Virus MSN

Bonjour,
ma fille a chopper un trojant sur MSN je n'arrive pas a le virer MSNfix avast hitachit bit defender rien ny fait que fair meme plus de connection internet live box aux secour merci de m'aider car je peux suivre que d'un autre poste car celui infecter plus possible de fair quoi que ce soit et meme maintenent windows 32 exe s'affiche que fair??????????
Configuration: Windows XP
Firefox 2.0.0.13

28 réponses

Résumé de la discussion

Une infection par trojan est signalée sur Windows XP avec affichage récurrent de rundll32.exe et perte partielle de connexion Internet, nécessitant l'identification et la suppression des éléments malveillants. Plusieurs outils antivirus et anti-spyware ont été évoqués, notamment Avast et BitDefender, mais les journaux HijackThis et les processus suspects montrent des entrées multiples dans Run et les services système. Des éléments repérés incluent des barres d'outils et des modules DLL liés à Yahoo!, Google et SweetIM, ainsi que des services et tâches planifiées, nécessitant une purge simultanée des programmes indésirables. D'autres mesures utiles incluent l'exécution en mode sécurisé, la suppression manuelle des entrées suspectes dans le registre et l'utilisation d'un outil de restauration système après nettoyage.

Bobot (l’IA à votre service)
  1. Re,
    ok alors fais ceci stp :
    > Fais une récupération système : Tu as besoin du CD Windows pour cela.
    - Redémarre ton PC puis accède au BIOS (Pour accéder au BIOS il faut appuyer sur F1 au démarrage du PC).
    Tuto : http://cofofides.heberg-forum.net/ftopic37_tutoriel-sur-le-bios-theorique.html
    Regarde surtout ici : http://cofofides.heberg-forum.net/sutra96_tutoriel-bios-theorique.html#96
    - Il faut que tu choisisses CDROM en première séquence de boot.
    - Relance alors ton PC avec le CDRom Windows déjà dans le lecteur.
    => Windows Install se lance. Choisis ensuite réparer windows.
    Tuto : http://www.cybersolus.net/windows/windows_xp/console/cd_console.html
    Résumé : Boot CD => récupération de XP => c:\chkdsk (sous l'invite dos : c:\)

    Dis moi où tu rencontres des problèmes sinon.

    Puis,
    désinstalle SweetIm qui est souces de cochonneries :

    "If you choose to use the SweetIM Software or the Services, you may be exposed to a variety of risks such as : (i) unauthorized invasion of your privacy during, or as a result of, your or another's use of the Service (ii) unauthorized exposure of information and material posted by you or others on or through the Services. (iii) potential exposure to objectionable material and/or parties, such as content and messages that may offend and which may contain contaminated files.,(iv) spoofing, eavesdropping, sniffing, spamming, breaking passwords, harassment, fraud, forgery, "imposturing", electronic trespassing, tampering, hacking, nuking, system contamination including without limitation use of viruses, worms and Trojan horses causing unauthorized, damaging or harmful access and/or retrieval of information and data on your computer and other forms of activity that may even be illegal."


    A+
    0
    1. et si tu as pas le CD tu est dans la merde c'est ça ??????
      0
    2. @croutillouxSalut,
      Mmmm..oui...c'est un peu ça....

      En fait, dis moi pourquoi tu n'as pas le CD, on va trouver une solution....
      Est-ce parce que tu ne l'as pas eu avec ton PC ? Si oui, c'est quoi comme marque et comme modèle ?

      A+
      0
  2. Re,
    ok alors fais ceci stp :
    > Télécharge Zeb-Restore : http://telechargement.zebulon.fr/zeb-restore.html
    - Mets le dans un dossier, sur ton bureau par exemple.
    - Lance Zebrestore et coche la/les case(s) suivante(s) :

    Panneau de configuration
    Ajout/Suppression de programmes

    - Ne coche que la/les case(s) indiquée(s).
    - Clique sur le bouton Restaurer.
    - Quitte le programme puis renvoie un log HiJack,

    toujour le message windows 32 exe,
    quel est-il exactement ?

    je n'arrive pas a allez dans mes parametres, c'est bien le panneau de configuration dont tu parles.

    Essaye de m'expliquer un maximum stp (sans m'envoyer un roman...;)))

    A+
    0
    1. panneau de configuration

      windows ne trouve pas :/windows/systeme32/rundll32.exe.vérifiez que le non correctement et essayer à nouveau.pour rechercher un fichier cliquer sur le bouton demarer puis sur rechercher

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 15:52:39, on 13/04/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16640)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
      C:\Program Files\Controle Parental\bin\optproxy.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\Mixer.exe
      C:\Program Files\Lexmark 3400 Series\lxcymon.exe
      C:\Program Files\Lexmark 3400 Series\ezprint.exe
      C:\WINDOWS\system32\lxcycoms.exe
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
      C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
      C:\PROGRA~1\Wanadoo\ComComp.exe
      C:\PROGRA~1\Wanadoo\Toaster.exe
      C:\PROGRA~1\Wanadoo\Inactivity.exe
      C:\PROGRA~1\Wanadoo\PollingModule.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\PROGRA~1\Wanadoo\Watch.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
      O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
      O4 - HKLM\..\Run: [lxcymon.exe] "C:\Program Files\Lexmark 3400 Series\lxcymon.exe"
      O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 3400 Series\ezprint.exe"
      O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
      O4 - HKLM\..\Run: [LXCYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?81e3966d696a49f8be87436af68475c9
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?81e3966d696a49f8be87436af68475c9
      O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
      O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
      O23 - Service: lxcy_device - - C:\WINDOWS\system32\lxcycoms.exe
      O23 - Service: Control Parental (OPTENET_FILTER) - Contrôle Parental - C:\Program Files\Controle Parental\bin\optproxy.exe
      0
  3. Bonjour,
    Ok, très bien.

