchits pour verifier
          0
          1. voici mon nouveau rapport hijack this

            qu'en est-il ?

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 17:50:23, on 30/03/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16608)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\SYSTEM32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            C:\WINDOWS\SYSTEM32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
            C:\WINDOWS\system32\drivers\CDAC11BA.EXE
            c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
            C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\SearchIndexer.exe
            c:\APPS\Powercinema\Kernel\TV\CLSched.exe
            C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
            C:\WINDOWS\SOUNDMAN.EXE
            C:\WINDOWS\ALCWZRD.EXE
            C:\Apps\Powercinema\PCMService.exe
            C:\apps\ABoard\ABoard.exe
            C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe
            C:\WINDOWS\system32\LVCOMSX.EXE
            C:\apps\ABoard\AOSD.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
            C:\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
            C:\Program Files\Microsoft IntelliPoint\ipoint.exe
            C:\Program Files\Logitech\Video\LogiTray.exe
            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
            C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
            C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\Program Files\Windows Desktop Search\WindowsSearch.exe
            C:\Program Files\Logitech\Video\FxSvr2.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Documents and Settings\Nat\Bureau\eden.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
            O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
            O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
            O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
            O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
            O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
            O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
            O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
            O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
            O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
            O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe
            O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
            O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
            O4 - HKLM\..\Run: [ATIPTA] C:\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
            O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
            O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
            O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
            O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
            O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
            O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
            O8 - Extra context menu item: &Search - ?p=ZC
            O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
            O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
            O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra button: Allocam Multi Vision - {2D6B57BF-71FA-41A3-BDC5-3B5A25813D2E} - C:\PROGRA~1\ALLOCA~1\allocam.exe (file missing) (HKCU)
            O9 - Extra 'Tools' menuitem: Allocam Multi Vision - {2D6B57BF-71FA-41A3-BDC5-3B5A25813D2E} - C:\PROGRA~1\ALLOCA~1\allocam.exe (file missing) (HKCU)
            O12 - Plugin for .tif: C:\Program Files\Internet Explorer\Plugins\npzzatif.dll
            O12 - Plugin for .tiff: C:\Program Files\Internet Explorer\Plugins\npzzatif.dll
            O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
            O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
            O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
            O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
            O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
            O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
            O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
            O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://www.msnjeux.com/online2/MSN_INTL_FRANCE/insaniquarium/zylomgamesplayer.cab
            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
            O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
            O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
            O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
            O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
            O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
            O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
            0
        2. puis-je me reconnecter maintenant, est-ce que mon virus est enlevé ? Si quelqu'un peut me donner une réponse svp...
          0
          1. coucou tu es toujours là jlpjlp ? Que dois-je faire maintenant est-ce que mon problème est résolu ? Merci d'avance pour ta réponse...
            0
            1. tu es toujours là jlpjlp ? Est-ce qu'il y a autre chose à faire ou mon virus est parti ?
              0
              1. coucou est-ce quelqu'un peut m'aider et me dire si mon virus et parti ? Je n'ose pas me reconnecter je ne sais pas si je dois faire d'autres manipulations avant. Merci beaucoup d'avance
                0
            2. Contributeur sécurité
              parfait
              mets a jour internet explorer:
              https://www.01net.com/telecharger/windows/Internet/navigateur/fiches/33081.html

              _____________

              si tout c'est bien passé désactive la restauration système pour purger les virus qui seraient dedans puis réactive là : https://www.informatruc.com

              ______________

              colle un rapport antivir et dis tes soucis
              0
              1. coucou me revoilà, j'ai désactivé et réactivé la restauration du système et voilà mon rapport antivir, que dois-je faire maintenant ?

                AntiVir PersonalEdition Classic
                Report file date: dimanche 30 mars 2008 15:33

                Scanning for 1169688 virus strains and unwanted programs.

