Virus msn album zip.

Résolu
Bonjour,

je viens de me prendre le virus sur msn, celui ou ca envoie a tous mes contacts un album photo :-s
j'ai télécharger msnfix
je vous colle le rapport de recherche :

MSNFix 1.495

C:\Documents and Settings\m‚li\Bureau\MSNFix
Fix exécuté le 10/09/2007 - 14:07:21,59 By m‚li
mode normal

************************ Recherche les fichiers présents

... C:\WINDOWS\IMG0024.zip

************************ Recherche les dossiers présents

Aucun dossier trouvé

************************ Suppression des fichiers

.. OK ... C:\WINDOWS\IMG0024.zip

************************ Nettoyage du registre

************************ Fichiers suspects

/!\ ces fichiers nécessitent un avis expérimenté avant toute intervention

[C:\WINDOWS\cfdemo.scr] 7065EA78122F0FFA97CC564CFBD61E61
[C:\WINDOWS\WLXPGSS.SCR] 1331E709EE682AD4F2EAFF31933E38BC

Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 10092007_14074193.zip

------------------------------------------------------------------------
Auteur : !aur3n7 Contact: https://www.ionos.fr/
------------------------------------------------------------------------

--------------------------------------------- END ---------------------------------------------

Merci beaucoup de pouvoir m'aider
Configuration: Windows XP
Firefox 2.0.0.6

22 réponses

  1. Contributeur sécurité
    poste un rapport hijack this et fais aussi ceci
    affiche tes fichiers et dossiers cachés comme ceci
    Ouvrir un dossier, n'importe lequel. Aller dans :
    Outils/Options des dossiers/Affichage et
    - cocher "afficher les dossiers et fichiers cachés",
    - décocher "masquer les extensions des fichiers dont le type est connu".
    - décocher masquer les fichiers protégés du système d'exploitation (recommandé)"
    "appliquer" et "ok"
    va sur ce site
    https://www.virustotal.com/gui/
    et fais y analyser ces fcihiers
    C:\WINDOWS\cfdemo.scr
    C:\WINDOWS\WLXPGSS.SCR
    poste les rapports obtenus
    0
    1. Voici le rapport d'hijacthis :

      Logfile of HijackThis v1.99.1
      Scan saved at 14:37:48, on 10/09/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16512)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\WINDOWS\eHome\ehRecvr.exe
      C:\WINDOWS\eHome\ehSched.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\SearchIndexer.exe
      C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Logitech\Video\LogiTray.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\system\services.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\Windows Desktop Search\WindowsSearch.exe
      C:\WINDOWS\system32\LVComS.exe
      C:\Program Files\BHODemon 2\BHODemon.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\WinRAR\WinRAR.exe
      C:\DOCUME~1\MLI~1\LOCALS~1\Temp\Rar$EX00.234\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
      O4 - HKLM\..\Run: [EPSON Stylus DX5000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE /FU "C:\WINDOWS\TEMP\E_SB9.tmp" /EF "HKLM"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
      O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Windows Services Registry] C:\WINDOWS\system\services.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - Startup: BHODemon 2.0.lnk = C:\Program Files\BHODemon 2\BHODemon.exe
      O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O11 - Options group: [INTERNATIONAL] International*
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
      O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
      O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{C786566D-7400-4AFE-9B5A-D620D1B63882}: NameServer = 86.64.145.140,84.103.237.140
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
      O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
      O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

      et le suis en trin d'envoyer les fichier pour les analyser mais c'est un peu long
      0
      1. Contributeur sécurité
        il reste de l'infection
        tu feras aussi ceci après les résultats de virus total car cette manip se fait en mode sans échec et tu n'auras pas accès à internet
        Télécharge SDFix sur ton bureau
        http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

        clic double sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau.
        Redémarre ton ordinateur en mode sans échec
        1) Redémarre ton ordi
        2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
        3) Tu verras un écran avec options de démarrage apparaître
        4) Choisi la première option : Sans Échec, et valide avec "Entrée"
        5) Choisi ton compte régulier, et non Administrateur

