Virus msn...

Bonjour,
Voila, je crois avoir attrapé un virus msn je ne sais pas où (sa devait arriver sans antivirus...) et il essaye de se transmettre à tout mes contacts en leur demandant de cliquer sur un lien... Alors si quelqu'un pourrait me conseiller un logiciel ou la démarche à suivre pour éliminer ce virus une bonne fois pour toute... merci beaucoup d'avance!!!
Configuration: Windows XP
Internet Explorer 6.0

65 réponses

Résumé de la discussion

Une suspicion de virus MSN qui se propage par un lien est évoquée sur un système Windows XP équipé d'Internet Explorer 6.0 et sans antivirus actif. Les échanges intègrent des analyses techniques à l'aide d'outils comme MSNFix et HijackThis, avec des rapports détaillant fichiers, dossiers et processus susceptibles d'être liés à l'infection. Des éléments des réponses évoquent des composants McAfee et d'autres services Windows, ce qui peut orienter vers un nettoyage approfondi et des vérifications du démarrage. En cas de doute persistant, des vérifications complémentaires en mode sans échec et une évaluation croisée des éléments du registre et des services pourraient préciser l'état réel.

Bobot (l’IA à votre service)
  1. Oui oui elles sont en cours!
    Bonne continuation a toi ossi! ciao!
    0
    1. Alors voilà le rapport de TCleaner:

      -->- Recherche:

      C:\_OtMoveIt: trouvé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
      C:\Documents and Settings\Nico.MON-ORDI\Bureau\HijackThis.lnk: trouvé !
      C:\Documents and Settings\Nico.MON-ORDI\Bureau\OtMoveIt2.exe: trouvé !
      C:\Documents and Settings\Nico.MON-ORDI\Bureau\HJTInstall.exe: trouvé !
      C:\Documents and Settings\Nico.MON-ORDI\Recent\HijackThis.lnk: trouvé !
      C:\Program Files\Trend Micro\HijackThis: trouvé !
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !

      Corbeille vidée!
      Fichiers temporaires nettoyés !
      ---------------------------------
      -->- Suppression:
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
      C:\Documents and Settings\Nico.MON-ORDI\Bureau\HijackThis.lnk: supprimé !
      C:\Documents and Settings\Nico.MON-ORDI\Bureau\OtMoveIt2.exe: supprimé !
      C:\Documents and Settings\Nico.MON-ORDI\Bureau\HJTInstall.exe: supprimé !
      C:\Documents and Settings\Nico.MON-ORDI\Recent\HijackThis.lnk: supprimé !
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
      C:\_OtMoveIt: supprimé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
      C:\Program Files\Trend Micro\HijackThis: supprimé !

      Je crois que l'infection a belle et bien été supprimée! Merci encore sKe 69 de m'avoir aidé et surtout de m'avoir fourni une protection qui tiens la route ^^
      0
      1. Contributeur sécurité
        tout le plaisir fu pour moi ^^

        Fais bien les étapes C et D , c'est très important !

        Bonne continuation à toi ...

        A + =)
        0
    2. Et bien merci beaucoup pour tout ce que tu as fait et tout ce que tu m'a conseillé, je vais aller voir tous ces sites (et faire un peu plus attention désormais ^^) et finaliser en réalisant toutes les opérations demandées. Prochaines nouvelles et rapports au post suivant!
      0
      1. Contributeur sécurité
        nous y voilà !... ton PC est sécurisée correctement ...
        mais je te rappelle que le meilleurs antivirus reste encore la personne qui est devant l'écran ... !

        Fais ce-ci pour finir :

        A- Télécharges ToolsCleaner (de A.Rothstein) sur ton Bureau.
        http://pc-system.fr/

        Lances le .
        *Cliques sur Recherche et laisses le scan se terminer (cela peut être long).
        *Cliques sur Suppression pour finaliser.
        *Tu peux, si tu le souhaites, te servir des Options facultatives
        *Click sur "quitter" pour générer un rapport :
        ---> Postes le (TCleaner.txt), il se trouve à la racine de ton disque dur (C:\).

