Trojan win 32 homles

Bonjour,

Je suis sur l'ordi de mon père et en plus de s'arrêter de temps en temps tout seul, avast détecte le trojan win 32 homles.

Je ne sais pas trop quelles lignes enlever et lesquelles conserver!

Je vous joins le rapport Hijackthis: Merci de votre aide

Logfile of HijackThis v1.99.1
Scan saved at 09:47:58, on 03/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSI\DigiCell\DigiCell.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\OLIFAXVX\TOOLBAR.EXE
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Morel\LOCALS~1\Temp\Répertoire temporaire 1 pour hijackthis_199.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\^%% ^% ^% %%^% ^%%^ % %^ %%%^% %% % % %^ %^% .exe
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\^%% ^% ^% %%^% ^%%^ % %^ %%%^% %% % % %^ %^% .exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Barre d'Outils Olitec.lnk = C:\OLIFAXVX\TOOLBAR.EXE
O4 - Startup: Moniteur Fax-Voix.lnk = C:\OLIFAXVX\MONITEUR.EXE
O4 - Global Startup: DigiCell.lnk = C:\Program Files\MSI\DigiCell\DigiCell.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0) - http://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVSrvLauncher - Labtec Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
Configuration: Windows XP SP2
Internet Explorer 7.0

14 réponses

  1. Contributeur sécurité
    ok a plus tu diras
    0
    1. Contributeur sécurité
      mettre une prise parafoudre

      ________

      teste ta memoire vive

      http://www.world-informatique.com/pasapas/faq/voir.html?qid=48
      0
      1. Je suis déjà sur un onduleur, ça doit être dans l'ordi. Je verrais ça quand je reviendrais voir mon paternel !

        Merci pour ton coup de main, c'était la première fois que je me lançais sur un forum et j'en suis ravi!

        Bonne continuation, a plus.

        Alex.
        0
    2. Contributeur sécurité
      non laisse

      pour info:
      https://support.microsoft.com/fr-fr/help/198768

      sinon encore des soucis?
      0
      1. Ouai l'ordi s'arrête encore de temps en temps.

        Pour le reste tout semble fonctionner.

        Merci pour tout, si tu connais un moyen de tester si ce ne sont pas des micro coupures d'alimentation qui coupent mon ordi.
        0
    3. Contributeur sécurité
      tu mets ceci dans la fenetre de gauche si il est considéré comme infécté sur virus total

      C:\WINDOWS\system32\Wintdist.exe
      0
      1. Allo,

        Une fois le fichier Wintdist.exe analysé le résultat est le suivant:

        Fichier Wintdist.exe reçu le 2006.11.16 09:47:58 (CET)
        Situation actuelle: terminé

        Résultat: 1/28 (3.57%)
        Formaté Impression des résultats
        Antivirus Version Dernière mise à jour Résultat
        AntiVir - - -
        Authentium - - -
        Avast - - -
        AVG - - -
        BitDefender - - -
        CAT-QuickHeal - - -
        ClamAV - - -
        DrWeb - - -
        eTrust-InoculateIT - - -
        eTrust-Vet - - -
        Ewido - - -
        F-Prot - - -
        F-Prot4 - - -
        Fortinet - - suspicious
        Ikarus - - -
        Kaspersky - - -
        McAfee - - -
        Microsoft - - -
        NOD32v2 - - -
        Norman - - -
        Panda - - -
        Prevx1 - - -
        Sophos - - -
        T3 - - -
        TheHacker - - -
        UNA - - -
        VBA32 - - -
        VirusBuster - - -

        Faut-il que je le mette dans la fenêtre de gauche même s'il n'y a que Fortinet qui detecte quelque chose de suspicieux?
        0
    4. Contributeur sécurité
      vire le fichier backups _old en allant dans poste de travail puis

      C:\SDFix\backups_old\

      _______________
      analyse ce fichier sur virus total et si infecté tu le mets dans la citation otmovit:

      https://www.virustotal.com/gui/

      C:\WINDOWS\system32\Wintdist.exe

      __________________

      télécharge OTMoveIt
      http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau. Ou sur https://www.luanagames.com/index.fr.html
      double-clique sur OTMoveIt.exe pour le lancer.
      copie la liste qui se trouve en citation ci-dessous,
      et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