        Ouvre le dossier SDFix qui vient d'être créé sur le Bureau et clic double sur RunThis.bat
        Appuie sur Y pour commencer le nettoyage.
        Il va supprimer les services et les entrées du Registre infectés puis te demandera d'appuyer sur une touche pour redémarrer.
        Appuie sur une touche pour redémarrer le PC.
        Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
        Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
        Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
        Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
        Enfin, poste le contenu du fichier Report.txt dans ta prochaine réponse sur le forum,
        avec un nouveau rapport Hijack this
        0
        1. alors voici le rapprot pour ce fichier :C:\WINDOWS\WLXPGSS.SCR

          Antivirus Version Dernière mise à jour Résultat
          AhnLab-V3 2007.9.8.0 2007.09.10 -
          AntiVir 7.6.0.5 2007.09.10 -
          Authentium 4.93.8 2007.09.09 -
          Avast 4.7.1043.0 2007.09.10 -
          AVG 7.5.0.485 2007.09.10 -
          BitDefender 7.2 2007.09.10 -
          CAT-QuickHeal 9.00 2007.09.10 -
          ClamAV 0.91.2 2007.09.10 -
          DrWeb 4.33 2007.09.10 -
          eSafe 7.0.15.0 2007.09.04 -
          eTrust-Vet 31.1.5124 2007.09.10 -
          Ewido 4.0 2007.09.10 -
          FileAdvisor 1 2007.09.10 -
          Fortinet 3.11.0.0 2007.09.10 -
          F-Prot 4.3.2.48 2007.09.09 -
          F-Secure 6.70.13030.0 2007.09.10 -
          Ikarus T3.1.1.12 2007.09.10 -
          Kaspersky 4.0.2.24 2007.09.10 -
          McAfee 5115 2007.09.07 -
          Microsoft 1.2803 2007.09.10 -
          NOD32v2 2519 2007.09.10 -
          Norman 5.80.02 2007.09.07 -
          Panda 9.0.0.4 2007.09.09 -
          Rising 19.40.02.00 2007.09.10 -
          Sophos 4.21.0 2007.09.10 -
          Sunbelt 2.2.907.0 2007.09.07 -
          Symantec 10 2007.09.10 -
          TheHacker 6.1.10.183 2007.09.10 -
          VBA32 3.12.2.4 2007.09.09 -
          VirusBuster 4.3.26:9 2007.09.09 -
          Webwasher-Gateway 6.0.1 2007.09.10 -
          Information additionnelle
          File size: 580096 bytes
          MD5: 1331e709ee682ad4f2eaff31933e38bc
          SHA1: 6ab614fdd1956d3fccb9f3d2c8af30af1d1e1bae

          (j'èspère que c'est bien ca)
          0
          1. pour ce fichier C:\WINDOWS\cfdemo.scr ca me met juste ca :

            Bigger than max permited size / Mayor del tamaño máximo permitido

            donc je sais pas si c'est bon.

            Je fais le reste
            0
            1. Voila le rapport de sdfix

              SDFix: Version 1.103

              Run by m‚li on 10/09/2007 at 15:12

              Microsoft Windows XP [version 5.1.2600]

              Running From: C:\DOCUME~1\MLI~1\Bureau\SDFix

              Safe Mode:
              Checking Services:

              Restoring Windows Registry Values
              Restoring Windows Default Hosts File

              Rebooting...

              Normal Mode:
              Checking Files:

              Trojan Files Found:

              C:\WINDOWS\system\services.exe - Deleted

              Removing Temp Files...

              ADS Check:

              C:\WINDOWS
              No streams found.

              C:\WINDOWS\system32
              No streams found.

              C:\WINDOWS\system32\svchost.exe
              No streams found.

              C:\WINDOWS\system32\ntoskrnl.exe
              No streams found.

              Final Check:

              Remaining Services:
              ------------------

              Authorized Application Key Export:

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
              "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
              "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
              "C:\\Program Files\\Toshiba\\ConfigFree\\CFXFER.exe"="C:\\Program Files\\Toshiba\\ConfigFree\\CFXFER.exe:*:Disabled:ConfigFree SUMMIT Engine"
              "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
              "C:\\Program Files\\Sunbelt Software\\Personal Firewall\\kpf4gui.exe"="C:\\Program Files\\Sunbelt Software\\Personal Firewall\\kpf4gui.exe:*:Disabled:Sunbelt Firewall GUI"
              "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
              "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
              "C:\\WINDOWS\\system\\services.exe"="C:\\WINDOWS\\system\\services.exe:*:Enabled:Messenger Sharing"