        Note : Ce petit soft va te nettoyer tout les trucs dont on c'est servi pour la désinfection ( tu n'en as plus besoin ! ) .
        Supprimes tout les outils , dossiers ou rapports concernant la désinfection que Toolsclaener2 n'a pas supprimé .

        Puis enfin supprimes Toolscleaner2 ... ( gardes CCleaner et Malwarebytes : très utile ! )

        B- refait un coup de Ccleaner ( registre compris )

        C- Quelque mise à jours s'imposent :
        Tu devrais mettre à jour IE ( tu as l'ancienne version 6 ) et Java ( des versions pas à jour ont des failles de sécurité...) .
        Je te conseille donc de les mettre à jour:
        *IE 7 ici

        *et pour la console Java :
        aller sur : Démarrer > Panneau de configuration > Icône Java > onglet Mise à jour > "Mettre à jour maintenant" > cocher la case "Automatiser la détection des mises à jour".

        D- Un petit check-up maintenant, un peu long mais fort conseiller :

        ( étape 1 à faire de suite ! et le reste dès que tu peut mais ne tardes pas trop ;) )

        1-Restauration système
        *Désactives ta restauration :
        Cliques droit sur poste de travail/propriétés/Restauration système/coche la case désactiver la restauration, appliquer, OK
        --->Redémarres ton PC
        *Réactives ta restauration :
        Cliques droit sur poste de travail/propriétés/Restauration système/décoche la case désactiver la restauration, appliquer, OK
        --->Redémarres ton PC

        2-Nettoyage et Défragmentation de tes Disques
        *Nettoyage :
        Clic droit sur "poste de travail" ==>"ouvrir" ==>clic droit sur le disque C ==>Propriétés ==>onglet "Général"
        Cliques sur le bouton "nettoyage de disque", OK
        tu le fais pour chacun de tes disques

        *Vérifications des erreurs :
        Clic droit sur "poste de travail" ==>"ouvrir" ==>clic droit sur le disque C ==>Propriétés ==>onglet "Outil"
        "Vérifier maintenant", une boîte s'ouvre, cocher les cases :
        -réparer automatiquement les erreurs...
        -rechercher et tenter une récupération...
        --->Démarrer, ok
        Note : s'il te dis de redémarrer ton Pc pour le faire , tu redémarres et tu laisses faire, cela prend un peu de temps c'est normal
        tu le fais pour chacun de tes disques

        ensuite toujours dans le même onglet tu choisis :
        *Défragmentation :
        "défragmenter maintenant", OK
        une boîte s'ouvre, tu sélectionnes le disque à défragmenter, et tu cliques sur "analyser", puis après l'analyse, "défragmenter" . OK
        tu le fais pour chacun de tes disques

        **********************************************************
        E - infos diverses très intéressantes :

        * lien sympa pour paramétrer et sécurisé son MSN :
        http://pageperso.aol.fr/loraline60/MSN.htm

        * Comportement à adopter avec son PC : http://assiste.com.free.fr/p/abc/a/safe_cex.html

        * Rappel sur les principales causes d'infection :

        -> L'utilisation de cracks ou keygens est à proscrire, de même que le surf sur les sites de téléchargement de ceux-ci :

        Les dangers des cracks : http://forum.malekal.com/ftopic893.php

        Le crack dans toute sa splendeur, journal d'une infection attendue :
        https://forum.zebulon.fr/topic/93281-pr%C3%A9vention-le-crack-dans-toute-sa-splendeur/

        -> Le P2P ( l'utilisation de logiciels comme eMule, Sharazaa, LimeWire, Bit torrent):

        Les conséquences du P2P : https://forum.zebulon.fr/topic/85544-pr%C3%A9vention-le-p2p-et-ses-cons%C3%A9quences/

        Pourquoi éviter le P2P : http://www.speedweb1.org/forum-tesgaz/viewtopic.php?t=1793
        https://lexpansion.lexpress.fr/actualite-economique/

        -> Prévention sur deux autres types d'infection d'actualité :

        MSN prévention : https://forum.zebulon.fr/topic/130590-infection-par-msn-ou-wlm/

        Infection par supports amovibles (clefs usb, flash, DD externes ..) https://forum.zebulon.fr/topic/131959-infections-par-supports-amovibles/
        https://forum.malekal.com/viewtopic.php?f=45&t=5544
        *************************************************************

