Virus ???????

Résolu
bonjour a tous depuis peu lomptemps dans la barre des tache il y a un triangle avec un poin d'exclamation jaune qui me bloque mes fenetre et ne me donne plus accés a internet pouvez vous me dire si c'est vrément un virus et si vous pouvez l enlevez svppppppppppppp
Configuration: Windows XP
Firefox 2.0.0.6

39 réponses

Résumé de la discussion

Un triangle avec un point d'exclamation jaune apparaît dans la barre des tâches, bloquant les fenêtres et l'accès à Internet sur Windows XP avec Firefox 2.0.0.6, et la question porte sur la possibilité d'un virus. Plusieurs conseils proposent de lancer un scan antivirus, notamment BitDefender, en mode sans échec, et d'utiliser Spybot pour un premier nettoyage, afin d'identifier les éléments bloquant l'accès et l'affichage. D'autres suggèrent d'analyser les entrées de HijackThis pour repérer des processus indésirables et de vérifier un éventuel conflit avec Avast, ce qui peut expliquer les alertes persistantes. Par exemple, une entrée évoquée est O4-HKCU\..\Run:[LDM]C:\ProgramFiles\Logitech\DesktopMessenger\8876480\Program\BackWeb-8876480.exe, à examiner via HijackThis et pouvant nécessiter une suppression manuelle si non nécessaire, car elle peut refléter un composant persistant.

Bobot (l’IA à votre service)
  1. Tout d'abord Bonjour et bienvenue sur le forum d'entraide COMMENT CA MARCHE

    Télécharge HijackThis ici:
    http://www.merijn.org/files/hijackthis.zip
    ou ici :
    https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/29061.html

    Dézippe le dans un dossier prévu à cet effet.
    Par exemple C:\hijackthis < Enregistre le bien dans c : !
    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://perso.orange.fr/rginformatique/section%20virus/Hijenr.gif

    Lance le puis:
    clique sur "do a system scan and save logfile" (cf démo)
    faire un copier coller du log entier sur le forum

    Démo : (Merci a Balltrap34 pour cette réalisation)

    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

    Bon courage
    A+
    1. Salut ! Surtout ,ne panique pas ! Je ne sais pas si c'est un virus mais il me semble suspect !
      Démmarre en mode sans échec(tapote F8) Et fait un scan avec Spybot !
      En espérant pouvoir t'aider ! Bonne chance ! :)
      1. merci bocoup pour le sexplication voici le rapport

        Logfile of HijackThis v1.99.1
        Scan saved at 21:43:59, on 08/08/2007
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
        C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
        C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
        C:\WINDOWS\system32\CTsvcCDA.exe
        C:\WINDOWS\eHome\ehRecvr.exe
        C:\WINDOWS\eHome\ehSched.exe
        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
        C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
        C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\wanmpsvc.exe
        C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\pspvideo9\pspVideo9.exe
        C:\Program Files\Norton Save and Restore\Agent\NSRTray.exe
        C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
        C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
        C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\Program Files\Google\Google Updater\GoogleUpdater.exe
        C:\WINDOWS\system32\dllhost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
        C:\Program Files\Windows Live\Messenger\usnsvc.exe
        C:\Program Files\LimeWire\LimeWire.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\Hijackthis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\1.0\NppBho.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
        O3 - Toolbar: Afficher Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [PSPVideo9] C:\Program Files\pspvideo9\pspVideo9.exe -t
        O4 - HKLM\..\Run: [Norton Save and Restore] "C:\Program Files\Norton Save and Restore\Agent\NSRTray.exe"
        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
        O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] "C:\Program Files\Neuf\Kit\WiFi\9wifi.exe"
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        O4 - Global Startup: AOL 9.0 Icône AOL.lnk = C:\Program Files\AOL 9.0a\aoltray.exe
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
        O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
        O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
        O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
        O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
        O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
        O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
        O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
        O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
        O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
        O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
        O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
        O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
        O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
        O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
        O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
        O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
        O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
        O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
        O23 - Service: Intel(R) Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
        O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
        O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
        O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
        O23 - Service: Norton Save and Restore - Symantec Corporation - C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
        O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
        O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
        O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
        O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
        1. REEEEEE !
          Si tu n'as pas spybot telecharge-le :
          https://fileforum.com/download/Spybot_Search_and_Destroy/1043809773/1

          Il est gratuit ! Install-le et fait les MAJ puis vaccine , Puis Un Scan(annalyse) !
          En espérant pouvoir t'aider ! Bonne chance !
          1. donc au demaragge je tapotte F8 et je fais un scan avec spybot et je n'aurais plus rien ??
          2. @tupac-shakurA mon avis OUI jusqua maintenant Spybot ma détruit tous les problemmes que javais !!!!
        2. Ouvre ce lien (merci a S!RI pour ce programme). http://siri.urz.free.fr/Fix/SmitfraudFix.php
          et télécharge SmitfraudFix.exe.

          Regarde le tuto
          Exécute le en choisissant l’option 1, il va générer un rapport
          Copie/colle le sur le poste stp.
          1. vu l'infection je ne pense pas que spybot sera d'une grande utilité, mais ca ne peux pas faire de mal...

