VIRUS RECU SUR MSN

Résolu
Bonjour,

Après avoir reçu un document (une photo) par msn, que j'ai ouvert, mon antivirus s'est déclenché.
J'ai fermé tous les programmes et j'ai fait une analyse complète aves Avast mais certains fichiers ne peuvent pas être scannés ni supprimés.

Comment me débarrasser de tout ça??
Configuration: Windows XP
Internet Explorer 6.0

40 réponses

Résumé de la discussion

Problème de sécurité informatique: après l'ouverture d'une photo reçue par MSN, l'antivirus Avast s'est déclenché et certains fichiers n'ont pas pu être scannés ni supprimés, sous Windows XP et Internet Explorer 6. Plusieurs réponses proposent d'analyser les éléments suspects avec des outils comme HijackThis, OAD ou MSNFix, puis de générer un rapport et de suivre les procédures de suppression et de nettoyage. D'autres conseils évoquent l'analyse du registre, la suppression de fichiers problématiques et le redémarrage en mode normal, avec des instructions détaillées et des rapports à poster pour guidance supplémentaire. En parallèle, des mises à jour recommandées incluent l'abandon d'Internet Explorer 6 au profit d'un navigateur plus récent et d'une version actualisée d'Adobe Reader, afin de réduire les risques futurs.

Bobot (l’IA à votre service)
  1. Contributeur
    De rien mary851,
    Bye`
    0
    1. alala merci my g!rly , ton aide reste précieuse^^
      0
  2. Contributeur
    oui ;D

    on peux maintenant se separer

    je te souhaite une bonne continuation

    bye`

    g!rly`
    0
    1. ok merci beaucoup!!!!!!
      0
  3. Contributeur
    ok

    ces deux warning la;

    c´est relatif a la memoire de windows; windows utilise ces processus pour hiberner en quelque sorte, donc pas de panic ;D
    0
    1. je considère donc que mon oridnateur n'est plus infecté par le virus de msn et que tout va pour le mieux???
      0
  4. Contributeur
    ok tres bien

    @+
    0
    1. AntiVir PersonalEdition Classic
      Report file date: mercredi 9 avril 2008 15:52

      Scanning for 1188179 virus strains and unwanted programs.

      Licensed to: Avira AntiVir PersonalEdition Classic
      Serial number: 0000149996-ADJIE-0001
      Platform: Windows XP
      Windows version: (Service Pack 2) [5.1.2600]
      Username: SYSTEM
      Computer name: CHAZÉ

      Version information:
      BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
      AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 12:16:29
      AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 11:23:51
      LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 14:32:47
      LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 11:35:20
      ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 13:27:15
      ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 20:22:48
      ANTIVIR2.VDF : 7.0.3.127 649216 Bytes 07/04/2008 20:22:48
      ANTIVIR3.VDF : 7.0.3.135 57344 Bytes 08/04/2008 19:15:55
      AVEWIN32.DLL : 7.6.0.81 3424768 Bytes 07/04/2008 20:22:50
      AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
      AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 06:39:17
      AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
      AVPACK32.DLL : 7.6.0.3 360488 Bytes 07/04/2008 20:22:51
      AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 06:17:06
      AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 11:26:33
      AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 06:10:18
      NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
      RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 11:38:13
      RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 11:50:37
      SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 08:37:21

      Configuration settings for the scan:
      Jobname..........................: Complete system scan
      Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
      Logging..........................: low
      Primary action...................: interactive
      Secondary action.................: ignore
      Scan master boot sector..........: on
      Scan boot sector.................: on
      Boot sectors.....................: D:,
      Scan memory......................: on
      Process scan.....................: on
      Scan registry....................: on
      Search for rootkits..............: on
      Scan all files...................: All files
      Scan archives....................: on
      Recursion depth..................: 20
      Smart extensions.................: on
      Macro heuristic..................: on
      File heuristic...................: high