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
              "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
              "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
              "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

              Remaining Files:
              ---------------

              File Backups: - C:\DOCUME~1\MLI~1\Bureau\SDFix\backups\backups.zip

              Files with Hidden Attributes:

              C:\Documents and Settings\m‚li\Mes documents\Ma musique\musique\Rihanna - A Girl Like Me (2006) - R&B [www.torrentazos.com]\Thumbs.db
              C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP53\A0007943.exe
              C:\Program Files\Common Files\X10\Common\x10prod.sys
              C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
              C:\Documents and Settings\m‚li\Mes documents\~WRL0002.tmp
              C:\Documents and Settings\m‚li\Mes documents\~WRL0004.tmp

              Finished!

              et la le rapport d'hijacthis

              Logfile of HijackThis v1.99.1
              Scan saved at 15:26:14, on 10/09/2007
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16512)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              C:\WINDOWS\eHome\ehRecvr.exe
              C:\WINDOWS\eHome\ehSched.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\SearchIndexer.exe
              C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\Program Files\Logitech\Video\LogiTray.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\Program Files\Windows Desktop Search\WindowsSearch.exe
              C:\WINDOWS\system32\dllhost.exe
              C:\WINDOWS\system32\LVComS.exe
              C:\Program Files\BHODemon 2\BHODemon.exe
              C:\WINDOWS\system32\SearchProtocolHost.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\WINDOWS\system32\notepad.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Program Files\WinRAR\WinRAR.exe
              C:\DOCUME~1\MLI~1\LOCALS~1\Temp\Rar$EX00.563\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
              O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
              O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
              O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
              O4 - HKLM\..\Run: [EPSON Stylus DX5000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE /FU "C:\WINDOWS\TEMP\E_SB9.tmp" /EF "HKLM"
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
              O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [Windows Services Registry] C:\WINDOWS\system\services.exe
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              O4 - Startup: BHODemon 2.0.lnk = C:\Program Files\BHODemon 2\BHODemon.exe
              O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
              O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O11 - Options group: [INTERNATIONAL] International*
              O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
              O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
              O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
              O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{C786566D-7400-4AFE-9B5A-D620D1B63882}: NameServer = 86.64.145.140,84.103.237.140
              O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
              O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
              O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
              O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
              O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
              O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
              O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
              O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
              0
              1. Contributeur sécurité
                lance hijack this pour un scan et coche les lignes suivantes
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                O4 - HKLM\..\Run: [Windows Services Registry] C:\WINDOWS\system\services.exe
                ferme toutes tes fenêtres y compris internet et clique sur fixer l'objet

                Télécharge clean.zip, de Malekal
                http://www.malekal.com/download/clean.zip

                décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier clean.
                Ouvre le dossier clean qui se trouve sur ton bureau, et double-clic sur clean.cmd, une fenêtre noire va apparaître pendant un instant, laisse la ouverte.
                Choisis l'option 1 puis patiente
                Poste ensuite le contenu du rapport
                C:\rapport_clean.txt
                0
                1. voila :

                  10/09/2007 a 15:43:10,06

                  *** Recherche des fichiers dans C:

                  *** Recherche des fichiers dans C:\WINDOWS\

                  *** Recherche des fichiers dans C:\WINDOWS\system32

                  *** Recherche des fichiers dans C:\Program Files
                  "C:\Program Files\Everest Poker\" FOUND
                  *** Fin du rapport !
                  0
                  1. Contributeur sécurité
                    Redémarre en mode sans échec sans accès à Internet.
                    1) Redémarre ton ordi
                    2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                    3) Tu verras un écran avec options de démarrage apparaître
                    4) Choisi la première option : Sans Échec, et valide avec "Entrée"
                    5) Choisi ton compte régulier, et non Administrateur

                    Ouvre le dossier jaune nommé clean sur ton bureau.
                    Double-clique sur clean.cmd
                    Choisis l'option 2 et copie sur le bureau le rapport généré.
                    Si une fenêtre s'ouvre, laisse-la.
                    Clique sur Q pour quitter le programme.
                    Redémarre normalement
                    et dis moi comment va la PC
                    0
                    1. voila le rapport :