                Licensed to: Avira AntiVir PersonalEdition Classic
                Serial number: 0000149996-ADJIE-0001
                Platform: Windows XP
                Windows version: (Service Pack 2) [5.1.2600]
                Username: Nat
                Computer name: NATHALIE

                Version information:
                BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
                AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
                LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
                LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
                ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
                ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 16:43:29
                ANTIVIR2.VDF : 7.0.3.85 434176 Bytes 27/03/2008 16:43:29
                ANTIVIR3.VDF : 7.0.3.92 20480 Bytes 28/03/2008 19:40:44
                AVEWIN32.DLL : 7.6.0.78 3408384 Bytes 28/03/2008 16:43:29
                AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
                AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
                AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                AVPACK32.DLL : 7.6.0.3 360488 Bytes 28/03/2008 16:43:29
                AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
                AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
                AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
                NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
                RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
                RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
                SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

                Configuration settings for the scan:
                Jobname..........................: Local Drives
                Configuration file...............: c:\program files\avira\antivir personaledition classic\alldrives.avp
                Logging..........................: low
                Primary action...................: interactive
                Secondary action.................: ignore
                Scan master boot sector..........: off
                Scan boot sector.................: on
                Boot sectors.....................: D:,
                Scan memory......................: on
                Process scan.....................: on
                Scan registry....................: on
                Search for rootkits..............: off
                Scan all files...................: Intelligent file selection
                Scan archives....................: on
                Recursion depth..................: 20
                Smart extensions.................: on
                Macro heuristic..................: on
                File heuristic...................: medium

                Start of the scan: dimanche 30 mars 2008 15:33

                The scan of running processes will be started
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                Scan process 'hpqste08.exe' - '1' Module(s) have been scanned
                Scan process 'searchfilterhost.exe' - '1' Module(s) have been scanned
                Scan process 'searchprotocolhost.exe' - '1' Module(s) have been scanned
                Scan process 'FxSvr2.exe' - '1' Module(s) have been scanned
                Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                Scan process 'WindowsSearch.exe' - '1' Module(s) have been scanned
                Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
                Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                Scan process 'backWeb-8876480.exe' - '1' Module(s) have been scanned
                Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                Scan process 'realsched.exe' - '1' Module(s) have been scanned
                Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
                Scan process 'LogiTray.exe' - '1' Module(s) have been scanned
                Scan process 'ipoint.exe' - '1' Module(s) have been scanned
                Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
                Scan process 'apdproxy.exe' - '1' Module(s) have been scanned
                Scan process 'qttask.exe' - '1' Module(s) have been scanned
                Scan process 'AOSD.EXE' - '1' Module(s) have been scanned
                Scan process 'LVCOMSX.EXE' - '1' Module(s) have been scanned
                Scan process 'MotiveSB.exe' - '1' Module(s) have been scanned
                Scan process 'ABOARD.EXE' - '1' Module(s) have been scanned
                Scan process 'PCMService.exe' - '1' Module(s) have been scanned
                Scan process 'ALCWZRD.EXE' - '1' Module(s) have been scanned
                Scan process 'SOUNDMAN.EXE' - '1' Module(s) have been scanned
                Scan process 'jusched.exe' - '1' Module(s) have been scanned
                Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
                Scan process 'alg.exe' - '1' Module(s) have been scanned
                Scan process 'CLSched.exe' - '1' Module(s) have been scanned
                Scan process 'searchindexer.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'CLMLService.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'CLMLServer.exe' - '1' Module(s) have been scanned
                Scan process 'CLCapSvc.exe' - '1' Module(s) have been scanned
                Scan process 'CDAC11BA.EXE' - '1' Module(s) have been scanned
                Scan process 'AOLacsd.exe' - '1' Module(s) have been scanned
                Scan process 'sched.exe' - '1' Module(s) have been scanned
                Scan process 'explorer.exe' - '1' Module(s) have been scanned
                Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                Scan process 'avguard.exe' - '1' Module(s) have been scanned
                Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                Scan process 'lsass.exe' - '1' Module(s) have been scanned
                Scan process 'services.exe' - '1' Module(s) have been scanned
                Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'smss.exe' - '1' Module(s) have been scanned
                57 processes with 57 modules were scanned

                Start scanning boot sectors:
                Boot sector 'C:\'
                [NOTE] No virus was found!
                Boot sector 'E:\'
                [NOTE] In the drive 'E:\' no data medium is inserted!
                Boot sector 'F:\'
                [NOTE] In the drive 'F:\' no data medium is inserted!
                Boot sector 'G:\'
                [NOTE] In the drive 'G:\' no data medium is inserted!
                Boot sector 'H:\'
                [NOTE] In the drive 'H:\' no data medium is inserted!

                Starting to scan the registry.
                The registry was scanned ( '50' files ).