      Start of the scan: mercredi 9 avril 2008 15:52

      Starting search for hidden objects.
      Error in ARK lib

      The scan of running processes will be started
      Scan process 'avscan.exe' - '1' Module(s) have been scanned
      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
      Scan process 'iexplore.exe' - '1' Module(s) have been scanned
      Scan process 'alg.exe' - '1' Module(s) have been scanned
      Scan process 'iPodService.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'CDAC11BA.EXE' - '1' Module(s) have been scanned
      Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
      Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
      Scan process 'sched.exe' - '1' Module(s) have been scanned
      Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
      Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
      Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
      Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
      Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
      Scan process 'E_S10IC2.EXE' - '1' Module(s) have been scanned
      Scan process 'mixer.exe' - '1' Module(s) have been scanned
      Scan process 'shwicon2k.exe' - '1' Module(s) have been scanned
      Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
      Scan process 'kbd.exe' - '1' Module(s) have been scanned
      Scan process 'hphmon05.exe' - '1' Module(s) have been scanned
      Scan process 'hpwuSchd.exe' - '1' Module(s) have been scanned
      Scan process 'HpqCmon.exe' - '1' Module(s) have been scanned
      Scan process 'hpsysdrv.exe' - '1' Module(s) have been scanned
      Scan process 'avguard.exe' - '1' Module(s) have been scanned
      Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
      Scan process 'aawservice.exe' - '1' Module(s) have been scanned
      Scan process 'explorer.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'lsass.exe' - '1' Module(s) have been scanned
      Scan process 'services.exe' - '1' Module(s) have been scanned
      Scan process 'winlogon.exe' - '1' Module(s) have been scanned
      Scan process 'csrss.exe' - '1' Module(s) have been scanned
      Scan process 'smss.exe' - '1' Module(s) have been scanned
      39 processes with 39 modules were scanned

      Starting master boot sector scan:
      Master boot sector HD0
      [NOTE] No virus was found!
      Master boot sector HD1
      [NOTE] No virus was found!
      [WARNING] The boot sector file could not be read!
      [WARNING] Error code: 0x0015
      Master boot sector HD2
      [NOTE] No virus was found!
      [WARNING] The boot sector file could not be read!
      [WARNING] Error code: 0x0015
      Master boot sector HD3
      [NOTE] No virus was found!
      [WARNING] The boot sector file could not be read!
      [WARNING] Error code: 0x0015
      Master boot sector HD4
      [NOTE] No virus was found!
      [WARNING] The boot sector file could not be read!
      [WARNING] Error code: 0x0015

      Start scanning boot sectors:
      Boot sector 'C:\'
      [NOTE] No virus was found!
      Boot sector 'D:\'
      [NOTE] No virus was found!

      Starting to scan the registry.
      The registry was scanned ( '44' files ).

      Starting the file scan:

      Begin scan in 'C:\' <HP_PAVILION>
      C:\hiberfil.sys
      [WARNING] The file could not be opened!
      C:\pagefile.sys
      [WARNING] The file could not be opened!
      Begin scan in 'D:\' <HP_RECOVERY>

      End of the scan: mercredi 9 avril 2008 16:41
      Used time: 48:31 min

      The scan has been done completely.

      4914 Scanning directories
      330751 Files were scanned
      0 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      2 Files cannot be scanned
      330751 Files not concerned
      18308 Archives were scanned
      2 Warnings
      0 Notes
      26807 Objects were scanned with rootkit scan
      0 Hidden objects were found
      0
  5. Contributeur
    Dis moi que sont ces warning ?
    @+
    0
    1. Je t'envoie le rapport dès qu'Antivir a terminé!
      0
  6. Contributeur
    re,

    le virus msn est partie ;-)

    tu ne devrais plus avoir de soucis maintenant...

    @+
    0
    1. ok merci beaucoup!!
      dernière question : à quoi correspondent les 2 warnings qu'Antivir détecte toujours???
      0
  7. Contributeur
    salut mary,

    c´est bon cette fois ci, la cle a disparu ;-)

    maintenant instale un par feu pour plus de securité :

    Comodo 3 pro :

    http://www.commentcamarche.net/telecharger/telecharger 34055041 comodo firewall pro

    tuto : https://www.malekal.com/tutorial-comodo-firewall/

    ou

    Online armor :

    http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall

    tuto : https://www.malekal.com/tutorial-online-armor-free/

    rajoute aussi ceci :

    spywareblaster :

    http://www.brightfort.com/spywareblaster.html

    c´est un resident, il suffit de le mettre a jour de temps en temps car la version gratuite ne le fait pas toute seul , une fois installé et mis a jour tu mets toutes les protections sur "enable"

    tuto : https://www.malekal.com/tutorial-spywareblaster/

    puis fais ceci :