      Citation :

      clique sur MoveIt! pour lancer la suppression.
      le résultat apparaitra dans le cadre "Results".
      clique sur Exit pour fermer.
      poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

      il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

      __________________

      dis tes soucis actuels et recolle un hijakhcits
      0
      1. Contributeur sécurité
        analyse ce fichier sur virus total et si infecté tu le mets dans la citation otmovit:

        https://www.virustotal.com/gui/

        C:\WINDOWS\system32\Wintdist.exe

        __________________

        télécharge OTMoveIt
        http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau. Ou sur https://www.luanagames.com/index.fr.html
        double-clique sur OTMoveIt.exe pour le lancer.
        copie la liste qui se trouve en citation ci-dessous,
        et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

        Citation :

        clique sur MoveIt! pour lancer la suppression.
        le résultat apparaitra dans le cadre "Results".
        clique sur Exit pour fermer.
        poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

        il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

        __________________

        essyae de faire bien sûr antivir en mode sans echec et de me coller le rapport et dis tes soucis
        0
        1. Ok, j'ai réussi un scan antivir dont voici le résultat:

          Avira AntiVir Personal
          Report file date: vendredi 6 juin 2008 05:20

          Scanning for 1311148 virus strains and unwanted programs.

          Licensed to: Avira AntiVir PersonalEdition Classic
          Serial number: 0000149996-ADJIE-0001
          Platform: Windows XP
          Windows version: (Service Pack 2) [5.1.2600]
          Boot mode: Normally booted
          Username: SYSTEM
          Computer name: MOREL-926JZ3WGD

          Version information:
          BUILD.DAT : 8.1.0.308 16478 Bytes 28/05/2008 17:03:00
          AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 09:02:56
          AVSCAN.DLL : 8.1.1.0 53505 Bytes 07/02/2008 08:43:37
          LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 08:41:23
          LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 08:28:40
          ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
          ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 13:08:58
          ANTIVIR2.VDF : 7.0.4.120 2206720 Bytes 01/06/2008 11:15:13
          ANTIVIR3.VDF : 7.0.4.147 106496 Bytes 05/06/2008 11:14:06
          Engineversion : 8.1.0.51
          AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
          AESCRIPT.DLL : 8.1.0.37 270715 Bytes 03/06/2008 11:15:23
          AESCN.DLL : 8.1.0.20 119157 Bytes 03/06/2008 11:15:22
          AERDL.DLL : 8.1.0.20 418165 Bytes 03/06/2008 11:15:22
          AEPACK.DLL : 8.1.1.5 364918 Bytes 03/06/2008 11:15:21
          AEOFFICE.DLL : 8.1.0.18 192890 Bytes 03/06/2008 11:15:20
          AEHEUR.DLL : 8.1.0.29 1253750 Bytes 03/06/2008 11:15:19
          AEHELP.DLL : 8.1.0.15 115063 Bytes 03/06/2008 11:15:17
          AEGEN.DLL : 8.1.0.25 307573 Bytes 03/06/2008 11:15:16
          AEEMU.DLL : 8.1.0.6 430451 Bytes 03/06/2008 11:15:14
          AECORE.DLL : 8.1.0.30 168311 Bytes 03/06/2008 11:15:14
          AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 17:07:53
          AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 10:37:50
          AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:26:47
          AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 17:07:49
          AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
          AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 08:31:31
          SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
          SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 17:08:39
          NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
          RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 14:37:25
          RCTEXT.DLL : 8.0.32.0 86273 Bytes 06/03/2008 12:02:11

          Configuration settings for the scan:
          Jobname..........................: Complete system scan
          Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
          Logging..........................: low
          Primary action...................: interactive
          Secondary action.................: ignore
          Scan master boot sector..........: on
          Scan boot sector.................: on
          Boot sectors.....................: C:,
          Scan memory......................: on
          Process scan.....................: on
          Scan registry....................: on
          Search for rootkits..............: off
          Scan all files...................: Intelligent file selection
          Scan archives....................: on
          Recursion depth..................: 20
          Smart extensions.................: on
          Macro heuristic..................: on
          File heuristic...................: medium