    Si tu n'as plus de problème alors bonne continuation.

    A+
    0
    1. sisi toujour le message windows 32 exe et je n'arrive pas a allez dans mes parametres
      0
  4. Bonsoir,
    Ok super,
    alors on termine :
    > Peux-tu vérifier ta console JAVA ici : https://www.java.com/fr/download/uninstalltool.jsp, et installer la nouvelle version au besoin (dans ce cas désinstalle avant l'ancienne version). Dis moi ce qu'il en est stp.
    Pour info. ou en cas de problème : http://assiste.com.free.fr/p/abc/c/anti_java.html

    > Mets à jour Acrobat si ce n'est pas le cas (désinstalle avant la version antérieure) : https://get2.adobe.com/reader/otherversions/

    > Télécharge ToolsCleaner : https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/ sur ton bureau.
    - Clique sur Recherche et laisse le scan agir ...
    - Clique sur Suppression pour finaliser (tu peux, si tu le souhaites, te servir des Options facultatives)
    - Clique sur Quitter pour obtenir le rapport et poste le dans ta réponse (TCleaner.txt se trouve à la racine de ton disque dur (C:\)).
    - Supprime ToolsCleaner ensuite.

    > Télécharge et installe Easy Cleaner stp : https://www.01net.com/telecharger/windows/Utilitaire/registre/fiches/8351.html
    (lien miroir : https://www.clubic.com/telecharger-fiche11170-easycleaner.html )
    - Lance le programme puis clique sur <Registre> puis sur <Trouver>.
    - A la fin du scan clique sur <Supprime tout> puis confirme par <Oui> puis quitte le programme.
    Si besoin tuto ici : https://www.pcparadise.fr
    et http://www.6ma.fr/tuto/easycleaner-nettoyer-windows-des-elements-obsoletes/

    > Tu peux aussi vider ta corbeille.

    > Désactive et réactive la restauration de système, pour cela : suis les instructions de ce lien : http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20020830101856924

    > Passe un coup d'AGV et de Ccleaner de temps en temps (1 fois par semaine à 1 fois par mois, suivant l'utilisation que tu fais de ton PC). Utilise aussi tes autres logiciels de protection (scannes antivirus, antispywares...). N'oublie pas de faire les mises à jour avant de les utiliser. Pense aussi à faire une défragmentation de tes disques durs de temps en temps (garde suffisamment d'espace sur C:\ (1/3 de libre pour être alaise))
    Rappel des liens :
    - http://www.commentcamarche.net/telecharger/telecharger 218 avg anti spyware
    - https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

    > Pour bien protéger ton PC :
    [1 seul Antivirus] + [1 seul Pare feu] + [Quelques Antispywares] + [Mises à Jour récentes Windows et Logiciels de Protection] + [Utilisation de Firefox -ou autres- (Internet Explorer présente des failles de sécurité qui mettent longtemps avant d'être corrigées mais il faut absolument le conserver pour les mises à jour Windows)] + [Utilisation du PC en mode Invité (= limité). Lors d'une infection en mode administrateur le PC est beaucoup plus vulnérable. Voir ICI]

    > Quelques liens utiles :
    - http://www.commentcamarche.net/faq/sujet 2432 securite proteger un ordinateur contre les malwares d internet
    - https://sebsauvage.net/safehex.html
    - https://www.zebulon.fr/telechargements/securite/protection-donnees-personnelles/spywareblaster.html (= petit logiciel qui bloque l'installation d'activ-X nuisibles au PC. Fonctionne en arrière plan)

    Voila,
    Bonne lecture....

    A+
    0
    1. -->- Recherche:

      C:\Qoobox: trouvé !
      C:\_OtMoveIt: trouvé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
      C:\Documents and Settings\oiana\Bureau\HijackThis.lnk: trouvé !
      C:\Program Files\Navilog1: trouvé !
      C:\Program Files\Trend Micro\HijackThis: trouvé !
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !

      ---------------------------------
      -->- Suppression:

      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
      C:\Documents and Settings\oiana\Bureau\HijackThis.lnk: supprimé !
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
      C:\Qoobox: supprimé !
      C:\_OtMoveIt: supprimé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
      C:\Program Files\Navilog1: supprimé !
      C:\Program Files\Trend Micro\HijackThis: supprimé !
      voilla pour ce que tu ma dit par contre je n'arrive pas pour restoration de systeme et pour windoows 32 exe tu quelque chose le message s'affiche toujours???????? en tous cas merci beaucoup
      0
  5. Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 23:47:30, on 12/04/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16640)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\System32\FTRTSVC.exe
    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
    C:\Program Files\Controle Parental\bin\splash.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\Mixer.exe
    C:\Program Files\Lexmark 3400 Series\lxcymon.exe
    C:\Program Files\Lexmark 3400 Series\ezprint.exe
    C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
    C:\WINDOWS\system32\lxcycoms.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
    C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
    C:\PROGRA~1\Wanadoo\ComComp.exe
    C:\PROGRA~1\Wanadoo\Toaster.exe
    C:\PROGRA~1\Wanadoo\Inactivity.exe
    C:\PROGRA~1\Wanadoo\PollingModule.exe
    C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
    C:\PROGRA~1\Wanadoo\Watch.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
    O4 - HKLM\..\Run: [lxcymon.exe] "C:\Program Files\Lexmark 3400 Series\lxcymon.exe"
    O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 3400 Series\ezprint.exe"
    O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
    O4 - HKLM\..\Run: [LXCYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?81e3966d696a49f8be87436af68475c9
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?81e3966d696a49f8be87436af68475c9
    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
    O23 - Service: lxcy_device - - C:\WINDOWS\system32\lxcycoms.exe
    O23 - Service: Control Parental (OPTENET_FILTER) - Contrôle Parental - C:\Program Files\Controle Parental\bin\optproxy.exe
    0
    1. ces bon j'ai trouver attend les rapports merci
      0
      1. comment fait tu pour avoir le rapport du scan en ligne ????? je ne sais pas ou cliqué ?????
        0
        1. OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04112008_230008
          pour celui j'ai un message d'erreur qui arrive ces tous ce que ça me donne désoler pas plus et l'autre l'analyse ce refait mais tous a l'heure pas d'infection
          0
          1. Bonjour,
            Ok, alors quand tu auras posté le rapport Kasper. poste ensuite un nouveau rapport HiJackT stp.

            A+
            0
        2. Ok,
          C'est à moi de te dire Bonne chance !!!!!!!!!!!!!!!!!!!!!!!

          Parce que apparemment tu as du mal...

          Fais ce qu'il y d'inscrit ici : http://www.commentcamarche.net/forum/affich 5709333 virus msn#47

          => Rapport OtMoveIT + Kaspersky à fournir.

          Bonne chance !
          Travaille bien !
          Bon courage !

          Ha Ha Ha !!!
          0
          1. ho merde alors ces quelle etape que j'ai mal fait et sur le scan en ligne aucun virus detecter merci
            0
        3. Re,
          Ok,
          pour ajout/suppression de programmes on verra à la fin.

          La suite,
          > Bon il te faut un pare feu :
          - Je te conseille Kerio : http://www.commentcamarche.net/telecharger/telecharger 206 kerio . Si problème, tuto : https://kerio.probb.fr/
          - Si tu as des difficultés avec les configuration de Kerio, alors installe Zone Alarme : /telecharger/telecharger-157-zonealarm, en cas de problème : http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/zonealarm-tutorial-sujet_169658_1.htm
          - Installe le nouveau pare-feu, puis désactive le pare-feu windows.

          Après,

          > Lance Hijackthis :
          - Puis sélectionne < Scan >
          - Coche les cases des lignes suivantes :

          O4 - HKLM\..\Policies\Explorer\Run: [5E39J1V19L] C:\WINDOWS\whsyst32.exe

          Ensuite,
          - Ferme toutes les autres fenêtres et applications (même internet)
          - Clic sur < fixe checked >

          > Télécharge OTMoveIT (de Old_Timer) : http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe sur ton bureau...
          - Double-clique sur OTMoveIt.exe pour le lancer.
          - Assure toi que la case "Unregister Dll's and Ocx's" est bien cochée !!!
          - Copie le texte qui se trouve ci-dessous et colle-le dans le cadre de gauche de OTMoveIt nommé <Paste standard List of Files/Folders to be moved>.

          C:\WINDOWS\whsyst32.exe

          - Clique sur < MoveIt! > pour lancer la suppression.
          - Lorsqu'un résultat apparaît dans le cadre Results clique sur Exit
          N.B :Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. Accepte en cliquant sur YES.
          Un rapport est créé dans %SYSTEMDRIVE%\_OTMoveIt\MovedFiles\date du jour (C:\_OTMoveIt\MovedFiles\), copie-colle-le dans ta réponse suivante stp.

          > Passe un coup de Ccleaner en mode sans échec stp

          > Relance ton PC en mode normal puis Hijackthis :
          Puis sélectionne < do a system scan and save a logfile >,

          Et envoie, par collier/coller, ton log Hijackthis stp,

          Ensuite,
          > Fais un scan en ligne avec Kaspersky : https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
          - Sous Démonstration en ligne, on t'explique la marche à suivre, et pour lancer le scan il faut sélectionner < Exécuter l'analyse en ligne >.
          Le scan ne marche que sous Internet Explorer.
          - On va te demander de télécharger un contôle active x, accepte .
          - Dans le menu Choisissez la cible de l'analyse, sélectionne Poste de travail. Le scan va commencer.
          - Poste le rapport qui sera généré stp.
          S'il y a un problème, assure toi que les contrôles active x sont bien configurés dans les options internet comme décrit sur ce lien : http://www.inoculer.com/activex.php3
          Rappel : le scan est à faire sous Internet Explorer
          Tuto ici si problème : http://www.vista-xp.fr/forum/topic109.html

          Au travail !
          Bon courage, après on termine.

          A+

          :)
          0
          1. ok alors tous ça je le ferrai demain je pense en attendant je te remercie et surtout ne me lâche pas c'es peux etre que j'ai désactiver le par feu ca ne suffit pas de le réactivé ????? en tous cas merci beaucoup A+ reste avec moi en contact
            0
          2. @croutillouxRe,
            si tu peux très bien le réactiver seulement...pas de soucis...
            Je ne lâche pas mes postes comme cela. T'inquiète.

