Virus antivirus2009

Bonjour,

Mon ordi est infesté de virus depuis que ma chère et tendre est parti navigué je ne sais ou sur le web, donc j'ai droit a tout pop up, trojan et autre spyware (j'y conais que dalle moi a tout ça), mais depuis peut venai me harceler Antivirus2009 et suite a une mauvaise manip' il s'est installé sur mon ordi et me fait la misère en me bloquant l'accès aux sites Internet par exemple.

J'ai déja lu les differents post sur le sujet et apparement on doit en faire un perso, en meme temps je comprend pas grand chose adans le domaine info.

Donc si quelqu'un peut m'aider ça serait bien sympa.

Merci d'Avance....
Configuration: Windows XP
Internet Explorer 7.0

14 réponses

Résumé de la discussion

L'internaute signale une infection par Antivirus 2009 et d'autres malwares sur Windows XP et Internet Explorer 7, handicapant l'accès au Web par des blocages et des pop-ups persistants. La meilleure réponse préconise d'utiliser SmitFraudFix en mode sans échec et HijackThis pour générer des rapports à poster afin d'identifier et supprimer les éléments malveillants. En complément, plusieurs messages évoquent l'exécution des outils pas à pas et les rapports détaillés comme éléments clés pour guider le nettoyage, sans donner immédiatement une solution universelle. L'utilisateur indique ensuite que AVG signale encore des trojans occasionnels et demande des conseils sur un antivirus et un pare-feu efficaces pour prévenir une reprise de l'infection.

Bobot (l’IA à votre service)
  1. bonjour
    a part de changer de "chère et tendre " lol
    commence par poster ces rapports

    Télécharge SmitfraudFix : http://siri.urz.free.fr/Fix/SmitfraudFix.exe
    http://siri.urz.free.fr/Fix/SmitfraudFix.php
    - Enregistre-le sur le bureau

    - Double-clique sur SmitfraudFix.exe et choisis l'option 1 puis Entrée

    - Un rapport sera généré, poste-le dans ta prochaine réponse stp.

    Tutoriel ici pour t'aider : http://www.malekal.com//tutorial_SmitFraudfix.php

    télécharge hijackthis http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
    -> enregistre la cible sous .... "le bureau" renomme hijackthis.exe en par exemple HJT.exe

    -> Fais un double-clic sur "HJT.exe" afin de lancer l'installation

    -> Clique sur Install ensuite sur "I Accept"

    -> Clique sur" Do a scan system and save log file"

    -> Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse

    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/Hijenr.gif
    http://pageperso.aol.fr/balltrap34/demohijack.htm
    http://www.tutoriaux-excalibur.com/hijackthis.htm
    https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html
    0
    1. Je voulais changer de chere et tendre mais c pour le meilleur et le pire....

      Alors voici le rapport de SmitfraudFix

      SmitFraudFix v2.388

      Rapport fait à 15:06:55,85, 07/01/2009
      Executé à partir de C:\Documents and Settings\fattah koudia\Bureau\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode normal

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\system32\CTsvcCDA.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      C:\WINDOWS\system32\lxddcoms.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\Program Files\Microsoft LifeCam\MSCamS32.exe
      C:\WINDOWS\Explorer.exe
      C:\WINDOWS\system32\svchost.exe
      C:\PROGRA~1\AVG\AVG8\avgemc.exe
      C:\WINDOWS\system32\RunDll32.exe
      C:\Program Files\Lexmark 2500 Series\lxddmon.exe
      C:\Program Files\Lexmark 2500 Series\lxddamon.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
      C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\Program Files\Paltalk Messenger\paltalk.exe
      C:\Documents and Settings\fattah koudia\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
      C:\Documents and Settings\fattah koudia\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Documents and Settings\fattah koudia\Bureau\SmitfraudFix\Policies.exe
      C:\WINDOWS\system32\cmd.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

      C:\WINDOWS\system32\a.exe PRESENT !
      C:\WINDOWS\system32\ieupdates.exe PRESENT !
      C:\WINDOWS\system32\winsrc.dll PRESENT !

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\fattah koudia

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\FATTAH~1\LOCALS~1\Temp

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\fattah koudia\Application Data

      C:\Documents and Settings\fattah koudia\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk PRESENT !

      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

      C:\DOCUME~1\FATTAH~1\MENUDM~1\Antivirus 2009 PRESENT !

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\FATTAH~1\Favoris

      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="Ma page d'accueil"

      »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      o4Patch
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      Agent.OMZ.Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
      "{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"="STS"

      [HKEY_CLASSES_ROOT\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
      @="c:\windows\system32\zevihami.dll"

      [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
      @="c:\windows\system32\zevihami.dll"

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"="C:\\WINDOWS\\system32\\fatalofi.dll C:\\WINDOWS\\system32\\fotuwutu.dll avgrsstx.dll C:\\WINDOWS\\system32\\kafawagi.dll c:\\windows\\system32\\zevihami.dll"
      "LoadAppInit_DLLs"=dword:00000001

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» RK

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: Carte réseau Fast Ethernet PCI Realtek RTL8139 Family - Miniport d'ordonnancement de paquets
      DNS Server Search Order: 212.27.40.240
      DNS Server Search Order: 212.27.40.241