                      Script execute en mode sans echec
                      Rapport clean par Malekal_morte - http://www.malekal.com
                      Script execute en mode sans echec 10/09/2007 a 15:53:22,06

                      Microsoft Windows XP [version 5.1.2600]

                      *** Suppression des fichiers dans C:

                      *** Suppression des fichiers dans C:\WINDOWS\

                      *** Suppression des fichiers dans C:\WINDOWS\system32

                      *** Suppression des fichiers dans C:\Program Files
                      tentative de suppression de "C:\Program Files\Everest Poker\"

                      *** Suppression des clefs du registre effectuee..
                      *** Fin du rapport !

                      et je pense que j'ai plus de problème sur msn...
                      en tout cas je te remercie bcp de m'avoir aider !
                      bonne contination
                      0
                      1. Contributeur sécurité
                        fais encore ceci pour vérifier qu'il ne reste rien
                        faire un scan antivirus en ligne avec internet explorer et accepter l'activex
                        poster le rapport ici ensuite
                        https://www.bitdefender.fr/

                        En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
                        Dans la nouvelle fenêtre, clique sur I agree
                        La fenêtre change encore, clique sur Click here to scan
                        Les signatures se chargent, etc.

                        tuto en image
                        http://pageperso.aol.fr/rginformatique/mapage/defender.htm
                        0
                        1. voila le scan :

                          Statistics

                          Time

                          00:50:36

                          Files

                          190784

                          Folders

                          5018

                          Boot Sectors

                          3

                          Archives

                          7740

                          Packed Files

                          14409

                          Results

                          Identified Viruses

                          4

                          Infected Files

                          12

                          Suspect Files

                          0

                          Warnings

                          0

                          Disinfected

                          0

                          Deleted Files

                          12

                          Engines Info

                          Virus Definitions

                          800365

                          Engine build

                          AVCORE v1.0 (build 2411) (i386) (Jul 9 2007 12:10:22)

                          Scan plugins

                          14

                          Archive plugins

                          38

                          Unpack plugins

                          7

                          E-mail plugins

                          6

                          System plugins

                          1

                          Scan Settings

                          First Action

                          Disinfect

                          Second Action

                          Delete

                          Heuristics

                          Yes

                          Enable Warnings

                          Yes

                          Scanned Extensions

                          *;

                          Exclude Extensions

                          Scan Emails

                          Yes

                          Scan Archives

                          Yes

                          Scan Packed

                          Yes

                          Scan Files

                          Yes

                          Scan Boot

                          Yes

                          Scanned File

                          Status

                          C:\Documents and Settings\méli\Bureau\MSNFix\10092007_13082220.zip=>backup/IMG0024.zip=>http://3tgallery.com/icon/x.jpg c:\winsv.exe 1 -s

                          Infected with: Trojan.Multidrop.IB.Dam

                          C:\Documents and Settings\méli\Bureau\MSNFix\10092007_13082220.zip=>backup/IMG0024.zip=>http://3tgallery.com/icon/x.jpg c:\winsv.exe 1 -s

                          Disinfection failed

                          C:\Documents and Settings\méli\Bureau\MSNFix\10092007_13082220.zip=>backup/IMG0024.zip=>http://3tgallery.com/icon/x.jpg c:\winsv.exe 1 -s

                          Deleted

                          C:\Documents and Settings\méli\Bureau\MSNFix\10092007_13082220.zip=>backup/IMG0024.zip

                          Updated

                          C:\Documents and Settings\méli\Bureau\MSNFix\10092007_13082220.zip

                          Updated

                          C:\Documents and Settings\méli\Bureau\MSNFix\10092007_14074193.zip=>backup/IMG0024.zip=>http://3tgallery.com/icon/x.jpg c:\winsv.exe 1 -s

                          Infected with: Trojan.Multidrop.IB.Dam

                          C:\Documents and Settings\méli\Bureau\MSNFix\10092007_14074193.zip=>backup/IMG0024.zip=>http://3tgallery.com/icon/x.jpg c:\winsv.exe 1 -s

                          Disinfection failed

                          C:\Documents and Settings\méli\Bureau\MSNFix\10092007_14074193.zip=>backup/IMG0024.zip=>http://3tgallery.com/icon/x.jpg c:\winsv.exe 1 -s

