Virus msn !

Résolu
Bonjour,
J'ai un petit probleme avec mon ordinateur. En effet, internet marche parfaitement.. Seulement des que j'utilise msn, tout se met a bloqué surtout msn mais pas mon internet. J'en conclus donc que j'ai un probleme avec mon msn .. Alors j'ai décidé de le supprimer et de le réinstallé ... Toujours le meme probleme! Je ne sais que faire ( car je ne veux pas supprimer msn ) !! Est ce que j'ai un virus ?? Si oui comment le détecter ?? Comment le supprimer ?? Aidez moi rapidement svp. Merci d'avance !
Configuration: Windows Vista
Internet Explorer 7.0

34 réponses

Résumé de la discussion

Le problème décrit concerne Windows Vista et MSN qui bloquent l'ordinateur alors que l'accès à Internet reste opérationnel, créant une incompatibilité perçue entre le client et le réseau. Plusieurs intervenants suggèrent une infection par malware ou Trojan et recommandent des scans avec Malwarebytes, HijackThis et d'autres outils pour identifier les composants malveillants présents. La meilleure réponse précise qu'une clé de registre Run et un fichier associé ont été infectés par Trojan.Agent et mis en quarantaine, confirmant une menace logicielle active. D'autres conseils suggèrent une désinstallation propre d'antivirus, l'usage d'outils gratuits comme Antivir et Ad-Aware, et évoquent des problématiques liées à MSN avec des corrections possibles.

Bobot (l’IA à votre service)
  1. Je tiens a te tenir informer que mon msn remarche normalement grace a tes conseils je t'en remercie, j'ai réussi a réinstaller java et antivir normalement. Tout va pour le mieux pour moi. Merci beaucoup !!
    1. Contributeur sécurité
      Salut !!

      refais un nouveau rapport hijackthis pour vérifier java stp

      ensuite :

      je vais quand meme te faire passer msnfix et d autres programmes pour les infections msn, on vera bien...

      Télécharger sur le bureau msnFix à cette adresse :

      (c est le numéro 14 en bas de la page) : https://www.androidworld.fr/

      Voici un tuto pour bien l installer et savoir l utiliser : https://www.androidworld.fr/
      1. 1/ C'est a geoffrey5 de repondre, un seul helper par sujet.

        2/Il (on) est benevoles il n'y a pas que toi sur le forum penses-y.
        1. Comment fait-on avec msnfix ??? Et j'ai un autre probleme avec .. java !! Tout a disparu , je ne peux plus l'utilisé .. Sa me marque " impossible, vous ne disposez pas du package suffisant " .. Je ne sais que faire , cela commence a me rendre dingue !
          1. Slt,

            Je passe lire le sujet, geoffrey5 passe MSNFix peut-etre qu'il detectera quelque chose non? MBAM a supprimé ce qu'il avait trouvé et msn ne fonctionne tjrs pas alors essaye tu verras bien. ^^

            PS: c'est juste une remarque,un conseil, je n'intervient pas ds la desinfection (nuances ^^)
            1. Alors .. Merci tout d'abord. J'ai fait la mise a niveau de Java et tout s'est bien passé.
              J'ai fait c'que tu m'avais demandé en cliquant sur les 2lignes puis sur fix checked.
              Mais mon msn ne fonctionne toujours pas normalement, je ne sais pas du tout d'ou proviens le probleme.
              Penses tu a quelque chose d'autre en particulier ? Faut t-il formater mon ordinateur ? ( dont je pense que c'est la meilleur solution mais dont je pense aussi que c'est extrémement risquer ... )
              Merci d'avance.
              1. Contributeur sécurité
                wow !! t as le feu aux fesses ou quoi ?!

                relance hijackthis en cliquant sur scan only et coches ces lignes stp :

                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [holdbolt] "C:\ProgramData\SixthMapiMapi.or7fi3"

                puis tu cliques sur fix checked.

                vas faire la mise à niveau de java à cette adresse : https://www.java.com/fr/download/manual.jsp

                et ensuite désinstalle la version antérieure.

                est ce que tu as encore des problemes avec msn ??
                1. rapprt hijackthis :

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 22:08:30, on 25/08/2008
                  Platform: Windows Vista (WinNT 6.00.1904)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16711)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Windows\System32\igfxtray.exe
                  C:\Windows\System32\hkcmd.exe
                  C:\Windows\System32\igfxpers.exe
                  C:\Windows\RtHDVCpl.exe
                  C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                  C:\Program Files\Launch Manager\HotkeyApp.exe
                  C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                  C:\Windows\system32\igfxsrvc.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Program Files\Internet Explorer\ieuser.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\Windows\Explorer.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
                  C:\Users\Fujitsu\Desktop\HiJackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                  O4 - HKLM\..\Run: [Skytel] Skytel.exe
                  O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                  O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                  O4 - HKLM\..\Run: [HotkeyApp] "C:\Program Files\Launch Manager\HotkeyApp.exe"
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKCU\..\Run: [holdbolt] "C:\ProgramData\SixthMapiMapi.or7fi3"
                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                  O13 - Gopher Prefix:
                  O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                  O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                  O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                  O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Launch Manager\WisLMSvc.exe
                  1. rapport combofix ...