            :)

            A demain avec tes rapports,
            bonne soirée.
            0
          3. @Utilisateur anonymeok alors attend je n'est pas tous fait met en tous les cas je ne peux pas le réactivé le par feux je te posterai les rapports des que j'aurai fini ne me quitte pas merci A+
            0
          4. @croutillouxBonjour,
            Ok, pas de problème....
            Dis moi quand tu seras prêt.....

            A+
            0
        4. bon voilla toujour pas de ajout et suprim des prog donc voilla le rapport bosse bien et merci
          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 13:41:53, on 07/04/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16574)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          C:\WINDOWS\System32\FTRTSVC.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\Mixer.exe
          C:\Program Files\Lexmark 3400 Series\lxcymon.exe
          C:\Program Files\Lexmark 3400 Series\ezprint.exe
          C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
          C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
          C:\PROGRA~1\Wanadoo\ComComp.exe
          C:\PROGRA~1\Wanadoo\Toaster.exe
          C:\PROGRA~1\Wanadoo\Inactivity.exe
          C:\PROGRA~1\Wanadoo\PollingModule.exe
          C:\WINDOWS\system32\lxcycoms.exe
          C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
          C:\PROGRA~1\Wanadoo\Watch.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
          O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
          O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
          O4 - HKLM\..\Run: [lxcymon.exe] "C:\Program Files\Lexmark 3400 Series\lxcymon.exe"
          O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 3400 Series\ezprint.exe"
          O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
          O4 - HKLM\..\Run: [LXCYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
          O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
          O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
          O4 - HKLM\..\Policies\Explorer\Run: [5E39J1V19L] C:\WINDOWS\whsyst32.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?81e3966d696a49f8be87436af68475c9
          O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?81e3966d696a49f8be87436af68475c9
          O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
          O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: lxcy_device - - C:\WINDOWS\system32\lxcycoms.exe
          O23 - Service: Control Parental (OPTENET_FILTER) - Contrôle Parental - C:\Program Files\Controle Parental\bin\optproxy.exe
          0
          1. Bonjour,
            Ce n'est pas le rapport que je t'ai demandé !

            Il faut un nouveau rapport HiJackT !

            As tu récupérer l'accès au panneau de configuration => ajout/suppression de programmes ?

            A toi de bosser : bon courage.

            A+
            0
            1. Coucou,
              Mais non !!!
              lol
              regarde ici : http://www.commentcamarche.net/forum/affich 5709333 virus msn#33
              Quelqu'un d'autre est arrivé sur ton topik sans dire bonjour ni rien. Ce message lui été adressé (tu te tapes l'incruste....).

              :)

              Ensuite,
              > Télécharge Zeb-Restore : http://telechargement.zebulon.fr/zeb-restore.html
              - Mets le dans un dossier, sur ton bureau par exemple.
              - Lance Zebrestore et coche la/les case(s) suivante(s) :

              Ajout/Suppression de programmes

              - Ne coche que la/les case(s) indiquée(s).
              - Clique sur le bouton Restaurer.
              - Quitte le programme puis renvoie un log HiJack,

              A+
              0
              1. coucou sur le lien que tu ma envoyer ca ne marche pas ten a pas un autre ??? merci
                0
              2. ok voill[Settings]
                Language=Francais