                          Deleted

                          C:\Documents and Settings\méli\Bureau\MSNFix\10092007_14074193.zip=>backup/IMG0024.zip

                          Updated

                          C:\Documents and Settings\méli\Bureau\MSNFix\10092007_14074193.zip

                          Updated

                          C:\Documents and Settings\méli\Bureau\SDFix\backups\backups.zip=>backups/services.exe

                          Infected with: Trojan.Multidrop.IB.Dam

                          C:\Documents and Settings\méli\Bureau\SDFix\backups\backups.zip=>backups/services.exe

                          Disinfection failed

                          C:\Documents and Settings\méli\Bureau\SDFix\backups\backups.zip=>backups/services.exe

                          Deleted

                          C:\Documents and Settings\méli\Bureau\SDFix\backups\backups.zip

                          Updated

                          C:\Documents and Settings\méli\Bureau\sudoku.exe

                          Detected with: Adware.Navipromo.BYD

                          C:\Documents and Settings\méli\Bureau\sudoku.exe

                          Disinfection failed

                          C:\Documents and Settings\méli\Bureau\sudoku.exe

                          Deleted

                          C:\Documents and Settings\méli\Mes documents\Mes fichiers reçus\IMG0024.zip=>IMG096.JPG-www.photobucket.com

                          Infected with: Trojan.Multidrop.IB.Dam

                          C:\Documents and Settings\méli\Mes documents\Mes fichiers reçus\IMG0024.zip=>IMG096.JPG-www.photobucket.com

                          Disinfection failed

                          C:\Documents and Settings\méli\Mes documents\Mes fichiers reçus\IMG0024.zip=>IMG096.JPG-www.photobucket.com

                          Deleted

                          C:\Documents and Settings\méli\Mes documents\Mes fichiers reçus\IMG0024.zip

                          Updated

                          C:\Program Files\Navilog1\Backupnavi\tivcxesgmc.exe

                          Infected with: Trojan.Skintrim.ARR

                          C:\Program Files\Navilog1\Backupnavi\tivcxesgmc.exe

                          Disinfection failed

                          C:\Program Files\Navilog1\Backupnavi\tivcxesgmc.exe

                          Deleted

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP36\A0005487.exe

                          Infected with: Trojan.Skintrim.ARR

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP36\A0005487.exe

                          Disinfection failed

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP36\A0005487.exe

                          Deleted

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP59\A0009667.exe

                          Infected with: Trojan.Downloader.LoadAdv.A

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP59\A0009667.exe

                          Disinfection failed

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP59\A0009667.exe

                          Deleted

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP61\A0009714.exe

                          Infected with: Trojan.Multidrop.IB.Dam

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP61\A0009714.exe

                          Disinfection failed

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP61\A0009714.exe

                          Deleted

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP61\A0009723.exe

                          Infected with: Trojan.Multidrop.IB.Dam

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP61\A0009723.exe

                          Disinfection failed

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP61\A0009723.exe

                          Deleted

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP61\A0009819.exe

                          Detected with: Adware.Navipromo.BYD

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP61\A0009819.exe

                          Disinfection failed

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP61\A0009819.exe

                          Deleted

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP61\A0009839.exe

                          Infected with: Trojan.Skintrim.ARR

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP61\A0009839.exe

                          Disinfection failed

                          C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP61\A0009839.exe

                          Deleted
                          0
                          1. Contributeur sécurité
                            supprime MSNFix, SDfix,
                            supprime navilog par ajout suppression de programmes
                            supprime si encore présents les fichiers en gras
                            C:\Documents and Settings\méli\Bureau\sudoku.exe
                            C:\Documents and Settings\méli\Mes documents\Mes fichiers reçus\IMG0024.zip
                            C:\Documents and Settings\méli\Mes documents\Mes fichiers reçus\IMG0024.zip=>IMG096.JPG-www.photobucket.com
                            vide ta corbaille
                            passe ccleaner, nettoyeur et supprime tout ce qu'il trouve
                            passe ccleaner erreur et répare tout ce qu'il trouve, accepte les sauvegardes
                            https://www.pcastuces.com/logitheque/ccleaner.htm
                            ("Download Latest Version", sur la droite).
                            Ce logiciel va permettre de supprimer tous les fichiers temporaires. Avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires". Ensuite, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. C'est tout.