                Starting the file scan:

                Begin scan in 'C:\' <HDD>
                C:\hiberfil.sys
                [WARNING] The file could not be opened!
                C:\pagefile.sys
                [WARNING] The file could not be opened!
                C:\Documents and Settings\Nat\Bureau\catchme.zip
                [0] Archive type: ZIP
                --> ^^^^^.exe
                [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                --> ^^^^^.exe.1
                [DETECTION] Is the Trojan horse TR/Trash.Gen
                [INFO] The file was moved to '48639a66.qua'!
                Begin scan in 'E:\'
                Search path E:\ could not be opened!
                Le périphérique n'est pas prêt.

                Begin scan in 'F:\'
                Search path F:\ could not be opened!
                Le périphérique n'est pas prêt.

                Begin scan in 'G:\'
                Search path G:\ could not be opened!
                Le périphérique n'est pas prêt.

                Begin scan in 'H:\'
                Search path H:\ could not be opened!
                Le périphérique n'est pas prêt.

                Begin scan in 'D:\'
                Search path D:\ could not be opened!
                Le périphérique n'est pas prêt.

                End of the scan: dimanche 30 mars 2008 16:20
                Used time: 47:26 min

                The scan has been done completely.

                10784 Scanning directories
                278143 Files were scanned
                2 viruses and/or unwanted programs were found
                0 Files were classified as suspicious:
                0 files were deleted
                0 files were repaired
                1 files were moved to quarantine
                0 files were renamed
                2 Files cannot be scanned
                278141 Files not concerned
                8439 Archives were scanned
                2 Warnings
                0 Notes
                0
            3. Contributeur sécurité
              ok poursuis

              a plus
              0
              1. coucou, voilà mon scan malwarebytes

                Malwarebytes' Anti-Malware 1.09
                Version de la base de données: 568

                Type de recherche: Examen complet (C:\|E:\|F:\|G:\|H:\|)
                Eléments examinés: 191437
                Temps écoulé: 55 minute(s), 36 second(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 0
                Clé(s) du Registre infectée(s): 12
                Valeur(s) du Registre infectée(s): 0
                Elément(s) de données du Registre infecté(s): 0
                Dossier(s) infecté(s): 1
                Fichier(s) infecté(s): 40

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Clé(s) du Registre infectée(s):
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{90b5a95a-afd5-4d11-b9bd-a69d53d22226} (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8109fd3d-d891-4f80-8339-50a4913ace6f} (Adware.Zango) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a6573479-9075-4a65-98a6-19fd29cf7374} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\Software\BndDrive (Trojan.Adware) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

                Valeur(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Elément(s) de données du Registre infecté(s):
                (Aucun élément nuisible détecté)

                Dossier(s) infecté(s):
                C:\Program Files\Words (Adware.Rond) -> Quarantined and deleted successfully.

                Fichier(s) infecté(s):
                C:\Program Files\MSN Messenger\riched20.dll (Adware.MyWeb.FunWeb) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP684\snapshot\MFEX-1.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184301.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184302.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184304.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184305.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184306.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184307.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184309.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184310.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184311.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184312.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184313.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184314.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184315.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184316.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184317.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184318.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184319.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184320.DLL (Adware.MyWeb.FunWeb) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184321.EXE (Adware.MyWeb.FunWeb) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184322.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184323.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184324.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184326.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184327.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184328.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184329.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184331.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184332.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184333.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184334.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184335.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184336.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP696\A0184337.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP706\A0185805.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP706\A0185871.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Program Files\Words\list.txt (Adware.Rond) -> Quarantined and deleted successfully.
                C:\Program Files\Words\script.txt (Adware.Rond) -> Quarantined and deleted successfully.
                C:\Documents and Settings\All Users\Menu Démarrer\carlton (Dialer) -> Quarantined and deleted successfully.
                0
              2. @ludovic37et voilà mon rapport hijack this