    Désactive ta restauration système:
    pour cela :
    Click droit sur poste de travail, dans l´arborescence sur propriétés;
    dans la nouvelle fenettre click sur l´onglet restauration système;
    coche la case désactiver la restauration systèm et applique.
    puis redemarre le pc et click droit sur poste de travail, dans l´arborescence sur propriétés;
    dans la nouvelle fenettre click sur l´onglet restauration systèm
    décoche la case désactiver la restauration systèm et applique.

    puis

    Télécharge ToolsCleaner sur ton bureau.
    --> http://www.commentcamarche.net/telecharger/telechargement 34055291 toolsclean(...)
    # Clique sur Recherche et laisse le scan agir ...
    # Clique sur Suppression pour finaliser.
    # Tu peux, si tu le souhaites, te servir des Options facultatives.
    # Clique sur Quitter pour obtenir le rapport.
    # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

    dis moi quoi

    @+
    0
    1. oups, j'ai supprimé le rapport!!!

      Y a-t-il toujours le virus msn???
      0
  8. Contributeur
    ok lol
    tout est expliqué sur lien
    o_Ö
    @´+
    0
    1. merci my best!
      0
  9. jtape msconfig ds eecuter et dit alrs f8 et f5 merde que faire? mdr
    0
    1. Contributeur
      hi, msconfig my funnygirl`
      0
      1. Contributeur
        ok

        fais ceci :

        -> Redémarre en mode sans échec :

        Comment redémarrer en mode sans echec?

        Tu redemarre le pc et tapote la touche F8 des le début de l allumage sans t´arrêter.
        Une fenêtre sur fond noir va s’ouvrir, tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
        Une fois sur le bureau si il n y a pas toutes les couleurs et autres c´est normal!
        Ps : si F8 ne marche pas utilise la touche F5.

        -> Tuto : http://forum.telecharger.01net.com/forum/high-tech/SECURITE/Securite/redemarrer-mode-echec-sujet_1526_1.htm

        une fois en mode sans echec ouvre hijack this et coche et fix les lignes suivantes :

        O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\%%%%%.exe
        O4 - Global Startup: customize__IE.lnk = C:\hp\region\customizeIe.wsf

        repost un nouveau hijack this stp

        @+
        0
        1. hello my g!rly et si F8 et f5 ne marchait pas tiens!!! on fé quoi loool
          0
        2. Bonjour, ci-joint le rapport demandé :

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 09:13:28, on 09/04/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16608)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\windows\system\hpsysdrv.exe
          C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
          C:\Program Files\HP\HP Software Update\HPWuSchd.exe
          C:\WINDOWS\System32\hphmon05.exe
          C:\HP\KBD\KBD.EXE
          C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe
          C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
          C:\Program Files\Multimedia Card Reader\shwicon2k.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\WINDOWS\Mixer.exe
          C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\WINDOWS\system32\drivers\CDAC11BA.EXE
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
          O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
          O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
          O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe"
          O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
          O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
          O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
          O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
          O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
          O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
          O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
          O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
          O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
          O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C64 Series" /O5 "LPT1:" /M "Stylus C64"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
          O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [WINSOS VERIFY] "C:\Program Files\Winsos\WINSOS.EXE" MINI
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
          O4 - Global Startup: MsnFixer.lnk = ?
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
          0
      2. Contributeur
        mary851,

        cette cle me rend fou :

        O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\%%%%%.exe

        est ce que tu as customisé internet explorer ?