        Voili voilou ... une fois cela fais , dis moi ce que t'en pense ... y a t'il du mieux ? ^^
        0
        1. Alors voila le rapport Hijackthis comme demandé:

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 23:24:22, on 01/07/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Tall Emu\Online Armor\oasrv.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\spoolsv.exe
          c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\WINDOWS\System32\GEARSec.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\Program Files\Dell Network Assistant\hnm_svc.exe
          C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\alg.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\Program Files\Tall Emu\Online Armor\oaui.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKLM\..\Run: [OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
          O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
          O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exe
          0
          1. Ok merci beaucoup du conseil j'ai telechargé Armor, le rapport Hijackthis est a suivre...
            0
            1. Contributeur sécurité
              Au poil ^^

              dernière étape pour tes défences , le par-feu !

              je te conseil de télécharger celui-ci :
              Armor (Gratuit biensûr ^^ ) .
              Télécharges le set-up ici : http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall

              ! Attention ! : avant toute instalation , désactiver le pare-feu de windows ! ( via paneau de config./pare-feu ) .

              Tuto pour Armor : https://www.malekal.com/tutorial-online-armor-free/

              ---> une fois ce-ci installer et tout , fais moi un dernier rapport hijackthis pour contrôler ... puis on finalisera le tout ;)
              0
              1. Contributeur sécurité
                Ps : si tu veut que "msconfig" ne se mette plus en route à chaque démarrage , sur la première fenêtre qui apparait à l'arrivée du bureau, coche la petite case et valide ... ^^
                0
            2. Voila c'est fait + le rapport:

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 22:59:36, on 01/07/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\spoolsv.exe
              c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\WINDOWS\System32\GEARSec.exe
              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              C:\Program Files\Dell Network Assistant\hnm_svc.exe
              C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Windows Live\Messenger\usnsvc.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
              O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
              O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
              0
              1. Contributeur sécurité
                Y a un petit hic ... ( avec des reste de McAfee ...)

                vas dans "démarrage"/commande "Executer" : tu tapes " msconfig "et valides ...

                Dans cette nouvelle fenêtre , tu vas sur l'onglet " sevices " :
                décoches les cases devant les services de McAfee correspondant à ces .exe :
                McAfee WSC Integration (McDetect.exe)
                McAfee.com McShield (McShield.exe)
                McAfee Task Scheduler (McTskshd.exe)
                McAfee SecurityCenter Update Manager (mcupdmgr.exe)
                McAfee Personal Firewall Service (MpfService)
                McAfee SpamKiller Server (MskService)


                --> puis valides la modif et laisse toi guider ...

                Une fois fait , postes un nouvelle hijack pour vérifier ....
                0
                1. Et bien pour le scan il m'a trouvé 2 éléments: Double Click et PWS.LD PinchlE et je les ai "corrigés" comme demandés.

                  Voila le rapport Hijackthis:

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 22:41:57, on 01/07/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Messenger\msmsgs.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\WINDOWS\System32\GEARSec.exe
                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  C:\Program Files\Dell Network Assistant\hnm_svc.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Windows Live\Messenger\usnsvc.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                  O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                  O23 - Service: McAfee WSC Integration (McDetect.exe) - Unknown owner - c:\program files\mcafee.com\agent\mcdetect.exe (file missing)
                  O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe (file missing)
                  O23 - Service: McAfee Task Scheduler (McTskshd.exe) - Unknown owner - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe (file missing)
                  O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
                  O23 - Service: McAfee Personal Firewall Service (MpfService) - Unknown owner - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe (file missing)
                  O23 - Service: McAfee SpamKiller Server (MskService) - Unknown owner - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe (file missing)
                  0
                  1. Contributeur sécurité
                    impeccable ... rapport vierge ^^

                    Il faut maintenant s'occuper du reste :

                    Tout d'abors l'anti-spyware :

                    -Télécharges Spybot search and destroy (version complète et gratuite) :
                    https://www.safer-networking.org/?page=download

                    Installes le , mets le à jour et lance "la vaccination"--->vaccines tant que le compteur "Non protégé" n'arrive pas à 0.