                [Francais]
                LabelReg=RegEdit
                TextReg=restaure les clés/valeurs de la base de registres responsables de la non-opérabilité de l'Editeur du registre. (valeur "DisableRegistryTools" de Policies\System).
                LabelTask=Gestionnaire des tâches
                TextTask=restaure les clés/valeurs de la base de registres responsables de la disparition du Gestionnaire des tâches. (valeur "DisableTaskMgr" de Policies\System).
                LabelDeskop=Bureau
                TextDeskop=restaure les clés/valeurs de la base de registres responsables de l'altération du Bureau (fond d'écran, icônes, etc.).
                LabelPannel=Panneau de configuration
                TextPannel=restaure les clés/valeurs de la base de registres responsables de la disparition du Panneau de configuration. (valeur "NoControlPanel" de Policies\Explorer).
                LabelInet=Préfixes et Protocoles Internet
                TextInet=rétablit : - les valeurs de la base de registres relatives aux Préfixes par défaut d'Internet ftp, gopher, home, mosaic et www, certains malwares les modifiant et venant en rajouter pour router les adresses vers leurs sites marchands ou infectieux. Ceci correspond aux lignes O13 d'un rapport HijackThis. - les valeurs de la base de registres relatives aux Protocoles Internet http, https, ftp, file, @ivt et shell, certains malwares changeant leur affectation aux zones de sécurité. Ceci correspond à certaines lignes O15-protocoles d'un rapport HijackThis.
                LabelExtens=Extension des fichiers
                TextExtens=correspond au problème de fichiers impossibles à exécuter comme par exemple les .EXE ainsi qu'à RegEdit, le bouton d'arrêt ou le gestionnaire des tâches devenus inopérants. La solution employée remet en place les associations correspondant à .exe=fichiers exécutables, .reg=fichiers de registres, .scr=économiseurs d'écran, .pif=exécution de programmes Dos , .bat=exécution de fichiers batch, .cmd=exécution de fichiers de commande et .com=exécution de fichiers de commande. En même temps, la solution employée complète par la réinitialisation d'autres clés/valeurs relatives à RegEdit ou RegEdt32, relatives au bouton d'arrêt et relatives au Gestionnaire des tâches.
                LabelNoclose=Bouton Arrêter
                TextNoclose=restaure les clés/valeurs de la base de registres responsables de la désactivation du bouton Arrêter. (valeur "NoClose" de Policies\Explorer).
                LabelSiteConfiance=Sites de confiance et sensibles
                TextSiteConfiance=efface tout le contenu de ces zones dans l'onglet Sécurité d'Internet. On range dans ces zones, des listes d'URL auxquelles on donne des droits élevés (Sites de confiance) ou qu'on veut bloquer (Sites sensibles). Certains malwares rangent l'adresse de leurs propres pages dans ces sites de confiance de manière à avoir des droits élevés ! Ceci correspond aux lignes O15-sites de confiance d'un rapport HijackThis. Une utilisation simple de la base de registres ne permet pas de distinguer entre sites de confiance et sites sensibles et l'option supprime tout le contenu des clés ZoneMap\Domains et \Ranges). Ceci est également réalisé par l'outil DelDomains.inf de Mike Burgess aka WinHelp2002 (http://winhelp2002.mvps.org/restricted.htm Le système est à re-protéger par exemple par le contenu de IE-SPYAD d'Eric L. Howes sur https://netfiles.uiuc.edu/ehowes/www/resource.htm#IESPYAD ou NASTIE.REG de Chris Barker sur http:\\grc.com/cb-faq/nasties.reg
                LabelIESearch=Réparation IE
                TextIESearch=restaure les clés/valeurs de la base de registres qui ont pu être altérées par un malware.
                LabelHosts=Fichier Hosts
                TextHosts=remet à l'état initial le fichier de correspondance entre les URL et les adresses IP. Des malwares détournent Hosts de sa destination standard pour router les Internautes vers leur sites marchands ou néfastes ou bloquer les recours aux ressources antimalwares. Ceci correspond aux lignes O1 d'un rapport HijackThis. Des utilitaires spécialisés permettent d'aller plus loin dans la gestion de ce fichier Hosts, tels que Hoster de toadbee sur http://www.funkytoad.com/hoster.htm, HostsMan de R.J.Governa & R.Loureiro sur http://abelhadigital.netlify.com/hostsman/ Une page Web de référence est https://winhelp2002.mvps.org/hosts.htm de Mike Burgess aka WinHelp2002. Le fichier Hosts nettoyé est à re-protéger par diverses lignes fournies par WinHelp2002, tesgaz, Assiste ou autres.
                LabelFixKeys=Restaurer les clés
                TextFixKeys=applique les restauration détaillees ci dessus...
                LabelFixFile=Restaurer
                TextFixFile=applique les restaurations cochées ci dessus...
                LabelPolicies=Policies
                TextPolicies=réinitialise les valeurs de la Base de registres qui apportent beaucoup de restrictions. Ces restrictions peuvent avoir été mises volontairement en place, pour protéger le système de mauvaises manipulations... à utiliser avec discernement !
                LabelRunKey=Clés RUN
                TextRunKey=réactive les valeurs bloquant l'utilisation de ces clés.
                LabelAddRemovePrg=Ajout-Suppression de programmes
                TextAddRemovePrg=réactive les valeurs bloquant l'utilisation de cette fonction.
                LabelWinUp=Windows Update
                TextWinUp=réactive les valeurs bloquant l'utilisation de cette fonction.
                AutorTeam=Zeb-Team
                TextSysRestore=restaure l'onglet "Restauration du système" des propriétés de Poste de travail. (valeurs DisableConfig et DisableSR de HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore) Ceci n'active ni ne désactive le système de restauration.
                LabelSysRestore=Restauration du système