            Fait smitfraud fix
            1. ensuite,

              fait un scan ici
              https://www.bitdefender.fr/

              * En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
              * Dans la nouvelle fenêtre, clique sur j‘accepte
              * Accepte le contrôle Active X et Installe le. Le scanner se charge
              * La fenêtre change encore, clique sur ’cliquez ici pour scanner’
              * Les signatures se chargent, etc.

              tuto en image :
              http://pageperso.aol.fr/rginformatique/mapage/defender.htm

              copie colle le résultat ici
          2. SmitFraudFix v2.210

            Rapport fait à 22:08:56,73, 08/08/2007
            Executé à partir de C:\Documents and Settings\HP_Administrateur\Bureau\SmitfraudFix
            OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
            Le type du système de fichiers est NTFS
            Fix executé en mode normal

            »»»»»»»»»»»»»»»»»»»»»»»» Process

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
            C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
            C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
            C:\WINDOWS\system32\CTsvcCDA.exe
            C:\WINDOWS\eHome\ehRecvr.exe
            C:\WINDOWS\eHome\ehSched.exe
            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
            C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
            C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\wanmpsvc.exe
            C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
            C:\Program Files\pspvideo9\pspVideo9.exe
            C:\Program Files\Norton Save and Restore\Agent\NSRTray.exe
            C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
            C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
            C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\Program Files\Google\Google Updater\GoogleUpdater.exe
            C:\WINDOWS\system32\dllhost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            C:\Program Files\LimeWire\LimeWire.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\WINDOWS\system32\cmd.exe

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            »»»»»»»»»»»»»»»»»»»»»»»» C:\

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Administrateur

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Administrateur\Application Data

            »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

            »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\HP_ADM~1\Favoris

            »»»»»»»»»»»»»»»»»»»»»»»» Bureau

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

            »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

            »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
            "Source"="About:Home"
            "SubscribedURL"="About:Home"
            "FriendlyName"="Ma page d'accueil"

            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLs"=""
            "LoadAppInit_DLLs"=dword:00000001

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "System"=""

            »»»»»»»»»»»»»»»»»»»»»»»» Rustock

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            Description: Wireless LAN PCI 802.11 b/g adapter WN5301A - Miniport d'ordonnancement de paquets
            DNS Server Search Order: 16.92.3.242
            DNS Server Search Order: 16.92.3.243
            DNS Server Search Order: 16.81.3.243
            DNS Server Search Order: 16.118.3.243

            Description: Wireless LAN PCI 802.11 b/g adapter WN5301A - Miniport d'ordonnancement de paquets
            DNS Server Search Order: 192.168.1.1

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
            HKLM\SYSTEM\CCS\Services\Tcpip\..\{BAD6091A-1CFE-4737-AB8A-0B85681E5AAC}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{BAD6091A-1CFE-4737-AB8A-0B85681E5AAC}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS3\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
            HKLM\SYSTEM\CS3\Services\Tcpip\..\{BAD6091A-1CFE-4737-AB8A-0B85681E5AAC}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

            »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

            »»»»»»»»»»»»»»»»»»»»»»»» Fin
            1. J'ai trouver la cause dans ton rapporrrt !
              coche sa et efface dans hijackthis :
              O4-HKCU\..\Run:[LDM]C:\ProgramFiles\Logitech\DesktopMessenger\8876480\Program\BackWeb-8876480.exe
              1. Je ne pense pas , si tu verifie sur castelcop : http://www.castlecops.com/StartupList.html

                BackWeb-8876480.exe est legitime memesi il envois des info car installé par l'utilisateur et en aucun cas il n'as de rapport avec l'infection
              2. @rudyritalDésolé alors ! Mais je fait ce que je peux pour l'aider !
                Bonne chance alors !
                A+
            2. bonsoir,

              il y a des restes de norton>point d´interrogation???

              Desinstalleur Norton:
              http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924
              1. pour bit defender je fais un scan avec avast en ce moment je peux pas

                et pour hijackthis je mais do a systheme and save a logfile ou do a systheme only ??
                1. o a systheme only
                2. @bigdarkmortattends plutot de régler tes propres soucis avant d´intervenir pour aider les autres, regis t´as répondu...
              2. bon je fais quoi alors je peux pas désinstallé norton paske j'ai payé pour l avoir et je veux le garder
                1. Contine le scan avec avast ou/et essaye Spybot ! Sinon je ne suis pas expert donc Bonne chance !
              3. mais rudyrital a dit qu il avait rien avoir avec l'infection
                1. mais tu as avast = conflit, tu voie...
                  1. Tu as surement raison ! J'avais pas fait attention !! dsl ^^
                2. oué je c'est mais le probeleme c'est que les 2 me servent paske norton detecte pas tout mais je veux pas le supprimer paske j'ai payer pour l avoir alors je le garde
                  1. c´est pas bon, il faut que t´en garde qu´un...
                    1. moK´s@ à raison ! Si tu veux garde AVAST c'est un très bon Antivirus Gratuit !
                    2. @bigdarkmortbigdarkmort,

                      tu as vu O_O regis t´as répondu, suite a ton message (message lié virus), il serait peut etre préférable que tu régle tes problemes avant d´intervenir pour réoudre ceux ses autres, qu´est c´que t´en pensse?
                  2. mais c'est dur a chaque fois je fais des scan avec norton il me trouve rien tendi que avast lui m'en trouve
                    1. oué ben je desinstallerais avast quand il aura fini son scan
                      1. oui ok, desinstal avast alors...

                        pensse plutot a faire le scan on line avec bitdefender que t´a conseillé rudyrital et post le rapport ici...
                        • 1
                        • 2