                            si tout va bien supprime tout ce qu'on a utilisé car ce ne sera plus utile désormais
                            conserve néanmoins ccleaner et effectue le nettoyage tous les jours avant de couper le PC

                            installe ce logiciel très utile et scanne ton PC avec une fois par semaine au moins...
                            AVG Antispyware
                            https://www.avg.com/en-ww/free-antivirus-download

                            mode d'utilisation :
                            Lance AVG Anti-Spyware, mets le à jour,
                            Clique sur le bouton « Analyse »
                            Puis « Comment réagir », clique sur Actions recommandées. Sélectionne Quarantaine.
                            Retour à l'onglet Analyse.
                            Clique sur Analyse complète du système.
                            A la fin du scan, choisis " Appliquer toutes les actions "
                            Clique sur "Enregistrer le rapport". Le fichier texte se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.

                            tu peux le coupler avec celui-ci
                            spybot search and destroy
                            https://www.safer-networking.org/?page=download

                            défragmente

                            pense à bien te protéger, j'ai découvert ce lien qui est plutôt pas mal à ce sujet

                            https://forum.pcastuces.com/default.asp

                            désactive ta restauration
                            clique droit sur poste de travail/propriétés/coche la case désactiver la restauration, appliquer
                            redémarre ton PC
                            clique droit sur poste de travail/propriétés/décoche la case désactiver la restauration, appliquer
                            démarrer/tous les programmes/ outils système/ restauration du système/ créer un point de restauration

                            la sécurité c'est très important mais ne remplace pas l'internaute, un surf prudent en évitant le crack, les sites "chauds", permet déjà d'éviter bien des soucis, le P2P lui aussi est source d'infections...

                            et bon surf
                            0
                            1. BJR BJR... VOILA J'AI LE MEME VIRUS ET J'AI DONC PRIS LES DEVANTS
                              ET DONC MON SCAN MSN FIX DONNE CECI

                              MSNFix 1.493

                              C:\Documents and Settings\M‚gane\Mes documents\fichier telecharger\MSNFix\MSNFix
                              Fix exécuté le 08/09/2007 - 15:07:35,00 By M‚gane
                              mode normal

                              ************************ Recherche les fichiers présents

                              ... C:\WINDOWS\IMG0024.zip

                              ************************ Recherche les dossiers présents

                              Aucun dossier trouvé

                              ************************ Suppression des fichiers

                              .. OK ... C:\WINDOWS\IMG0024.zip

                              ************************ Nettoyage du registre

                              ************************ Fichiers suspects

                              /!\ ces fichiers nécessitent un avis expérimenté avant toute intervention

                              [C:\archive.zip] 8E862B4071A5B6810B17FD260F3C1E23

                              Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 08092007_15080687.zip

                              ------------------------------------------------------------------------
                              Auteur : !aur3n7 Contact: https://www.ionos.fr/
                              ------------------------------------------------------------------------

                              --------------------------------------------- END ---------------------------------------------
                              0
                              1. Et donc mon rapport Hijackthis donne :

                                Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                                Scan saved at 18:29:56, on 10/09/2007
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                Boot mode: Normal

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                C:\WINDOWS\system32\LEXBCES.EXE
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\WINDOWS\system32\LEXPPS.EXE
                                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\drivers\KodakCCS.exe
                                C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
                                C:\WINDOWS\system32\nvsvc32.exe
                                C:\WINDOWS\system32\ScsiAccess.EXE
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\WINDOWS\system32\RunDll32.exe
                                C:\WINDOWS\AGRSMMSG.exe
                                C:\WINDOWS\Dit.exe
                                C:\WINDOWS\mHotkey.exe
                                C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
                                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                C:\Program Files\Logitech\Video\LogiTray.exe
                                C:\WINDOWS\system32\rundll32.exe
                                C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
                                C:\WINDOWS\system32\LVComS.exe
                                C:\Program Files\iTunes\iTunesHelper.exe
                                C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
                                C:\WINDOWS\system\services.exe
                                C:\Program Files\iPod\bin\iPodService.exe
                                C:\Program Files\Windows Live\Messenger\usnsvc.exe
                                C:\Program Files\iTunes\iTunes.exe
                                C:\WINDOWS\system32\wuauclt.exe
                                c:\dc2.exe
                                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                C:\Documents and Settings\Mégane\Mes documents\fichier telecharger\HiJackThis_v2.exe