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 14:25:37, on 30/03/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\SYSTEM32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                C:\WINDOWS\SYSTEM32\Ati2evxx.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\SearchIndexer.exe
                c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                C:\WINDOWS\SYSTEM32\notepad.exe
                C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
                C:\WINDOWS\SOUNDMAN.EXE
                C:\WINDOWS\ALCWZRD.EXE
                C:\Apps\Powercinema\PCMService.exe
                C:\apps\ABoard\ABoard.exe
                C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe
                C:\WINDOWS\system32\LVCOMSX.EXE
                C:\Program Files\QuickTime\qttask.exe
                C:\apps\ABoard\AOSD.exe
                C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                C:\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
                C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                C:\Program Files\Logitech\Video\LogiTray.exe
                C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
                C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                C:\Program Files\Logitech\Video\FxSvr2.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                C:\WINDOWS\system32\NOTEPAD.EXE
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                C:\WINDOWS\system32\SearchProtocolHost.exe
                C:\Documents and Settings\Nat\Bureau\eden.exe

                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer par NUMERICABLE
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
                O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
                O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
                O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
                O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
                O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
                O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe
                O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                O4 - HKLM\..\Run: [ATIPTA] C:\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
                O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
                O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                O8 - Extra context menu item: &Search - ?p=ZC
                O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
                O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra button: Allocam Multi Vision - {2D6B57BF-71FA-41A3-BDC5-3B5A25813D2E} - C:\PROGRA~1\ALLOCA~1\allocam.exe (file missing) (HKCU)
                O9 - Extra 'Tools' menuitem: Allocam Multi Vision - {2D6B57BF-71FA-41A3-BDC5-3B5A25813D2E} - C:\PROGRA~1\ALLOCA~1\allocam.exe (file missing) (HKCU)
                O12 - Plugin for .tif: C:\Program Files\Internet Explorer\Plugins\npzzatif.dll
                O12 - Plugin for .tiff: C:\Program Files\Internet Explorer\Plugins\npzzatif.dll
                O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
                O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://www.msnjeux.com/online2/MSN_INTL_FRANCE/insaniquarium/zylomgamesplayer.cab
                O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
                O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
                0
            4. Contributeur sécurité
              slt,

              Télécharge MSNFix de Laurent
              http://sosvirus.changelog.fr/MSNFix.zip

              Décompresse-le et double clic sur le fichier MSNFix.bat.
              - Exécute l'option R.
              --Si l'infection est détectée, exécute l'option N
              - Sauvegarde ce rapport puis fais un copier/coller de ce rapport sur le forum.

              Note :
              Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal
              Sauvegarder et fermer le rapport pour que Windows termine de se lancer normalement.

              envoyer le fichier [b] C:\DOCUME~1\florian\Bureau\Upload_Me.zip [/b] sur http://upload.changelog.fr pour faire evoluer msnfix

              ______________

              scan avec
              MalwareByte's Anti-Malware et vire ce qui est trouvé et colle le rapport

              https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

              ______________

              colle un rapport hijackthis

              http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

              manuel :
              http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
              https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

              Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

              ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

              Ensuite avec Explorer créer un dossier c:\hijackthis
              Décompresser Hijackthis dans ce dossier.
              C'est important pour les sauvegardes."
              0
              1. voilà déjà mon rapport MSNfix

                MSNFix 1.693

                C:\Documents and Settings\Nat\Bureau\MSNFix
                Fix exécuté le 30/03/2008 - 12:58:01,50 By Nat
                mode normal

                ************************ Recherche les fichiers présents

                ... C:\WINDOWS\system32\^^^^^.exe
                ... C:\WINDOWS\system32\real.txt

                ************************ Recherche les dossiers présents

                Aucun dossier trouvé

                ************************ Suppression des fichiers

                /!\ ... C:\WINDOWS\system32\^^^^^.exe
                .. OK ... C:\WINDOWS\system32\^^.exe
                /!\ ... C:\WINDOWS\system32\^^^^^.exe
                /!\ ... C:\WINDOWS\system32\real.txt

                ************************ Nettoyage du registre

                Les fichiers encore présents seront supprimés au prochain redémarrage

                ************************ Suppression des fichiers

                .. OK ... C:\WINDOWS\system32\real.txt

                ************************ Fichiers suspects

                Aucun Fichier trouvé

                Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 30032008_13021610.zip

                ************************ HKLM\...\Winlogon\Userinit

                Userinit = C:\WINDOWS\system32\userinit.exe,

                ------------------------------------------------------------------------
                Auteur : !aur3n7 Contact: https://www.ionos.fr/
                ------------------------------------------------------------------------

                --------------------------------------------- END ---------------------------------------------
                0