                [English]
                LabelReg=RegEdit
                TextReg=restores keys/values of the registry which are responsible for the non-operability of Registry Editor. (value "DisableRegistryTools" in Policies\System)
                LabelTask=Task Manager
                TextTask=restores keys/values of the registry which are responsible for the disappearance of Task Manager. (value "DisableTaskMgr" in Policies\System)
                LabelDeskop=Desktop
                TextDeskop=restores keys/values of the registry which are responsible for the alteration of the Desktop. (wallpaper, icons, etc)
                LabelPannel=Control Panel
                TextPannel=restores keys/values of the registry which are responsible for the disappearance of the Control Panel. (value "NoControlPanel" in Policies\Explorer)
                LabelInet=Internet Prefixes and Protocols
                TextInet=restores: - Registry values regarding Internet default Prefixes (ftp, gopher, home, mosaic and www) when malwares change or add some to route addresses to their vendor or infectious sites. This corresponds to lines 013 of a HijackThis log. - Registry values regarding Internet Protocols (http, https, ftp, file, @ivt and shell) when malwares change their affectation to security areas. This corresponds to certain lines 015 - Protocols of a HijackThis log.
                LabelExtens=File Extensions
                TextExtens=corresponds to the problem of files which are impossible to execute such as .EXE, or when RegEdit, the Stop Button or Task Manager become ineffective. The solution is to reset associations corresponding to .EXE=executable files, .REG=Registry files, .SCR=Screen Savers, .PIF=execution of DOS programs, .BAT=execution of batch files, .CMD=execution of command files and .COM=execution of command files. At the same time, the solution reinitializes other keys/values regarding RegEdit or RegEdt32, the Stop Button and Task Manager.
                LabelNoclose=Stop Button
                TextNoclose=restores keys/values of the registry which are responsible for disabling of the Stop Button. (value "NoClose" in Policies\Explorer)
                LabelSiteConfiance=Trusted and Restricted Sites
                TextSiteConfiance=removes all of the contents of Zones in the Security tab of Internet Options. In these zones, there are stored lists of URLs to which we give high level rights (Trusted Sites) or those that we want to block (Restricted Sites). Some malwares store addresses of their own pages in these Trusted areas in order to gain high rights! This corresponds to lines 015 - Trusted Sites of a HijackThis log. Simple use of the registry doesn't allow to distinguish between Trusted and Restricted sites and the option erases all contents of ZoneMap\Domains and ZoneMap\Ranges keys. This is also done by DelDomains.inf by Mike Burgess aka WinHelp2002 (http://winhelp2002.mvps.org/restricted.htm The system must be protected again afterwards, for example by restoring the restricted URLs from IE-SPYAD by Eric L. Howes (https://netfiles.uiuc.edu/ehowes/www/resource.htm#IESPYAD) or NASTIE.REG by Chris Barker (https://www.grc.com/cb-faq/nasties.reg
                TextIESearch=restores keys/values of the registry that may be altered by a malware.
                LabelIESearch=IE Fix
                LabelHosts=Hosts File
                TextHosts=resets the file of correspondance between URLs and IP addresses. Malware diverts Hosts from its standard destination to lead users to their vendor or nasty sites or block access to anti-malware resources. This corresponds to lines 01 of a HijackThis log. Specialized tools permit us to go further in the management of the Hosts file, such as HOSTER by toadbee (http://www.funkytoad.com/hoster.htm) HOSTSMAN by RJ Governa and R Loureiro (http://abelhadigital.netlify.com/hostsman/ A reference Web page is https://winhelp2002.mvps.org/hosts.htm by Mike Burgess aka WinHelp2002. The cleaned Hosts file must be protected again by various lines provided by WinHelp2002, tesgaz, Assiste or others.
                LabelFixKeys=Restore Keys
                TextFixKeys=apply detailed restoration...
                LabelFixFile=Restore
                TextFixFile=apply checked restoration...
                LabelPolicies=Policies
                TextPolicies=re-initializes Registry Values that implement many restrictions. These restrictions might have been set intentionally to protect the system from poor handling...so please use with prudent judgement!
                LabelRunKey=RUN Keys
                TextRunKey=re-enables values that block use of these keys.
                LabelAddRemovePrg=Add-Remove Programs
                TextAddRemovePrg=re-enables values that block use of this function.
                LabelWinUp=Windows Update
                TextWinUp=re-enables values that block use of this function.
                AutorTeam=Zeb-Team
                TextSysRestore=restores the "System Restore" tab from My Compuer Properties. (values DisableConfig and DisableSR in HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore) This neither enable nor disable the System Restore.
                LabelSysRestore=System Restore
                a le rapport a toi de bosser et merci
                0
            2. Ok,
              alors réinstalle IE stp.

              A+
              0
              1. je suis en train attend tu ne ma pas répondu pourquoi tu ma dit je tape l'incruste
                0
              2. ok super ça marche mais je n'arrive toujours pas a rentrer dans ajout et suppressions des programme comment faire tu sais ?????? en tous cas gros merci a toi
                0
              3. il me reste ce problème tu as quelque chose dans ta musettemerci
                0
            3. croutilloux,

              Pourquoi as tu supprimé des programmes ? Et lesquels ?

              Bon,
              Fais ce qui suit stp :

              Installe IE7 : https://www.01net.com/telecharger/windows/Internet/navigateur/fiches/33081.html

              Dis moi si tu as retrouver le web.

              A+
              0
              1. car a chaque foi que je me commecter aux gestionnaire live box tous les virus arriver et impossible de les mètre en quarantaine donc supprimer tous ce qui concerner internet et msn
                0
            4. MSNFix 1.700

              C:\Documents and Settings\HP_Propri‚taire\Bureau\MSNFix\MSNFix
              Fix exécuté le 06/04/2008 - 20:14:23,17 By HP_Propri‚taire
              mode normal

              ************************ Recherche les fichiers présents

              ... C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\services.exe
              ... C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\services.exe
              ... C:\WINDOWS\system32\real.txt

              ************************ Recherche les dossiers présents

              Aucun dossier trouvé

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 20:23:19, on 06/04/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16608)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\savedump.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
              C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
              C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
              C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
              C:\WINDOWS\system32\notepad.exe
              C:\WINDOWS\RTHDCPL.EXE
              C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
              C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
              C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
              C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
              C:\Program Files\Logitech\QuickCam\Quickcam.exe
              C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
              C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
              C:\Program Files\Windows Desktop Search\WindowsSearch.exe
              C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
              C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
              C:\Program Files\Windows Desktop Search\wds_sl.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
              C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
              O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
              O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
              O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
              O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
              O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
              O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
              O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
              O4 - HKLM\..\Run: [clhyisojn] c:\windows\system32\clhyisojn.exe clhyisojn
              O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKCU\..\Run: [Foue] C:\Program Files\?icrosoft\n?tepad.exe
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [Tsra] "C:\WINDOWS\WNSXS~1\chkntfs.exe" -vt ndrv
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
              O4 - S-1-5-18 Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (User 'SYSTEM')
              O4 - .DEFAULT Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe (User 'Default user')
              O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
              O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
              O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
              O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
              O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://squalldu01.spaces.live.com//PhotoUpload/MsnPUpld.cab
              O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
              O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
              O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
              O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
              O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
              O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
              O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
              O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
              O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
              O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              0
              1. Bonjour ????