                    Aide pour utilisation Spybot ici (merci Balltrap ;) ) : http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

                    Lances une "recherche" :
                    une fois le scan terminé, vérifies que tout ce qu'il a trouvé (surtout ce qui est en rouge) soit valider puis fait "corriger les prb" .
                    PS : dans certains cas, il te sera demander de planifier la suite des "corrections" au redémarrage du PC , acceptes .

                    dis moi ce que cela à donner pour le scan et postes moi un nouveau rapport hijackthis pour contrpoler ...
                    0
                    1. Un scan complet! voila le rapport:

                      Avira AntiVir Personal
                      Report file date: mardi 1 juillet 2008 20:53

                      Scanning for 1371745 virus strains and unwanted programs.

                      Licensed to: Avira AntiVir PersonalEdition Classic
                      Serial number: 0000149996-ADJIE-0001
                      Platform: Windows XP
                      Windows version: (Service Pack 2) [5.1.2600]
                      Boot mode: Save mode
                      Username: Nico
                      Computer name: MON-ORDI

                      Version information:
                      BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
                      AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 09:02:56
                      AVSCAN.DLL : 8.1.1.0 53505 Bytes 07/02/2008 08:43:37
                      LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 08:41:23
                      LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 08:28:40
                      ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
                      ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 18:12:58
                      ANTIVIR2.VDF : 7.0.5.20 142336 Bytes 30/06/2008 18:13:02
                      ANTIVIR3.VDF : 7.0.5.30 47616 Bytes 01/07/2008 18:13:03
                      Engineversion : 8.1.0.59
                      AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
                      AESCRIPT.DLL : 8.1.0.44 278907 Bytes 01/07/2008 18:13:42
                      AESCN.DLL : 8.1.0.22 119157 Bytes 01/07/2008 18:13:40
                      AERDL.DLL : 8.1.0.20 418165 Bytes 01/07/2008 18:13:39
                      AEPACK.DLL : 8.1.1.6 364918 Bytes 01/07/2008 18:13:35
                      AEOFFICE.DLL : 8.1.0.20 192891 Bytes 01/07/2008 18:13:32
                      AEHEUR.DLL : 8.1.0.32 1274231 Bytes 01/07/2008 18:13:30
                      AEHELP.DLL : 8.1.0.15 115063 Bytes 01/07/2008 18:13:15
                      AEGEN.DLL : 8.1.0.29 307573 Bytes 01/07/2008 18:13:13
                      AEEMU.DLL : 8.1.0.6 430451 Bytes 01/07/2008 18:13:09
                      AECORE.DLL : 8.1.0.31 168310 Bytes 01/07/2008 18:13:06
                      AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 17:07:53
                      AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 10:37:50
                      AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:26:47
                      AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 17:07:49
                      AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                      AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 08:31:31
                      SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                      SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 17:08:39
                      NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                      RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 14:37:25
                      RCTEXT.DLL : 8.0.32.0 86273 Bytes 06/03/2008 12:02:11

                      Configuration settings for the scan:
                      Jobname..........................: Complete system scan
                      Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                      Logging..........................: low
                      Primary action...................: interactive
                      Secondary action.................: ignore
                      Scan master boot sector..........: on
                      Scan boot sector.................: on
                      Boot sectors.....................: C:, D:,
                      Scan memory......................: on
                      Process scan.....................: on
                      Scan registry....................: on
                      Search for rootkits..............: on
                      Scan all files...................: All files
                      Scan archives....................: on
                      Recursion depth..................: 20
                      Smart extensions.................: on
                      Macro heuristic..................: on
                      File heuristic...................: high

                      Start of the scan: mardi 1 juillet 2008 20:53

                      Starting search for hidden objects.
                      The driver could not be initialized.