                    ComboFix 08-08-24.03 - Fujitsu 2008-08-25 22:00:52.1 - NTFSx86
                    Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1161 [GMT 2:00]
                    Endroit: C:\Users\Fujitsu\Desktop\ComboFix.exe
                    * Création d'un nouveau point de restauration
                    .

                    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                    .

                    C:\Users\Fujitsu\AppData\Roaming\Microsoft\Windows\Cookies\fujitsu@serving-sys[1].txt
                    C:\Windows\system32\x64

                    .
                    ((((((((((((((((((((((((((((( Fichiers créés 2008-07-25 to 2008-08-25 ))))))))))))))))))))))))))))))))))))
                    .

                    Pas de nouveau fichier créé dans cet espace de temps

                    .
                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    2008-08-25 10:44 --------- d-----w C:\ProgramData\DvdInside
                    2008-08-25 09:59 --------- d-----w C:\ProgramData\Avira
                    2008-08-25 09:59 --------- d-----w C:\Program Files\Avira
                    2008-08-25 09:43 --------- d-----w C:\Users\Fujitsu\AppData\Roaming\Malwarebytes
                    2008-08-25 09:43 --------- d-----w C:\ProgramData\Malwarebytes
                    2008-08-25 09:43 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
                    2008-08-25 09:31 --------- d-----w C:\Users\Fujitsu\AppData\Roaming\LimeWire
                    2008-08-24 21:23 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
                    2008-08-24 20:50 --------- d-----w C:\Program Files\Spybot - Search & Destroy
                    2008-08-24 01:08 --------- d-----w C:\Program Files\Windows Mail
                    2008-08-23 21:12 --------- d-----w C:\ProgramData\Admin Inter 1 Mags
                    2008-08-17 13:01 38,472 ----a-w C:\Windows\system32\drivers\mbamswissarmy.sys
                    2008-08-17 13:01 17,144 ----a-w C:\Windows\system32\drivers\mbam.sys
                    2008-07-31 21:06 --------- d-----w C:\ProgramData\WLInstaller
                    2008-07-26 09:53 --------- d-----w C:\Program Files\Common Files\MAGIX Shared
                    2008-07-15 23:48 2,048 ----a-w C:\Windows\System32\tzres.dll
                    2008-07-12 23:15 --------- d-----w C:\Program Files\Common Files\InstallShield
                    2008-07-12 23:14 --------- d--h--w C:\Program Files\InstallShield Installation Information
                    2008-07-09 02:38 174 --sha-w C:\Program Files\desktop.ini
                    2008-06-27 03:54 826,368 ----a-w C:\Windows\System32\wininet.dll
                    2008-06-27 03:54 56,320 ----a-w C:\Windows\System32\iesetup.dll
                    2008-06-27 03:54 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
                    2008-06-27 03:54 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
                    2008-06-26 00:34 7,964,672 ----a-w C:\Windows\System32\NlsLexicons0024.dll
                    2008-06-26 00:33 9,892,864 ----a-w C:\Windows\System32\NlsLexicons000a.dll
                    2008-06-25 19:11 --------- d-----w C:\ProgramData\eMule
                    2008-06-25 19:08 --------- d-----w C:\Program Files\eMule
                    2008-06-25 11:35 --------- d-----w C:\Users\Fujitsu\AppData\Roaming\OpenOffice.org2
                    2008-06-25 09:46 --------- d-----w C:\Program Files\Rockstar Games
                    2008-06-19 03:25 61,440 ----a-w C:\Windows\System32\winipsec.dll
                    2008-06-19 03:25 361,984 ----a-w C:\Windows\System32\IPSECSVC.DLL
                    2008-06-19 03:25 28,672 ----a-w C:\Windows\System32\FwRemoteSvr.dll
                    2008-06-19 03:25 272,896 ----a-w C:\Windows\System32\polstore.dll
                    2008-06-17 13:14 499,712 ----a-w C:\Windows\System32\msvcp71.dll
                    2008-06-12 06:54 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
                    2008-06-12 06:54 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
                    2008-06-12 01:21 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
                    2008-06-05 01:24 87,040 ----a-w C:\Windows\System32\msoert2.dll
                    2008-06-05 01:24 39,424 ----a-w C:\Windows\System32\ACCTRES.dll
                    2008-06-05 01:24 205,824 ----a-w C:\Windows\System32\msoeacct.dll
                    2008-06-05 01:23 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
                    2008-06-05 01:23 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
                    2008-06-05 01:23 542,720 ----a-w C:\Windows\System32\sysmain.dll
                    2008-06-05 01:23 502,784 ----a-w C:\Windows\System32\wlansvc.dll