          Start of the scan: vendredi 6 juin 2008 05:20

          The scan of running processes will be started
          Scan process 'avscan.exe' - '1' Module(s) have been scanned
          Scan process 'iexplore.exe' - '1' Module(s) have been scanned
          Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
          Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
          Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
          Scan process 'alg.exe' - '1' Module(s) have been scanned
          Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
          Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'kpf4ss.exe' - '1' Module(s) have been scanned
          Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
          Scan process 'CDAC11BA.EXE' - '1' Module(s) have been scanned
          Scan process 'avguard.exe' - '1' Module(s) have been scanned
          Scan process 'ntvdm.exe' - '1' Module(s) have been scanned
          Scan process 'KHALMNPR.EXE' - '1' Module(s) have been scanned
          Scan process 'TOOLBAR.EXE' - '1' Module(s) have been scanned
          Scan process 'SetPoint.exe' - '1' Module(s) have been scanned
          Scan process 'DigiCell.exe' - '1' Module(s) have been scanned
          Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
          Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
          Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
          Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
          Scan process 'avgnt.exe' - '1' Module(s) have been scanned
          Scan process 'qttask.exe' - '1' Module(s) have been scanned
          Scan process 'LVCOMSX.EXE' - '1' Module(s) have been scanned
          Scan process 'shwicon2k.exe' - '1' Module(s) have been scanned
          Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned
          Scan process 'sched.exe' - '1' Module(s) have been scanned
          Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
          Scan process 'explorer.exe' - '1' Module(s) have been scanned
          Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
          Scan process 'lsass.exe' - '1' Module(s) have been scanned
          Scan process 'services.exe' - '1' Module(s) have been scanned
          Scan process 'winlogon.exe' - '1' Module(s) have been scanned
          Scan process 'csrss.exe' - '1' Module(s) have been scanned
          Scan process 'smss.exe' - '1' Module(s) have been scanned
          42 processes with 42 modules were scanned

          Starting master boot sector scan:
          Master boot sector HD0
          [INFO] No virus was found!
          Master boot sector HD1
          [INFO] No virus was found!
          [WARNING] Le périphérique n'est pas prêt.
          Master boot sector HD2
          [INFO] No virus was found!
          [WARNING] Le périphérique n'est pas prêt.
          Master boot sector HD3
          [INFO] No virus was found!
          [WARNING] Le périphérique n'est pas prêt.
          Master boot sector HD4
          [INFO] No virus was found!
          [WARNING] Le périphérique n'est pas prêt.

          Start scanning boot sectors:
          Boot sector 'C:\'
          [INFO] No virus was found!

          Starting to scan the registry.
          The registry was scanned ( '25' files ).

          Starting the file scan:

          Begin scan in 'C:\'
          C:\pagefile.sys
          [WARNING] The file could not be opened!
          C:\SDFix\backups_old\^%% ^% ^% %%^% ^%%^ % %^ %%%^% %% % % %^ %^% .exe
          [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
          [NOTE] The file was moved to '486db24e.qua'!
          C:\System Volume Information\_restore{CCB06137-1A08-44E7-92AE-4D7041FAD497}\RP431\A0136881.exe
          [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
          [NOTE] The file was moved to '4879b303.qua'!

          End of the scan: vendredi 6 juin 2008 05:53
          Used time: 33:34 min

          The scan has been done completely.

          6073 Scanning directories
          166771 Files were scanned
          2 viruses and/or unwanted programs were found
          0 Files were classified as suspicious:
          0 files were deleted
          0 files were repaired
          2 files were moved to quarantine
          0 files were renamed
          1 Files cannot be scanned
          166769 Files not concerned
          1572 Archives were scanned
          5 Warnings
          2 Notes

          Je fais le reste de ce que tu m'a écrit.
          0
        2. Excuse moi mais je ne comprend pas ce que tu entends par citation. Peux-tu m'expliquer ce qu'il faut que je colle dans la fenêtre de gauche?

          Merci.
          0
      2. Contributeur sécurité
        oui je sais que c'est dans la restauration ce qui a été trouvé mais on ne desactivera que a la fin!

        ___________

        scan avec antivir en mode sans echec pour voir

        _____________

        Télécharge MSNFix de Laurent
        http://sosvirus.changelog.fr/MSNFix.zip

        Décompresse-le et double clic sur le fichier MSNFix.bat.
        - Exécute l'option R.
        --Si l'infection est détectée, exécute l'option N
        - Sauvegarde ce rapport puis fais un copier/coller de ce rapport sur le forum.