                      The scan of running processes will be started
                      Scan process 'avscan.exe' - '1' Module(s) have been scanned
                      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                      Scan process 'explorer.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'lsass.exe' - '1' Module(s) have been scanned
                      Scan process 'services.exe' - '1' Module(s) have been scanned
                      Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                      Scan process 'csrss.exe' - '1' Module(s) have been scanned
                      Scan process 'smss.exe' - '1' Module(s) have been scanned
                      11 processes with 11 modules were scanned

                      Starting master boot sector scan:
                      Master boot sector HD0
                      [INFO] No virus was found!
                      Master boot sector HD1
                      [INFO] No virus was found!
                      [WARNING] Le périphérique n'est pas prêt.
                      Master boot sector HD2
                      [INFO] No virus was found!
                      [WARNING] Le périphérique n'est pas prêt.
                      Master boot sector HD3
                      [INFO] No virus was found!
                      [WARNING] Le périphérique n'est pas prêt.
                      Master boot sector HD4
                      [INFO] No virus was found!
                      [WARNING] Le périphérique n'est pas prêt.
                      Master boot sector HD5
                      [INFO] No virus was found!
                      [WARNING] Le périphérique n'est pas prêt.

                      Start scanning boot sectors:
                      Boot sector 'C:\'
                      [INFO] No virus was found!
                      Boot sector 'D:\'
                      [INFO] No virus was found!

                      Starting to scan the registry.
                      The registry was scanned ( '19' files ).

                      Starting the file scan:

                      Begin scan in 'C:\'
                      C:\pagefile.sys
                      [WARNING] The file could not be opened!
                      Begin scan in 'D:\' <Sauvegarder>

                      End of the scan: mardi 1 juillet 2008 21:54
                      Used time: 1:00:30 min

                      The scan has been done completely.

                      8676 Scanning directories
                      785871 Files were scanned
                      0 viruses and/or unwanted programs were found
                      0 Files were classified as suspicious:
                      0 files were deleted
                      0 files were repaired
                      0 files were moved to quarantine
                      0 files were renamed
                      1 Files cannot be scanned
                      785871 Files not concerned
                      3626 Archives were scanned
                      6 Warnings
                      0 Notes
                      0
                      1. Contributeur sécurité
                        ok tu as oublier quelques ligne non ?

                        1- Fermes toutes tes applications et déconnectes toi .

                        Relances Hijackthis mais click sur " Do a scan only "
                        Tu vois donc apparaitre le résultat du scan : une multitudes de lignes ,chacunes précédées d'un carré vide .
                        Tu vas cliquer sur les carrés des lignes suivantes :

                        O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - C:\WINDOWS\system32\shdocvw.dll
                        O9 - Extra 'Tools' menuitem: McAfee Anti-Phishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - C:\WINDOWS\system32\shdocvw.dll
                        O23 - Service: McAfee WSC Integration (McDetect.exe) - Unknown owner - c:\program files\mcafee.com\agent\mcdetect.exe (file missing)
                        O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe (file missing)
                        O23 - Service: McAfee Task Scheduler (McTskshd.exe) - Unknown owner - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe (file missing)
                        O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
                        O23 - Service: McAfee Personal Firewall Service (MpfService) - Unknown owner - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe (file missing)
                        O23 - Service: McAfee SpamKiller Server (MskService) - Unknown owner - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe (file missing)

                        Tu cliques en bas sur le bouton FIX CHECKED et valides .

                        2- refais un coup de CCleaner ( registre compris )

                        3- impératif : redémarres en mode sans échec

                        lances un scan complet de ton PC avec AntiVir ; mets tout ce qu'il peut trouver en "quarantaine " ....

                        Redémarres ton PC une fois finis et postes moi le rapport obtenu pour analyse ....
                        0
                        1. Ok j'ai tout fait comme indiqué et voila le rapport Hijackthis:

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 20:19:53, on 01/07/2008
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\Program Files\Messenger\msmsgs.exe
                          C:\Program Files\Bonjour\mDNSResponder.exe
                          C:\WINDOWS\System32\GEARSec.exe
                          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          C:\Program Files\Dell Network Assistant\hnm_svc.exe
                          C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Windows Live\Messenger\usnsvc.exe
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                          O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - C:\WINDOWS\system32\shdocvw.dll
                          O9 - Extra 'Tools' menuitem: McAfee Anti-Phishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - C:\WINDOWS\system32\shdocvw.dll
                          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                          O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                          O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                          O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
                          O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                          O23 - Service: McAfee WSC Integration (McDetect.exe) - Unknown owner - c:\program files\mcafee.com\agent\mcdetect.exe (file missing)
                          O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe (file missing)
                          O23 - Service: McAfee Task Scheduler (McTskshd.exe) - Unknown owner - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe (file missing)
                          O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
                          O23 - Service: McAfee Personal Firewall Service (MpfService) - Unknown owner - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe (file missing)
                          O23 - Service: McAfee SpamKiller Server (MskService) - Unknown owner - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe (file missing)
                          0
                          1. Contributeur sécurité
                            1- Fermes toutes tes applications et déconnectes toi .