                    2008-06-05 01:23 47,104 ----a-w C:\Windows\System32\wlanapi.dll
                    2008-06-05 01:23 297,984 ----a-w C:\Windows\System32\wlansec.dll
                    2008-06-05 01:23 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
                    2008-06-05 01:23 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
                    2008-06-05 01:23 2,923,520 ----a-w C:\Windows\explorer.exe
                    2008-06-05 01:23 194,560 ----a-w C:\Windows\System32\WebClnt.dll
                    2008-06-05 01:22 49,664 ----a-w C:\Windows\System32\csrsrv.dll
                    2008-06-05 01:22 376,320 ----a-w C:\Windows\System32\winsrv.dll
                    2008-06-05 01:18 414,208 ----a-w C:\Windows\System32\msscp.dll
                    2008-06-05 01:18 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll
                    2008-06-05 01:17 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
                    2008-06-05 01:17 7,680 ----a-w C:\Windows\System32\spwmp.dll
                    2008-06-05 01:17 4,096 ----a-w C:\Windows\System32\dxmasf.dll
                    2008-06-05 01:17 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
                    2008-06-05 01:16 86,016 ----a-w C:\Windows\System32\icfupgd.dll
                    2008-06-05 01:16 61,952 ----a-w C:\Windows\System32\cmifw.dll
                    2008-06-05 01:16 396,800 ----a-w C:\Windows\System32\MPSSVC.dll
                    2008-06-05 01:16 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
                    2008-06-05 01:16 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll
                    2008-06-05 01:16 16,896 ----a-w C:\Windows\System32\wfapigp.dll
                    2008-06-05 01:15 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
                    2008-06-05 01:15 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
                    2008-06-05 01:15 2,048 ----a-w C:\Windows\System32\msxml3r.dll
                    2008-06-05 01:15 1,191,936 ----a-w C:\Windows\System32\msxml3.dll
                    2008-06-05 01:13 24,064 ----a-w C:\Windows\System32\netcfg.exe
                    2008-06-05 01:13 22,016 ----a-w C:\Windows\System32\netiougc.exe
                    2008-06-05 01:13 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
                    2008-06-05 01:12 1,585,664 ----a-w C:\Windows\System32\setupapi.dll
                    2008-06-05 01:10 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
                    2008-06-05 01:10 223,232 ----a-w C:\Windows\System32\WMASF.DLL
                    2008-06-05 01:10 2,048 ----a-w C:\Windows\System32\asferror.dll
                    2008-06-05 01:10 2,027,008 ----a-w C:\Windows\System32\win32k.sys
                    2008-06-05 01:09 57,856 ----a-w C:\Windows\System32\SLUINotify.dll
                    2008-06-05 01:09 566,784 ----a-w C:\Windows\System32\SLCommDlg.dll
                    2008-06-05 01:09 39,936 ----a-w C:\Windows\System32\slcinst.dll
                    2008-06-05 01:09 351,232 ----a-w C:\Windows\System32\SLUI.exe
                    2008-06-05 01:09 33,280 ----a-w C:\Windows\System32\slwmi.dll
                    2008-06-05 01:09 296,448 ----a-w C:\Windows\System32\gdi32.dll
                    2008-06-05 01:09 268,288 ----a-w C:\Windows\System32\mcbuilder.exe
                    2008-06-05 01:09 223,232 ----a-w C:\Windows\System32\SLC.dll
                    2008-06-05 01:09 2,605,568 ----a-w C:\Windows\System32\SLsvc.exe
                    2008-06-05 01:09 186,368 ----a-w C:\Windows\System32\SLLUA.exe
                    2008-06-05 01:08 2,048 ----a-w C:\Windows\System32\msxml6r.dll
                    2008-06-05 01:08 1,335,296 ----a-w C:\Windows\System32\msxml6.dll
                    2008-06-05 01:06 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
                    2008-06-05 01:06 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
                    2008-06-05 01:06 11,776 ----a-w C:\Windows\System32\sbunattend.exe
                    2008-06-05 01:05 83,968 ----a-w C:\Windows\System32\dnsrslvr.dll
                    2008-06-05 01:05 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
                    2008-06-05 01:05 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
                    2008-06-05 01:05 24,576 ----a-w C:\Windows\System32\dnscacheugc.exe
                    2008-06-05 01:05 1,686,528 ----a-w C:\Windows\System32\gameux.dll
                    2008-06-05 01:03 5,120 ----a-w C:\Windows\System32\wmi.dll
                    2008-06-05 01:03 152,576 ----a-w C:\Windows\System32\imagehlp.dll
                    2008-06-05 01:01 750,080 ----a-w C:\Windows\System32\qmgr.dll
                    2008-06-05 01:01 633,856 ----a-w C:\Windows\System32\user32.dll
                    .