                Tu n'as pas l'impression d'abuser ??? Ou de te taper l'incruste ?

                Donc,
                fais ce qui suit stp : http://pagesperso-orange.fr/rginformatique/section%20virus/demofairesontmessage.htm (Merci à Balltrap pour ce flash player)

                A+++++++++++++++
                0
              2. @Utilisateur anonymepourquoi tu me demande si j'ai pas l'impression de taper l'incruste ??????????????????????????????
                si je t'emmerde dit le !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
                0
            5. Ok,

              je ne peux plus me commecter au net a cause de ceux windows 32 qui s'affiche,

              Peux tu me donner le message d'erreur dans sa totalité ?
              J'ai des solutions dans ma besace....

              A+
              0
              1. windows ne trouve pas de chemin cela depui que j'ai suprimer a ajout et suprim des programmes tous ce qui conserne internet et ce message de c:\windows \system32\rundll32exe quoi faire ?????
                0
            6. Pour SDFix c'est obligatoirement en mode sans échec.

              Bon fais ce alors :

              > Télécharge ComboFix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe (par sUBs) sur ton Bureau.
              Déconnecte toi du net et désactive ton antivirus pour que Combofix puisse s'exécuter normalement.
              - Double clique combofix.exe
              - Tape sur la touche 1 (Yes) pour démarrer le scan.
              - Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
              NOTE : Le rapport se trouve également ici : C:\Combofix.txt
              Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

              A+
              0
              1. ok alors attend j'y vai mais je ne peux plus me commecter au net a cause de ceux windows 32 qui s'affiche quoi y faire???????
                0
              2. ci le rapport
                ComboFix 08-03-30.3 - oiana 2008-04-06 20:06:06.3 - NTFSx86 MINIMAL
                Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.621 [GMT 2:00]
                Endroit: G:\ComboFix.exe

                [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                .

                ((((((((((((((((((((((((((((( Fichiers créés 2008-03-06 to 2008-04-06 ))))))))))))))))))))))))))))))))))))
                .

                2008-04-06 18:01 . 2008-04-06 18:01 12,883,015 --a------ C:\upload_moi_HOME.tar.gz
                2008-04-06 14:30 . 2006-01-27 23:38 503,296 --a------ C:\WINDOWS\system32\aswBoot.exe
                2008-04-06 14:30 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
                2008-04-06 14:30 . 2006-01-27 23:30 90,112 --a------ C:\WINDOWS\system32\AVASTSS.scr
                2008-04-06 14:30 . 2006-01-28 00:05 85,760 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
                2008-04-06 14:30 . 2006-01-28 00:04 83,968 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
                2008-04-06 14:30 . 2006-01-28 00:02 36,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
                2008-04-06 14:30 . 2006-01-28 00:00 24,240 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
                2008-04-06 14:30 . 2006-01-28 00:03 16,352 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
                2008-04-06 12:01 . 2008-04-06 12:01 <REP> d-------- C:\Documents and Settings\oiana\Application Data\Grisoft
                2008-04-06 12:01 . 2008-04-06 12:01 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
                2008-04-06 12:01 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
                2008-03-31 21:11 . 2008-04-06 19:58 <REP> d-------- C:\Documents and Settings\oiana\Bureau
                2008-03-31 21:01 . 2008-03-31 21:04 <REP> d-------- C:\WINDOWS\SxsCaPendDel
                2008-03-31 20:55 . 2008-03-31 20:55 <REP> d-------- C:\Program Files\Trend Micro
                2008-03-30 17:31 . 2008-03-30 17:31 <REP> d-------- C:\WINDOWS\system32\AlertModule
                2008-03-30 17:30 . 2004-08-23 14:49 40,960 --a------ C:\WINDOWS\system32\FTRTSVC.exe
                2008-03-30 17:30 . 2005-10-06 14:55 36,864 --a------ C:\WINDOWS\system32\IfHelper.dll
                2008-03-30 16:46 . 2008-03-30 16:46 <REP> d-------- C:\Program Files\SAGEM
                2008-03-23 23:01 . 2008-03-31 20:59 121 --a------ C:\WINDOWS\bdagent.INI
                2008-03-23 21:57 . 2008-03-23 21:57 <REP> d-------- C:\Program Files\BitDefender
                2008-03-23 21:56 . 2008-03-23 21:57 <REP> d-------- C:\Program Files\Fichiers communs\BitDefender
                2008-03-19 20:10 . 2008-04-05 02:58 <REP> d-------- C:\SDFix
                2008-03-10 12:49 . 2008-03-10 12:49 <REP> d-------- C:\Program Files\Lavasoft
                2008-03-10 12:48 . 2008-03-10 12:50 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
                2008-03-10 12:46 . 2008-03-10 12:46 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
                2008-03-10 12:37 . 2008-03-10 12:37 268 --ah----- C:\sqmdata19.sqm
                2008-03-10 12:37 . 2008-03-10 12:37 244 --ah----- C:\sqmnoopt19.sqm

                .
                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2008-04-06 16:45 --------- d-----w C:\Program Files\Wanadoo
                2008-03-30 14:46 --------- d--h--w C:\Program Files\InstallShield Installation Information
                2008-03-30 14:11 --------- d-----w C:\Program Files\lx_cats
                2008-03-19 18:57 --------- d-----w C:\Documents and Settings\oiana\Application Data\Temporary
                2008-03-19 18:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                2008-03-16 11:48 90,112 ----a-w C:\WINDOWS\DUMP4083.tmp
                2008-03-16 11:35 --------- d-----w C:\Program Files\Messenger Plus! Live
                2008-03-08 22:35 --------- d-----w C:\Program Files\Windows Live Safety Center
                2008-02-27 19:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
                2001-11-23 12:08 712,704 ----a-r C:\WINDOWS\inf\OTHER\audio3d.dll
                .