                            Relances Hijackthis mais click sur " Do a scan only "
                            Tu vois donc apparaitre le résultat du scan : une multitudes de lignes ,chacunes précédées d'un carré vide .
                            Tu vas cliquer sur les carrés des lignes suivantes :

                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                            O2 - BHO: (no name) - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - (no file)
                            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                            O23 - Service: McAfee WSC Integration (McDetect.exe) - Unknown owner - c:\program files\mcafee.com\agent\mcdetect.exe (file missing)
                            O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe (file missing)
                            O23 - Service: McAfee Task Scheduler (McTskshd.exe) - Unknown owner - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe (file missing)
                            O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
                            O23 - Service: McAfee Personal Firewall Service (MpfService) - Unknown owner - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe (file missing)
                            O23 - Service: McAfee SpamKiller Server (MskService) - Unknown owner - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe (file missing)

                            Tu cliques en bas sur le bouton FIX CHECKED et valides .

                            2- refait un coup de CCleaner ( registre compris )

                            Ton nouvel antivirus gratuis , le meilleur du momment :

                            3- Télécharges AntiVir ici :
                            https://www.pcastuces.com/logitheque/antivir.htm
                            ou
                            https://www.avira.com/

                            Anti-virus gratuit ( en anglais )
                            Aide AntiVir : https://www.malekal.com/avira-free-security-antivirus-gratuit/

                            Installes le et mets le à jour (fais ce-ci très régulièrement ) .

                            Si jamais tu as un problème avec la mise à jour , regardes ici :
                            http://www.commentcamarche.net/faq/sujet 8622 mise a jour d antivir impossible

                            Fais ce réglage :

                            ***************************************
                            Une fois AntiVir ouvert click sur configuration et coches la case "expert mode" .
                            *Puis click sur configuration en haut a droite; dans la nouvelle fenetre à gauche ->scanner -> coches "scan all files" et en dessous ->scanner priority = High
                            *coches : allow stopping the scanner, comme cela tu peux faire une pause pendant le scan si tu le desir.
                            *puis sur la droite, coches les cases suivantes :
                            scan boot sectors of selected drives
                            scan master boot sectors
                            scan memory
                            search for rootkit before scan
                            et décoches :
                            ignore off line files
                            *toujours a gauche -> scan -> deploie -> heuristique -> macrovirus heuristic = coché et en dessous -> win32 heuristic la case cochée et high detection level aussi ...

                            ---> cliques sur "OK" pour valider le réglage ...
                            ****************************************

                            Puit refais un hijack pour voir si tout est Ok et attends la suite ...
                            0
                            1. Voila!:

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 19:48:54, on 01/07/2008
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Program Files\Messenger\msmsgs.exe
                              C:\Program Files\Bonjour\mDNSResponder.exe
                              C:\WINDOWS\System32\GEARSec.exe
                              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              C:\Program Files\Dell Network Assistant\hnm_svc.exe
                              C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\Program Files\Windows Live\Messenger\usnsvc.exe
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                              O2 - BHO: (no name) - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - (no file)
                              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                              O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - C:\WINDOWS\system32\shdocvw.dll
                              O9 - Extra 'Tools' menuitem: McAfee Anti-Phishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - C:\WINDOWS\system32\shdocvw.dll
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
                              O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                              O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                              O23 - Service: McAfee WSC Integration (McDetect.exe) - Unknown owner - c:\program files\mcafee.com\agent\mcdetect.exe (file missing)
                              O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe (file missing)
                              O23 - Service: McAfee Task Scheduler (McTskshd.exe) - Unknown owner - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe (file missing)
                              O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
                              O23 - Service: McAfee Personal Firewall Service (MpfService) - Unknown owner - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe (file missing)
                              O23 - Service: McAfee SpamKiller Server (MskService) - Unknown owner - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe (file missing)
                              0
                              1. Contributeur sécurité
                                Bien ! ... maintenant refais un scan hijackthis et postes moi le nouveau rapport obtenu ...
                                0
                                1. Et voici le rapport:

                                  01/07/2008 ---- 19:39:13,40

                                  ----------------------------------
                                  §§§§§§ [McAfee] §§§§§§
                                  ----------------------------------
                                  [X] Registre

                                  -------------- [ ] rapide
                                  -- Fichier --- [ ] disque systeme
                                  ------------- [X] complete

                                  ********************
                                  [Registre]
                                  ********************

                                  Aucune entrée détectée

                                  *******************
                                  [Fichier]
                                  *******************

                                  c:\_OTMoveIt\MovedFiles\07012008_192111\Documents and Settings\All Users\Application Data\McAfee
                                  c:\_OTMoveIt\MovedFiles\07012008_192111\Documents and Settings\All Users\Application Data\McAfee.com
                                  c:\_OTMoveIt\MovedFiles\07012008_192111\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
                                  c:\_OTMoveIt\MovedFiles\07012008_192111\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
                                  c:\_OTMoveIt\MovedFiles\07012008_192111\Documents and Settings\Nico.MON-ORDI\Application Data\McAfee.com Personal Firewall
                                  c:\_OTMoveIt\MovedFiles\07012008_192111\Program Files\Dell\McAfee
                                  c:\_OTMoveIt\MovedFiles\07012008_192111\Program Files\McAfee
                                  c:\_OTMoveIt\MovedFiles\07012008_192111\Program Files\McAfee.com
                                  c:\Documents and Settings\All Users\Menu D‚marrer\Programmes\McAfee

                                  *********************
                                  [Même date]
                                  *********************

                                  [01/07/2008 ] ---> C:\hiberfil.sys
                                  [01/07/2008 ] ---> C:\resultat.txt
                                  [01/07/2008 ] ---> C:\WINDOWS\system32\mcinsctl.dll
                                  [R‚pertoire ] --- REP ---> C:\Program Files\Files

                                  Outil Aide Diagnostic By !aur3n7 Version 1.1
                                  ----------------------------------
                                  §§§§§ Fin Rapport §§§§§
                                  ----------------------------------
                                  0
                                  1. Contributeur sécurité
                                    ok ...

                                    ---> maitenant un gros coup de CCleaner ( registre compris ! )

                                    Puis ensuite, refais ce-ci pour voir ce qui reste :

                                    Double clique sur l'icone OAD pour le lancer

                                    - nom du fichier à rechercher --->tape ou fais un copier coller de : McAfee
                                    - Type de recherche : sélectionne l'option 6 puis valide ["entrée"]

                                    OAD va maintenant rechercher le fichier. Laisse le travailler jusqu'à ce qu'il en ait terminé.
                                    Le rapport de recherche s'affichera automatiquement à l’écran dès qu'il aura terminé.

                                    Note : suivant la taille des disques durs cette recherche peut prendre plusieurs minutes. Sois patient ...

                                    - Sauvegardes ce rapport sur ton Bureau et fais un copier / coller de celui-c dans ton prochain post.
                                    0
                                    1. Opération effectué! rapport:

                                      C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1 moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Back\1 moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Back moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Users\2 moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Users\1 moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Users moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Updates moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Templates moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Sounds moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Logs moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Backup moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com\VSO\Quarantine moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com\VSO\ODSLog moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com\VSO\OASLogs moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com\VSO\Data moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com\VSO moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com\download moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\update moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\RegWiz\RegApp moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\RegWiz moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\Logs\TaskScheduler moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\Logs moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\Cache moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall\data\sports moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall\data moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall\Archive moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall\appicons moved successfully.
                                      C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall moved successfully.
                                      File/Folder C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\McAfee not found.
                                      C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall moved successfully.
                                      C:\Documents and Settings\Nico.MON-ORDI\Application Data\McAfee.com Personal Firewall moved successfully.
                                      C:\Program Files\Dell\McAfee moved successfully.
                                      C:\Program Files\McAfee\SpamKiller moved successfully.
                                      C:\Program Files\McAfee moved successfully.
                                      C:\Program Files\McAfee.com\VSO\Res00 moved successfully.
                                      C:\Program Files\McAfee.com\VSO\Dat\4816 moved successfully.
                                      C:\Program Files\McAfee.com\VSO\Dat moved successfully.
                                      C:\Program Files\McAfee.com\VSO moved successfully.
                                      C:\Program Files\McAfee.com\Shared\mcuicfg\6,0,0,4 moved successfully.
                                      C:\Program Files\McAfee.com\Shared\mcuicfg moved successfully.
                                      C:\Program Files\McAfee.com\Shared moved successfully.
                                      C:\Program Files\McAfee.com\Personal Firewall\help moved successfully.
                                      C:\Program Files\McAfee.com\Personal Firewall\data\sports moved successfully.
                                      C:\Program Files\McAfee.com\Personal Firewall\data\mvtx\maps moved successfully.
                                      C:\Program Files\McAfee.com\Personal Firewall\data\mvtx moved successfully.
                                      C:\Program Files\McAfee.com\Personal Firewall\data moved successfully.
                                      C:\Program Files\McAfee.com\Personal Firewall moved successfully.
                                      C:\Program Files\McAfee.com\Microsoft CAPICOM 2.1.0.2\License moved successfully.
                                      C:\Program Files\McAfee.com\Microsoft CAPICOM 2.1.0.2\Lib\X86 moved successfully.
                                      C:\Program Files\McAfee.com\Microsoft CAPICOM 2.1.0.2\Lib moved successfully.
                                      C:\Program Files\McAfee.com\Microsoft CAPICOM 2.1.0.2 moved successfully.
                                      C:\Program Files\McAfee.com\Agent\Uninst moved successfully.
                                      C:\Program Files\McAfee.com\Agent\submgr\6,0,0,3 moved successfully.
                                      C:\Program Files\McAfee.com\Agent\submgr\6,0,0,16 moved successfully.
                                      C:\Program Files\McAfee.com\Agent\submgr moved successfully.
                                      C:\Program Files\McAfee.com\Agent\oeminfo\fr-ca\105-99 moved successfully.
                                      C:\Program Files\McAfee.com\Agent\oeminfo\fr-ca\105-98 moved successfully.
                                      C:\Program Files\McAfee.com\Agent\oeminfo\fr-ca\105-102 moved successfully.
                                      C:\Program Files\McAfee.com\Agent\oeminfo\fr-ca\105-101 moved successfully.
                                      C:\Program Files\McAfee.com\Agent\oeminfo\fr-ca\105-100 moved successfully.
                                      C:\Program Files\McAfee.com\Agent\oeminfo\fr-ca moved successfully.
                                      C:\Program Files\McAfee.com\Agent\oeminfo\fr\105-97 moved successfully.
                                      C:\Program Files\McAfee.com\Agent\oeminfo\fr\105-96 moved successfully.
                                      C:\Program Files\McAfee.com\Agent\oeminfo\fr\105-95 moved successfully.
                                      C:\Program Files\McAfee.com\Agent\oeminfo\fr\105-94 moved successfully.
                                      C:\Program Files\McAfee.com\Agent\oeminfo\fr\105-93 moved successfully.
                                      C:\Program Files\McAfee.com\Agent\oeminfo\fr moved successfully.
                                      C:\Program Files\McAfee.com\Agent\oeminfo moved successfully.
                                      C:\Program Files\McAfee.com\Agent\Custom_Uninstall moved successfully.
                                      C:\Program Files\McAfee.com\Agent\app moved successfully.
                                      C:\Program Files\McAfee.com\Agent moved successfully.
                                      C:\Program Files\McAfee.com moved successfully.

                                      OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07012008_192111
                                      0
                                      • 1
                                      • 2
                                      • 3
                                      • 4