        Note :
        Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal
        Sauvegarder et fermer le rapport pour que Windows termine de se lancer normalement.

        envoyer le fichier [b] C:\DOCUME~1\florian\Bureau\Upload_Me.zip /b sur http://upload.changelog.fr pour faire evoluer msnfix
        0
        1. Ok, si c'était facile ça serait pas cool!! lol

          Je joins le rapport msnfix qui s'est avéré négatif appriori.

          MSNFix 1.720-1

          C:\Documents and Settings\Morel\Bureau\R‚paration problŠmes\MSNFix\MSNFix
          Fix exécuté le 06/06/2008 - 0:34:30,10 By Morel
          mode normal

          ************************ Recherche les fichiers présents

          Aucun Fichier trouvé

          ************************ Recherche les dossiers présents

          Aucun dossier trouvé

          ************************ Fichiers suspects

          /!\ ces fichiers nécessitent un avis expérimenté avant toute intervention

          [C:\WINDOWS\system32\Wintdist.exe] 45C6625F80227F104820B5E15673C9FA

          [color=#FF0000][b]==>[/b][/color] SVP merci d'envoyer le fichier [b] C:\DOCUME~1\Morel\Bureau\Upload_Me.zip [/b] sur http://upload.changelog.fr

          ************************ HKLM\...\Winlogon\Userinit

          Userinit = C:\WINDOWS\system32\userinit.exe,

          Important : http://msnfix.changelog.fr/index.php/2008/05/18/32-alerte

          ------------------------------------------------------------------------
          Auteur : !aur3n7 Contact: https://www.ionos.fr/
          ------------------------------------------------------------------------

          --------------------------------------------- END ---------------------------------------------

          Je vais retenter un scan avec antivir en espérant que l'ordi reste allumé assez longtemps!

          Pour le fichier msnfix c'est une mise à jour si j'ai bien compris? Je teste ça aussi.

          Merci encore.

          A plus.
          0
      3. Attention, la désinfection Malwarebytes n'a pas marché...Les trojans se trouvent dans la restauration du système...
        0
        1. Contributeur sécurité
          scan avec antivir en mode sans echec pour voir
          0
          1. Contributeur sécurité
            ok c'est mieux

            tu n'as pas d'anti espion

            scan avec malwarebytes antimal ware que tu gardera et spybot

            Malwarebytes Anti-Malware: http://www.malwarebytes.org/mbam/program/mbam-setup.exe
            Tutoriel Malwarebytes Anti-Malware: https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm

            colle moi le rapport malwarebytes après avoir viré ce qui a été trouvé
            ______________

            spybot:
            https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/26157.html

            ____________

            scan avec antivir que tu as et colle le rapport

            pour protéger gratos ton ordi

            https://www.commentcamarche.net/telecharger/ 4 securite

            mettre un antivirus

            AVAST en français ou ANTIVIR (en anglais mais très efficace)
            https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
            -------------
            des anti-espions :
            MALWAREBYTES ANTIMALWARE + SPYBOT
            +
            SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

            Rq : spybot et ad-aware on sorti de nouvelles versions cette année vérifiez que vous avez la dernière version
            --------
            un pare feu :
            celui de Windows ou mieux KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)

            https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
            https://manuelsdaide.com/contact/
            http://www.open-files.com/forum/index.php?showtopic=29277
            https://www.commentcamarche.net/telecharger/ 157 zonealarm

            -----------

            CCLEANER pour effacer les traces de surf
            0
            1. Bonjour,

              Je m'excuse du retard de mes réponses mais avec un ordi qui s'arrête n'importe quand c'est parfois difficille!