        @+
        0
        1. ce qui veut dire?
          En tout cas, j'ai installé Internet Explorer que tu m'avais indiqué avant
          0
      3. Contributeur
        salut mary851,

        fais les mises a jour suivantes :

        tu surf avec internet explorer 6.0 = failles de securitées importantes

        alors fais les mises a jour windows : tu veux la version 7.0

        https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70

        et pourquoi ne pas surfer avec firefox? = plus sur, tout en gardant ie 7.0 pour les mises a jour windows car impossible a effectuer sous firefox

        http://www.mozilla-europe.org/fr/

        plugins : ad block plus, no script ect...

        https://www.hugedomains.com/domain_profile.cfm?d=geckozone&e=org

        ta version de acrobat reader n´est pas a jour, tu veux la version 8.1 derniere en date alors desinstale ta version par le panneau de configuration / ajoue et suppression de programme

        et instale la derniere :

        https://get2.adobe.com/reader/otherversions/

        ou oublie completement acrobat reader et instales foxit plus léger a la place:

        https://www.clubic.com/telecharger-fiche13808-foxit-reader.html

        reviens apres avec un nouveau rapport hijack this stp

        @+
        0
        1. Où en sont les virus??

          Le rapport :
          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 18:49:28, on 08/04/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16608)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\windows\system\hpsysdrv.exe
          C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
          C:\Program Files\HP\HP Software Update\HPWuSchd.exe
          C:\WINDOWS\System32\hphmon05.exe
          C:\HP\KBD\KBD.EXE
          C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe
          C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
          C:\Program Files\Multimedia Card Reader\shwicon2k.exe
          C:\WINDOWS\Mixer.exe
          C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\WINDOWS\system32\drivers\CDAC11BA.EXE
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
          O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
          O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
          O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe"
          O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
          O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
          O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
          O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
          O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
          O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
          O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
          O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
          O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
          O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C64 Series" /O5 "LPT1:" /M "Stylus C64"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\%%%%%.exe
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
          O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [WINSOS VERIFY] "C:\Program Files\Winsos\WINSOS.EXE" MINI
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
          O4 - Global Startup: customize__IE.lnk = C:\hp\region\customizeIe.wsf
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
          O4 - Global Startup: MsnFixer.lnk = ?
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
          0
        2. Est-ce que le virus est toujours d'actualité??? Je m'inquiète vraiment!!!
          0
      4. oula oué !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!ya du menage pr my G!rly et toi ^^

        je suis c' topic car ca fini bien ^^

        bises
        0
        1. Contributeur
          ok

          post le rapport hijack this stp

          @+
          0
          1. Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 17:07:26, on 08/04/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            C:\windows\system\hpsysdrv.exe
            C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
            C:\Program Files\HP\HP Software Update\HPWuSchd.exe
            C:\WINDOWS\System32\hphmon05.exe
            C:\HP\KBD\KBD.EXE
            C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\Program Files\Multimedia Card Reader\shwicon2k.exe
            C:\WINDOWS\Mixer.exe
            C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\WINDOWS\system32\drivers\CDAC11BA.EXE
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\internet explorer\iexplore.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
            O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
            O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
            O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe"
            O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
            O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
            O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
            O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
            O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
            O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
            O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
            O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
            O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C64 Series" /O5 "LPT1:" /M "Stylus C64"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\%%%%%.exe
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
            O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
            O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [WINSOS VERIFY] "C:\Program Files\Winsos\WINSOS.EXE" MINI
            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
            O4 - Global Startup: customize__IE.lnk = C:\hp\region\customizeIe.wsf
            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
            O4 - Global Startup: MsnFixer.lnk = ?
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
            O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
            0
        2. Contributeur
          re,

          tu as du remarqué que je butte sur O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\%%%%%.exe

          peux etre une simple cle vu que tu ne trouve pas le fichier et msnfix non plus on va tenté ceci :

          a l´aide de hijack this coche et fix :

          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\%%%%%.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)

          comment fixer :

          Tutoriel d´utilisation (video) : (Merci a Balltrap34 pour cette réalisation)

          -> http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

          puis

          regarde ceci concernant avast :

          antivir vs avast :

          -> http://forum.malekal.com/ftopic3528.php

          alors je te conseille de le desinstaller et d´installer antivir a la place

          Telecharge et instales l'antivirus Antivir Personal Edition Classic :

          ->https://www.malekal.com/avira-free-security-antivirus-gratuit/

          https://www.avira.com/en/prime

          http://mickael.barroux.free.fr/securite/antivir.php
          http://speedweb1.free.fr/frames2.php?page=tuto5
          <- tutoriel configuration du scanner...