                    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    .
                    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                    REGEDIT4

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "holdbolt"="C:\ProgramData\SixthMapiMapi.or7fi3" [X]
                    "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-06-05 03:06 1232896]
                    "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
                    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-06-08 18:26 171448]
                    "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 14:36 201728]
                    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]
                    "WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 14:34 2159104 C:\Windows\System32\oobefldr.dll]

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-06-06 11:52 142104]
                    "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-06-06 11:52 154392]
                    "Persistence"="C:\Windows\system32\igfxpers.exe" [2007-06-06 11:52 138008]
                    "SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-08-17 14:40 102400]
                    "IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 13:00 174872]
                    "HotkeyApp"="C:\Program Files\Launch Manager\HotkeyApp.exe" [2007-07-26 14:56 192512]
                    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
                    "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]
                    "RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 11:06 4669440 C:\Windows\RtHDVCpl.exe]
                    "Skytel"="Skytel.exe" [2007-06-15 16:45 1826816 C:\Windows\SkyTel.exe]

                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
                    "{9F45C85C-D729-497B-A439-D1C2E45A00BD}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
                    "{26D860BC-9E89-44FC-9817-80C13C6228FD}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
                    "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

                    R1 Hotkey;Hotkey;C:\Windows\system32\drivers\Hotkey.sys [2003-04-28 11:27]
                    R3 WisLMSvc;WisLMSvc;C:\Program Files\Launch Manager\WisLMSvc.exe [2006-11-17 20:45]

                    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a2a88e32-30c5-11dd-a3da-806e6f6e6963}]
                    \shell\AutoRun\command - D:\Setup.exe

                    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cec34876-3576-11dd-b55c-0016d38c4a9a}]
                    \shell\AutoRun\command - E:\VFPcAssistant.exe

                    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cec3487c-3576-11dd-b55c-0016d38c4a9a}]
                    \shell\AutoRun\command - F:\VFPcAssistant.exe

                    *Newly Created Service* - AVGIO
                    *Newly Created Service* - AVGNTFLT
                    *Newly Created Service* - AVIPBB
                    *Newly Created Service* - CATCHME
                    *Newly Created Service* - PROCEXP90
                    .

                    **************************************************************************

                    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2008-08-25 22:03:07
                    Windows 6.0.6000 NTFS

                    Balayage processus cachés ...

                    Balayage caché autostart entries ...

                    Balayage des fichiers cachés ...

                    Scan terminé avec succès
                    Les fichiers cachés: 0

                    **************************************************************************
                    .
                    Temps d'accomplissement: 2008-08-25 22:04:47
                    ComboFix-quarantined-files.txt 2008-08-25 20:04:21

                    Pre-Run: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
                    Post-Run: 96,991,141,888 octets libres

                    175 --- E O F --- 2008-08-24 01:03:12
                    1. Contributeur sécurité
                      télécharge combofix (par sUBs) à cette adresse :

                      (c est le numéro 5 en bas de la page) : https://www.androidworld.fr/

                      et enregistre le sur le Bureau.

                      désactive tes protections et ferme toutes tes applications(antivirus, parefeu, garde en temps réel de l'antispyware)

                      Voici un tuto pour bien l'installer et savoir l utiliser : https://www.androidworld.fr/

                      ensuite envois le rapport et ensuite refais un nouveau rapport hijackthis stp
                      1. Voici mon rapport hijackthis

                        Malwarebytes' Anti-Malware 1.25
                        Version de la base de données: 1087
                        Windows 6.0.6000