              Voici le rapport Malwarebytes' Anti-Malware 1.14
              Version de la base de données: 821

              16:01:07 04/06/2008
              mbam-log-6-4-2008 (16-00-32).txt

              Type de recherche: Examen complet (C:\|)
              Eléments examinés: 102201
              Temps écoulé: 1 hour(s), 13 minute(s), 56 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 0
              Valeur(s) du Registre infectée(s): 0
              Elément(s) de données du Registre infecté(s): 0
              Dossier(s) infecté(s): 0
              Fichier(s) infecté(s): 4

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Valeur(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Elément(s) de données du Registre infecté(s):
              (Aucun élément nuisible détecté)

              Dossier(s) infecté(s):
              (Aucun élément nuisible détecté)

              Fichier(s) infecté(s):
              C:\System Volume Information\_restore{CCB06137-1A08-44E7-92AE-4D7041FAD497}\RP424\A0111626.exe (Trojan.Downloader) -> No action taken.
              C:\System Volume Information\_restore{CCB06137-1A08-44E7-92AE-4D7041FAD497}\RP425\A0112643.exe (Trojan.Downloader) -> No action taken.
              C:\System Volume Information\_restore{CCB06137-1A08-44E7-92AE-4D7041FAD497}\RP429\A0126859.exe (Trojan.Agent) -> No action taken.
              C:\System Volume Information\_restore{CCB06137-1A08-44E7-92AE-4D7041FAD497}\RP429\A0126860.exe (Trojan.Agent) -> No action taken.

              Le rapport Antivir demande plus de temps et l'ordi s'éteint avant la fin, Super quoi!!

              A plus.
              0
          2. Re le monde,

            Je vous joins le rapport Hijackthis, merci de me dire si vous voyez quelque chose de suspect.
            L'ordi de mon père s'arrête encore super souvent mais je pense que ça vient d'avantage de l'alimentation.

            Merci en tout cas de vos réponses rapides, c'est apprécié!

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 23:46:07, on 03/06/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16640)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            C:\WINDOWS\RTHDCPL.EXE
            C:\Program Files\Multimedia Card Reader\shwicon2k.exe
            C:\WINDOWS\system32\LVCOMSX.EXE
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\MSN Messenger\msnmsgr.exe
            C:\Program Files\MSI\DigiCell\DigiCell.exe
            C:\Program Files\Logitech\SetPoint\SetPoint.exe
            C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
            C:\OLIFAXVX\TOOLBAR.EXE
            C:\WINDOWS\system32\ntvdm.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            C:\WINDOWS\system32\drivers\CDAC11BA.EXE
            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\MSN Messenger\usnsvc.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Documents and Settings\Morel\Bureau\HiJackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
            O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
            O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
            O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
            O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
            O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
            O4 - Startup: Barre d'Outils Olitec.lnk = C:\OLIFAXVX\TOOLBAR.EXE
            O4 - Startup: Moniteur Fax-Voix.lnk = C:\OLIFAXVX\MONITEUR.EXE
            O4 - Global Startup: DigiCell.lnk = C:\Program Files\MSI\DigiCell\DigiCell.exe
            O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
            O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
            O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O15 - ESC Trusted Zone: http://*.update.microsoft.com
            O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0) - http://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
            O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: LVSrvLauncher - Labtec Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
            0
            1. Contributeur sécurité
              ok il a viré des choses pour verifier:

              ensuite remettre un rapport hijackhtis et idre les soucis
              0
              1. Contributeur sécurité
                slt pour virer les lignes (c'est une infection msn)
                il faut essayer msnfix ou sdfix

                Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
                http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
                Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
                • Redémarre ton ordinateur
                • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
                • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
                • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
                • Choisis ton compte.
                Déroule la liste des instructions ci-dessous :
                • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
                • Appuie sur Y pour commencer le processus de nettoyage.
                • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                • Appuie sur une touche pour redémarrer le PC.
                • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
                • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum

                ______________
                ensuite remettre un rapport hijackhtis et idre les soucis
                0
                1. Salut,

                  En effet je pense que c'est sur msn que j'ai chopé quelque chose.
                  Le rapport sdfix me donne cela:

                  [b]SDFix: Version 1.187 [/b]
                  Run by Morel on 03/06/2008 at 18:51

                  Microsoft Windows XP [version 5.1.2600]
                  Running From: C:\SDFix

                  [b]Checking Services [/b]:

                  Restoring Windows Registry Values
                  Restoring Windows Default Hosts File

                  Rebooting

                  [b]Checking Files [/b]:

                  Trojan Files Found:

                  C:\WINDOWS\system32\^%%^%^~1.exe - Deleted
                  C:\WINDOWS\system32\^%%^%^~1.exe - Deleted
                  C:\Documents and Settings\Morel\real.txt - Deleted
                  C:\WINDOWS\system32\real.txt - Deleted

                  Removing Temp Files

                  [b]ADS Check [/b]:

                  [b]Final Check [/b]:

                  catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2008-06-03 18:59:43
                  Windows 5.1.2600 Service Pack 2 NTFS

                  scanning hidden processes ...

                  scanning hidden services & system hive ...

                  scanning hidden registry entries ...

                  scanning hidden files ...

                  scan completed successfully
                  hidden processes: 0
                  hidden services: 0
                  hidden files: 0

                  [b]Remaining Services [/b]:

                  Authorized Application Key Export:

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                  "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                  "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
                  "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
                  "C:\\Program Files\\Steam\\SteamApps\\bobjameshoward\\counter-strike source\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\bobjameshoward\\counter-strike source\\hl2.exe:*:Enabled:hl2"
                  "C:\\Documents and Settings\\Morel\\Bureau\\steamapps\\bobjameshoward\\counter-strike source\\hl2.exe"="C:\\Documents and Settings\\Morel\\Bureau\\steamapps\\bobjameshoward\\counter-strike source\\hl2.exe:*:Enabled:hl2"
                  "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
                  "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
                  "C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
                  "C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Ex‚cuter une DLL en tant qu'application"
                  "C:\\Program Files\\Steam\\SteamApps\\bobjameshoward\\day of defeat source\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\bobjameshoward\\day of defeat source\\hl2.exe:*:Enabled:hl2"
                  "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
                  "C:\\Program Files\\Steam\\steam.exe"="C:\\Program Files\\Steam\\steam.exe:*:Disabled:Steam"

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                  "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                  "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
                  "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
                  "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

                  [b]Remaining Files [/b]:

                  File Backups: - C:\SDFix\backups\backups.zip

                  [b]Files with Hidden Attributes [/b]:

                  Wed 13 Oct 2004 1,694,208 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe"
                  Wed 16 Apr 2008 6,104,632 A..H. --- "C:\Program Files\Picasa2\setup.exe"
                  Thu 30 Nov 2006 0 A.SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\Cache\Indiv01.tmp"
                  Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0a67b6c406b1d7e0f5c1e6f6d44a3f6e\BIT6.tmp"
                  Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\18b19374451d28a8fbaf1939cf31ff45\BIT9.tmp"
                  Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\22fb973e059470cc1b5d76c4ae605351\BITD.tmp"
                  Sat 10 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\BIT3.tmp"
                  Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\26924cbc8132a10b438ce6e2b49d4652\BIT5.tmp"
                  Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2769b111678c52099a3b3123b12f2325\BITA.tmp"
                  Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\30285791903730fbf957a83562db4ff4\BIT7.tmp"
                  Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\9e870549834e2bceb796e44a1e3ac6f5\BITC.tmp"
                  Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\cb8921d0c7830b2f33c00fa4c8a10d17\BIT8.tmp"
                  Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d77b9b5b8fed23dd91f50d167cce60d3\BITB.tmp"

                  [b]Finished![/b]
                  0
              2. Salut,

                1) tu dois installer Hijackthis son emplacement
                C:\Programme\HijackThis\HijackThis.exe ou C:\Programme\trendmicro\HijackThis\HijackThis.exe
                https://www.malekal.com/tutoriel-hijackthis/
                voir tutorial

                2) En mode sans échec, tu peux fixer les lignes suivantes. Détrompe-toi, fixer les lignes ne va pas éliminer l'infection

                F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\^%% ^% ^% %%^% ^%%^ % %^ %%%^% %% % % %^ %^% .exe
                R3 - URLSearchHook: (no name) - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file)
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\^%% ^% ^% %%^% ^%%^ % %^ %%%^% %% % % %^ %^% .exe
                O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe

                3) Désinstalle Avast https://www.avast.com/fr-fr/uninstall-utility
                et installe Antivir http://www.commentcamarche.net/telecharger/telecharger 55 antivir personal

                Fais un scan en mode sans échec avec Antivir et colle le rapport d'analyse
                tutorial https://www.malekal.com/avira-free-security-antivirus-gratuit/

                Applique tout ceci,
                après on avisera

                Zor
                0