          une fois antivir ouvert click surconfiguration et coche la case "expert mode" puis sur l´onglet scanner dans la fenetre du dessous tu va voir : rootkit search click sur le petit + pour deployer et coche la case a coté de ton disk dur
          puis click sur configuration en haut a droite; dans la nouvelle fenetre a gauche >scanner > coche "scan all files" et en dessous >scanner priority = High
          coche : allow stopping the scanner, comme cela tu peux faire une pause pendant le scan si tu le desir.
          puis sur la droite coche les case suivantes :
          scan boot sectors of selected drives
          scan master boot sectors
          scan memory
          search foe rootkit before scan
          decoche :
          ignore off line files
          toujours a gauche > scan > deploie > heuristique > macrovirus heuristic = coché et en dessous > win32 heuristic la case coché et high detection level

          Je te dis tous ca car j´aimerais que tu performes un scan entier de ta machine a l´aide d´antivir avec les reglages stipulés ci dessus et que tu post le rapport généré ici stp

          @+
          0
          1. AntiVir PersonalEdition Classic
            Report file date: lundi 7 avril 2008 21:19

            Scanning for 835736 virus strains and unwanted programs.

            Licensed to: Avira AntiVir PersonalEdition Classic
            Serial number: 0000149996-ADJIE-0001
            Platform: Windows XP
            Windows version: (Service Pack 2) [5.1.2600]
            Username: SYSTEM
            Computer name: CHAZÉ

            Version information:
            BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
            AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 12:16:29
            AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 11:23:51
            LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 14:32:47
            LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 11:35:20
            ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 13:27:15
            ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 13:26:55
            ANTIVIR2.VDF : 7.0.0.1 2048 Bytes 13/09/2007 13:27:04
            ANTIVIR3.VDF : 7.0.0.2 2048 Bytes 13/09/2007 13:27:13
            AVEWIN32.DLL : 7.6.0.15 2806272 Bytes 17/09/2007 16:43:56
            AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
            AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 06:39:17
            AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
            AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 07:46:00
            AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 06:17:06
            AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 11:26:33
            AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 06:10:18
            NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
            RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 11:38:13
            RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 11:50:37
            SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 08:37:21

            Configuration settings for the scan:
            Jobname..........................: Complete system scan
            Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
            Logging..........................: low
            Primary action...................: interactive
            Secondary action.................: ignore
            Scan master boot sector..........: on
            Scan boot sector.................: on
            Boot sectors.....................: D:,
            Scan memory......................: on
            Process scan.....................: on
            Scan registry....................: on
            Search for rootkits..............: on
            Scan all files...................: All files
            Scan archives....................: on
            Recursion depth..................: 20
            Smart extensions.................: on
            Macro heuristic..................: on
            File heuristic...................: high

            Start of the scan: lundi 7 avril 2008 21:19

            Starting search for hidden objects.
            '40202' objects were checked, '0' hidden objects were found.

            The scan of running processes will be started
            Scan process 'avscan.exe' - '1' Module(s) have been scanned
            Scan process 'avgnt.exe' - '1' Module(s) have been scanned
            Scan process 'avguard.exe' - '1' Module(s) have been scanned
            Scan process 'sched.exe' - '1' Module(s) have been scanned
            Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
            Scan process 'alg.exe' - '1' Module(s) have been scanned
            Scan process 'iPodService.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'CDAC11BA.EXE' - '1' Module(s) have been scanned
            Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
            Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
            Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
            Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
            Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
            Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
            Scan process 'E_S10IC2.EXE' - '1' Module(s) have been scanned
            Scan process 'mixer.exe' - '1' Module(s) have been scanned
            Scan process 'shwicon2k.exe' - '1' Module(s) have been scanned
            Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
            Scan process 'kbd.exe' - '1' Module(s) have been scanned
            Scan process 'hphmon05.exe' - '1' Module(s) have been scanned
            Scan process 'hpwuSchd.exe' - '1' Module(s) have been scanned
            Scan process 'HpqCmon.exe' - '1' Module(s) have been scanned
            Scan process 'hpsysdrv.exe' - '1' Module(s) have been scanned
            Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
            Scan process 'aawservice.exe' - '1' Module(s) have been scanned
            Scan process 'explorer.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'lsass.exe' - '1' Module(s) have been scanned
            Scan process 'services.exe' - '1' Module(s) have been scanned
            Scan process 'winlogon.exe' - '1' Module(s) have been scanned
            Scan process 'csrss.exe' - '1' Module(s) have been scanned
            Scan process 'smss.exe' - '1' Module(s) have been scanned
            37 processes with 37 modules were scanned