                        12:44:32 25/08/2008
                        mbam-log-08-25-2008 (12-44-32).txt

                        Type de recherche: Examen complet (C:\|)
                        Eléments examinés: 86601
                        Temps écoulé: 56 minute(s), 9 second(s)

                        Processus mémoire infecté(s): 0
                        Module(s) mémoire infecté(s): 0
                        Clé(s) du Registre infectée(s): 0
                        Valeur(s) du Registre infectée(s): 1
                        Elément(s) de données du Registre infecté(s): 0
                        Dossier(s) infecté(s): 0
                        Fichier(s) infecté(s): 1

                        Processus mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Module(s) mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Clé(s) du Registre infectée(s):
                        (Aucun élément nuisible détecté)

                        Valeur(s) du Registre infectée(s):
                        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\1 mags 16 more (Trojan.Agent) -> Quarantined and deleted successfully.

                        Elément(s) de données du Registre infecté(s):
                        (Aucun élément nuisible détecté)

                        Dossier(s) infecté(s):
                        (Aucun élément nuisible détecté)

                        Fichier(s) infecté(s):
                        C:\ProgramData\Roam noun bias.vwh82h (Trojan.Agent) -> Quarantined and deleted successfully.
                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 21:52:12, on 25/08/2008
                        Platform: Windows Vista (WinNT 6.00.1904)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16711)
                        Boot mode: Normal

                        Running processes:
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Program Files\Windows Defender\MSASCui.exe
                        C:\Windows\System32\igfxtray.exe
                        C:\Windows\System32\hkcmd.exe
                        C:\Windows\System32\igfxpers.exe
                        C:\Windows\RtHDVCpl.exe
                        C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                        C:\Program Files\Launch Manager\HotkeyApp.exe
                        C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                        C:\Windows\system32\igfxsrvc.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                        C:\Program Files\Windows Media Player\wmpnscfg.exe
                        C:\Program Files\Internet Explorer\ieuser.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\Users\Fujitsu\Desktop\HiJackThis.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        O1 - Hosts: ::1 localhost
                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                        O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                        O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                        O4 - HKLM\..\Run: [Skytel] Skytel.exe
                        O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                        O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                        O4 - HKLM\..\Run: [HotkeyApp] "C:\Program Files\Launch Manager\HotkeyApp.exe"
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                        O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                        O4 - HKCU\..\Run: [holdbolt] "C:\ProgramData\SixthMapiMapi.or7fi3"
                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                        O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                        O13 - Gopher Prefix:
                        O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                        O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                        O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                        O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                        O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Launch Manager\WisLMSvc.exe
                        1. Dsl de ne te répondre que mtn j'ai eu une journée trés occupé !! Je vais maintenant faire le rapport et te dire le résultat okay??
                          1. Contributeur sécurité
                            ok maintenant refais un nouveau rapport hijackthis stp
                            1. voila rapport :

                              Malwarebytes' Anti-Malware 1.25
                              Version de la base de données: 1087
                              Windows 6.0.6000

                              12:44:32 25/08/2008
                              mbam-log-08-25-2008 (12-44-32).txt

                              Type de recherche: Examen complet (C:\|)
                              Eléments examinés: 86601
                              Temps écoulé: 56 minute(s), 9 second(s)

                              Processus mémoire infecté(s): 0
                              Module(s) mémoire infecté(s): 0
                              Clé(s) du Registre infectée(s): 0
                              Valeur(s) du Registre infectée(s): 1
                              Elément(s) de données du Registre infecté(s): 0
                              Dossier(s) infecté(s): 0
                              Fichier(s) infecté(s): 1

                              Processus mémoire infecté(s):
                              (Aucun élément nuisible détecté)

                              Module(s) mémoire infecté(s):
                              (Aucun élément nuisible détecté)

                              Clé(s) du Registre infectée(s):
                              (Aucun élément nuisible détecté)

                              Valeur(s) du Registre infectée(s):
                              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\1 mags 16 more (Trojan.Agent) -> Quarantined and deleted successfully.

                              Elément(s) de données du Registre infecté(s):
                              (Aucun élément nuisible détecté)

                              Dossier(s) infecté(s):
                              (Aucun élément nuisible détecté)

                              Fichier(s) infecté(s):
                              C:\ProgramData\Roam noun bias.vwh82h (Trojan.Agent) -> Quarantined and deleted successfully.
                              1. L'analyse est en cours ! J'en suis a 33minutes toujours rien .. J'attend ..
                                1. Contributeur sécurité
                                  on va désinfecter le pc, on réinstallera antivir apres...

                                  fais ce que je t ai demandé au message 7 stp
                                  • 1
                                  • 2