                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
                                R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.carrefour.fr/
                                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                R3 - URLSearchHook: (no name) - {CE000994-A58C-4441-8938-744CD72AB27F} - (no file)
                                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
                                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
                                O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                                O4 - HKLM\..\Run: [Dit] Dit.exe
                                O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
                                O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
                                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                                O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                                O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                                O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
                                O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
                                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] "C:\Program Files\Neuf\Kit\WiFi\9wifi.exe"
                                O4 - HKLM\..\Run: [Lexmark 2200 Series] "C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe"
                                O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
                                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                O4 - HKLM\..\Run: [Windows Services Registry] C:\WINDOWS\system\services.exe
                                O4 - HKLM\..\Run: [AntiVirusMonitorExe] c:\dc2.exe
                                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
                                O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                                O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
                                O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                                O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                                O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
                                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O14 - IERESET.INF: START_PAGE_URL=http://www.carrefour.fr/
                                O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
                                O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
                                O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                                O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1097743015284
                                O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                                O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - https://www.ea.com/ea-studios/popcap
                                O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                                O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                O23 - Service: Client de licence CA (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
                                O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
                                O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
                                O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
                                O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
                                O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
                                O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                                O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
                                O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
                                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
                                O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
                                O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
                                O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
                                O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                                O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
                                O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
                                O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
                                O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
                                O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                                0
                                1. Contributeur sécurité
                                  Télécharge clean.zip, de Malekal
                                  http://www.malekal.com/download/clean.zip

                                  décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier clean.
                                  Ouvre le dossier clean qui se trouve sur ton bureau, et double-clic sur clean.cmd, une fenêtre noire va apparaître pendant un instant, laisse la ouverte.
                                  Choisis l'option 1 puis patiente
                                  Poste ensuite le contenu du rapport
                                  C:\rapport_clean.txt
                                  0
                                  1. MERCII
                                    LE RAPPORT CLEAN DONNE CECI

                                    10/09/2007 a 18:54:22,26

                                    *** Recherche des fichiers dans C:

                                    *** Recherche des fichiers dans C:\WINDOWS\

                                    *** Recherche des fichiers dans C:\WINDOWS\system32
                                    C:\WINDOWS\system\services.exe FOUND

                                    *** Recherche des fichiers dans C:\Program Files
                                    *** Fin du rapport !
                                    0
                                    1. Contributeur sécurité
                                      Redémarre en mode sans échec sans accès à Internet.
                                      1) Redémarre ton ordi
                                      2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                                      3) Tu verras un écran avec options de démarrage apparaître
                                      4) Choisi la première option : Sans Échec, et valide avec "Entrée"
                                      5) Choisi ton compte régulier, et non Administrateur

                                      Ouvre le dossier jaune nommé clean sur ton bureau.
                                      Double-clique sur clean.cmd
                                      Choisis l'option 2 et copie sur le bureau le rapport généré.
                                      Si une fenêtre s'ouvre, laisse-la.
                                      Clique sur Q pour quitter le programme.
                                      Redémarre normalement et poste le rapport obtenu et un rapport hijack this
                                      et dis moi comment va la PC
                                      0
                                      1. Alors j'ai fais ce qu'il fallai je l'espere....

                                        le rapport CLEAN donne

                                        Script execute en mode sans echec
                                        Rapport clean par Malekal_morte - http://www.malekal.com
                                        Script execute en mode sans echec 10/09/2007 a 19:04:01,18

                                        Microsoft Windows XP [version 5.1.2600]

                                        *** Suppression des fichiers dans C:

                                        *** Suppression des fichiers dans C:\WINDOWS\

                                        *** Suppression des fichiers dans C:\WINDOWS\system32
                                        tentative de suppression de C:\WINDOWS\system\services.exe