            Starting master boot sector scan:
            Master boot sector HD0
            [NOTE] No virus was found!
            Master boot sector HD1
            [NOTE] No virus was found!
            [WARNING] The boot sector file could not be read!
            [WARNING] Error code: 0x0015
            Master boot sector HD2
            [NOTE] No virus was found!
            [WARNING] The boot sector file could not be read!
            [WARNING] Error code: 0x0015
            Master boot sector HD3
            [NOTE] No virus was found!
            [WARNING] The boot sector file could not be read!
            [WARNING] Error code: 0x0015
            Master boot sector HD4
            [NOTE] No virus was found!
            [WARNING] The boot sector file could not be read!
            [WARNING] Error code: 0x0015

            Start scanning boot sectors:
            Boot sector 'C:\'
            [NOTE] No virus was found!
            Boot sector 'D:\'
            [NOTE] No virus was found!

            Starting to scan the registry.
            The registry was scanned ( '45' files ).

            Starting the file scan:

            Begin scan in 'C:\' <HP_PAVILION>
            C:\hiberfil.sys
            [WARNING] The file could not be opened!
            C:\pagefile.sys
            [WARNING] The file could not be opened!
            C:\QooBox\Quarantine\catchme2008-04-07_190039,14.zip
            [0] Archive type: ZIP
            --> Documents and Settings/Propriétaire/Bureau/catchme.zip
            [1] Archive type: ZIP
            --> %%0e+000xe
            [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
            [INFO] The file was moved to '486e7b38.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0002143.exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '482a7b0f.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0002144.exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '482a7b12.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0007163.exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '482a7b17.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0008172.exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '482a7b1b.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0009169.exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '482a7b1d.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0010167.exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '482a7b21.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0011169.exe
            [DETECTION] Contains suspicious code HEUR/Malware
            [INFO] The file was moved to '482a7b23.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0011172.exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '482a7b26.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0011238.exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '482a7b29.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0012238.exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '482a7b2c.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0012282.exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '482a7b2f.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0012322.exe
            [DETECTION] Contains suspicious code HEUR/Malware
            [INFO] The file was moved to '482a7b31.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0012325.exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '482a7b33.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0013324.exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '482a7b38.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0014323.exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '482a7b3b.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0015323.exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '482a7b3e.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP1\A0015380.exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '482a7b40.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP2\A0015613.exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '482a7b4b.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP2\A0015644.exe
            [DETECTION] Contains suspicious code HEUR/Malware
            [INFO] The file was moved to '482a7b4e.qua'!
            C:\System Volume Information\_restore{02154015-BE0F-4EA2-9B01-6F19FB6A5D01}\RP70\A0023594.exe
            [DETECTION] Is the Trojan horse TR/Trash.Gen
            [INFO] The file was moved to '482a7c28.qua'!
            C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\81MBGTAZ\84785_winsgh[1].exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '48317ea4.qua'!
            C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KX6NG9IB\84785_winsgh[1].exe
            [DETECTION] Contains suspicious code HEUR/Crypted
            [INFO] The file was moved to '48317ea9.qua'!
            Begin scan in 'D:\' <HP_RECOVERY>

            End of the scan: lundi 7 avril 2008 22:12
            Used time: 53:17 min

            The scan has been done completely.

            5142 Scanning directories
            340065 Files were scanned
            2 viruses and/or unwanted programs were found
            21 Files were classified as suspicious:
            0 files were deleted
            0 files were repaired
            23 files were moved to quarantine
            0 files were renamed
            2 Files cannot be scanned
            340063 Files not concerned
            18327 Archives were scanned
            2 Warnings
            0 Notes
            40202 Objects were scanned with rootkit scan
            0 Hidden objects were found
            0
        • 1
        • 2