                ((((((((((((((((((((((((((((( snapshot@2008-03-31_17.19.28,64 )))))))))))))))))))))))))))))))))))))))))
                .
                + 2008-03-31 18:57:09 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\NtUser.dat
                .
                ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                REGEDIT4
                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:54 15360]
                "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-30 22:41 68856]
                "SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2007-12-24 15:03 103712]
                "WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 14:50 122880]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "C-Media Mixer"="Mixer.exe" [2002-03-25 17:02 1228800 C:\WINDOWS\mixer.exe]
                "lxcymon.exe"="C:\Program Files\Lexmark 3400 Series\lxcymon.exe" [2006-03-06 19:48 286720]
                "EzPrint"="C:\Program Files\Lexmark 3400 Series\ezprint.exe" [2006-02-07 07:10 98304]
                "FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2006-02-02 10:11 290816]
                "LXCYCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll" [2006-02-24 13:54 65536]
                "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
                "WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 14:49 20480]
                "WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55 32768]
                "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
                "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2006-01-27 23:35 102448]

                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:54 15360]

                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
                "5E39J1V19L"= C:\WINDOWS\whsyst32.exe

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                "%windir%\\system32\\sessmgr.exe"=
                "C:\\Program Files\\Messenger\\msmsgs.exe"=
                "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                "C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                "14265:TCP"= 14265:TCP:NortonAV
                "17810:TCP"= 17810:TCP:NortonAV
                "12983:TCP"= 12983:TCP:NortonAV
                "15256:TCP"= 15256:TCP:NortonAV
                "18606:TCP"= 18606:TCP:NortonAV
                "15236:TCP"= 15236:TCP:NortonAV
                "17118:TCP"= 17118:TCP:NortonAV
                "17271:TCP"= 17271:TCP:NortonAV
                "16901:TCP"= 16901:TCP:NortonAV
                "14316:TCP"= 14316:TCP:NortonAV
                "17094:TCP"= 17094:TCP:NortonAV
                "15825:TCP"= 15825:TCP:NortonAV
                "15683:TCP"= 15683:TCP:NortonAV
                "17963:TCP"= 17963:TCP:NortonAV
                "16106:TCP"= 16106:TCP:NortonAV
                "17458:TCP"= 17458:TCP:NortonAV
                "12789:TCP"= 12789:TCP:NortonAV
                "13884:TCP"= 13884:TCP:NortonAV
                "14810:TCP"= 14810:TCP:NortonAV
                "16868:TCP"= 16868:TCP:NortonAV
                "16933:TCP"= 16933:TCP:NortonAV
                "12641:TCP"= 12641:TCP:NortonAV

                S2 OPTENET_FILTER;Control Parental;C:\Program Files\Controle Parental\bin\optproxy.exe [2006-03-02 18:10]
                S3 Camdrv30;Philips ToUcam XS;C:\WINDOWS\system32\Drivers\camdrv30.sys [2001-08-17 22:04]
                S3 lxcy_device;lxcy_device;C:\WINDOWS\system32\lxcycoms.exe [2006-02-20 21:23]
                S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 17:57]
                S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 17:58]
                S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 17:59]

                .
                Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
                "2008-04-06 16:34:15 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
                - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
                .
                **************************************************************************

                catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-04-06 20:07:28
                Windows 5.1.2600 Service Pack 2 NTFS

                Balayage processus cachés ...

                Balayage caché autostart entries ...

                HKLM\Software\Microsoft\Windows\CurrentVersion\Run
                LXCYCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

                Balayage des fichiers cachés ...

                Scan terminé avec succès
                Les fichiers cachés: 0

                **************************************************************************
                .
                Temps d'accomplissement: 2008-04-06 20:08:02
                ComboFix-quarantined-files.txt 2008-04-06 18:07:53
                ComboFix2.txt 2008-04-06 17:58:36
                ComboFix3.txt 2008-03-31 15:20:03
                Pre-Run: 19,519,266,816 octets libres
                Post-Run: 19,509,497,856 octets libres
                .
                2008-03-23 21:05:36 --- E O F ---
                bon courrage !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
                0
            7. En fait il faut bien que tu lises ce qu'il y a ici : http://www.commentcamarche.net/forum/affich 5709333 virus msn#13

              Comme tu peux le lire le rapport SDFix apparait en fin de scan.

              Pour AVG avait il trouvé des crasses ? Si oui les as tu supprimé ?

              A+
              0
              1. pour avg rien de rien mais pour sdfix ou je suis trops con ou je n'y arrive pas ta pas autre chose desoler
                0
            8. Salut pourquoi tu m'envoies un combo que tu m'as déjà donné ici : http://www.commentcamarche.net/forum/affich 5709333 virus msn#11

              ?

              Le rapport SDFix n'est pas complet.....Reposte le stp.

              Et pour AVG ????

              Après on continue mais là on avance pas....

              A+
              0
              1. pour avg rien comme fichier infecters pour SDfix en mode sans echec ou je doit voir le rapport apres merci et pour le message windows rien a faire car ils me bloc tous celui ci
                0
            • 1
            • 2