                                        *** Suppression des fichiers dans C:\Program Files

                                        *** Suppression des clefs du registre effectuee..
                                        *** Fin du rapport !


                                        ET HIJACKTHIS


                                        Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                                        Scan saved at 19:09:54, on 10/09/2007
                                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\WINDOWS\System32\smss.exe
                                        C:\WINDOWS\system32\winlogon.exe
                                        C:\WINDOWS\system32\services.exe
                                        C:\WINDOWS\system32\lsass.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                        C:\WINDOWS\system32\LEXBCES.EXE
                                        C:\WINDOWS\system32\spoolsv.exe
                                        C:\WINDOWS\system32\LEXPPS.EXE
                                        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\WINDOWS\system32\drivers\KodakCCS.exe
                                        C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
                                        C:\WINDOWS\system32\nvsvc32.exe
                                        C:\WINDOWS\system32\ScsiAccess.EXE
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                        C:\WINDOWS\Explorer.EXE
                                        C:\WINDOWS\system32\wuauclt.exe
                                        C:\WINDOWS\system32\RunDll32.exe
                                        C:\WINDOWS\AGRSMMSG.exe
                                        C:\WINDOWS\Dit.exe
                                        C:\WINDOWS\mHotkey.exe
                                        C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
                                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                        C:\Program Files\Logitech\Video\LogiTray.exe
                                        C:\WINDOWS\system32\rundll32.exe
                                        C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
                                        C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
                                        C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                                        C:\Program Files\iTunes\iTunesHelper.exe
                                        C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                                        C:\WINDOWS\system32\wuauclt.exe
                                        C:\dc2.exe
                                        C:\WINDOWS\system32\ctfmon.exe
                                        C:\WINDOWS\system32\LVComS.exe
                                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                        C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                        C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
                                        C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                                        C:\Program Files\iPod\bin\iPodService.exe
                                        C:\Documents and Settings\Mégane\Mes documents\fichier telecharger\HiJackThis_v2.exe

                                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
                                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
                                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.carrefour.fr/
                                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                        R3 - URLSearchHook: (no name) - {CE000994-A58C-4441-8938-744CD72AB27F} - (no file)
                                        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                        O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
                                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                        O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
                                        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                                        O4 - HKLM\..\Run: [Dit] Dit.exe
                                        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                        O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
                                        O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
                                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                        O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                                        O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                                        O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                                        O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                        O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
                                        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
                                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                        O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] "C:\Program Files\Neuf\Kit\WiFi\9wifi.exe"
                                        O4 - HKLM\..\Run: [Lexmark 2200 Series] "C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe"
                                        O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
                                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                        O4 - HKLM\..\Run: [Windows Services Registry] C:\WINDOWS\system\services.exe
                                        O4 - HKLM\..\Run: [AntiVirusMonitorExe] C:\dc2.exe
                                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                        O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
                                        O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                                        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                                        O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
                                        O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                                        O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                                        O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
                                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
                                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O14 - IERESET.INF: START_PAGE_URL=http://www.carrefour.fr/
                                        O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
                                        O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
                                        O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                                        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1097743015284
                                        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                                        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                        O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - https://www.ea.com/ea-studios/popcap
                                        O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                                        O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                                        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                        O23 - Service: Client de licence CA (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
                                        O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
                                        O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
                                        O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
                                        O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
                                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                        O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
                                        O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                        O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
                                        O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                                        O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
                                        O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
                                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                        O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
                                        O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
                                        O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
                                        O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
                                        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                                        O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
                                        O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
                                        O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
                                        O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                        O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
                                        O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                                        0
                                        1. Contributeur sécurité
                                          lance hijack this pour un scan et coche les lignes suivantes
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                          R3 - URLSearchHook: (no name) - {CE000994-A58C-4441-8938-744CD72AB27F} - (no file
                                          O4 - HKLM\..\Run: [Windows Services Registry] C:\WINDOWS\system\services.exe
                                          ferme toutes tes fenêtres y compris internet et clique sur fixer l'objet

                                          affiche tes fichiers et dossiers cachés comme ceci
                                          Ouvrir un dossier, n'importe lequel. Aller dans :
                                          Outils/Options des dossiers/Affichage et
                                          - cocher "afficher les dossiers et fichiers cachés",
                                          - décocher "masquer les extensions des fichiers dont le type est connu".
                                          - décocher masquer les fichiers protégés du système d'exploitation (recommandé)"
                                          "appliquer" et "ok"
                                          va sur ce site
                                          https://www.virustotal.com/gui/
                                          et fais y analyser ces fichiers
                                          C:\dc2.exe
                                          C:\archive.zip
                                          poste les rapports obtenus
                                          0
                                          • 1
                                          • 2