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{DA939196-1071-49EC-B597-3C578E19B63A}: DhcpNameServer=212.27.40.240 212.27.40.241
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{DA939196-1071-49EC-B597-3C578E19B63A}: DhcpNameServer=212.27.40.240 212.27.40.241
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{DA939196-1071-49EC-B597-3C578E19B63A}: DhcpNameServer=212.27.40.240 212.27.40.241

      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

      »»»»»»»»»»»»»»»»»»»»»»»» Fin

      et voici celui de HJT

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 15:21:29, on 07/01/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16735)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\system32\CTsvcCDA.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      C:\WINDOWS\system32\lxddcoms.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\Program Files\Microsoft LifeCam\MSCamS32.exe
      C:\WINDOWS\Explorer.exe
      C:\WINDOWS\system32\svchost.exe
      C:\PROGRA~1\AVG\AVG8\avgemc.exe
      C:\WINDOWS\system32\RunDll32.exe
      C:\Program Files\Lexmark 2500 Series\lxddmon.exe
      C:\Program Files\Lexmark 2500 Series\lxddamon.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
      C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\Program Files\Paltalk Messenger\paltalk.exe
      C:\Documents and Settings\fattah koudia\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
      C:\Documents and Settings\fattah koudia\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Documents and Settings\fattah koudia\Bureau\SmitfraudFix\Policies.exe
      C:\WINDOWS\system32\cmd.exe
      C:\WINDOWS\notepad.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fimg%2ffr%2ffr-fr%2fdivertissement%2fcelebrites%2fgalery%2fwentworth02.jpg%3f
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\eksplorasi.exe"
      O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
      O1 - Hosts: "http://www.w3.org/TR/html4/loose.dtd">
      O1 - Hosts: <html>
      O1 - Hosts: <head>
      O1 - Hosts: <script LANGUAGE="JavaScript">
      O1 - Hosts: <!--
      O1 - Hosts: if (window != top)
      O1 - Hosts: top.location.href = location.href;
      O1 - Hosts: // -->
      O1 - Hosts: </script>
      O1 - Hosts: <title>Site Unavailable</title>
      O1 - Hosts: <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
      O1 - Hosts: <style type="text/css">
      O1 - Hosts: body{text-align:center;}
      O1 - Hosts: .geohead {font-family:Verdana, Arial, Helvetica, sans-serif; font-size:10px;width:750px;margin:10px 0 10px 0;height:35px;}
      O1 - Hosts: .geohead #geologo {width:270px;display:block; float:left; }
      O1 - Hosts: .geohead #rightside {width:480px;display:block; float:right;border-bottom:1px solid #999999; height:27px;}
      O1 - Hosts: .geohead #rightside #welcome {width:50%;display:block; float:left; text-align:left;}
      O1 - Hosts: .geohead #rightside #wlinks {width:50%;display:block; float:right; text-align:right;}
      O1 - Hosts: .ftr { margin:0px; color:#404040; font:x-small Arial,sans-serif; text-align:center; width:750px;}
      O1 - Hosts: .bodywrap{display:block;height:470px;}
      O1 - Hosts: .bodycnt{width:510px; display:block; float:left; background-color:#EEE9F5; height:auto; text-align:left; font-family:Arial, Helvetica, sans-serif;font-size:13px; color:#000000; padding:20px 20px 35px 20px;}
      O1 - Hosts: .title { font-family:Arial, Helvetica, sans-serif; font-weight:bold; font-size:24px; color:#7C56A9}
      O1 - Hosts: .adcnt{width:172px; display:block; float:right; text-align:left;cursor:pointer;cursor:hand;}
      O1 - Hosts: .adcnt td {text-align:left;}
      O1 - Hosts: .adsubt{font-size:10px; font-family:verdana; font-weight:bold; color:#b4b4b4; cursor:default;margin-top:5px;}
      O1 - Hosts: .ybadge { font-family: Verdana, Arial, Helvetica, sans-serif; font-size:10px; color: #666666; margin-top:10px;}
      O1 - Hosts: .ybadge img {margin-top:6px;}
      O1 - Hosts: .adtable {font-family:Verdana, Arial, Helvetica, sans-serif; font-size:10px;border: 1px solid #d6dbe7; background-color:#eff7ff; padding:3px; margin-bottom:10px; width:172px;}
      O1 - Hosts: .adttl{font-weight:bold;margin-bottom:3px;}
      O1 - Hosts: .addescr{color:#6b6b6b; margin-bottom:3px;}
      O1 - Hosts: .adlink a {color:#008200; text-decoration:none;}
      O1 - Hosts: </style>
      O1 - Hosts: </head>
      O1 - Hosts: <body>
      O1 - Hosts: <!-- following code added by server. PLEASE REMOVE -->
      O1 - Hosts: <!-- preceding code added by server. PLEASE REMOVE -->
      O1 - Hosts: <div id="maincnt">
      O1 - Hosts: <div class="geohead"><div id="geologo"><a href="https://smallbusiness.yahoo.com/"><img height=33 alt="Yahoo! GeoCities" src="http://us.i1.yimg.com/us.yimg.com/i/us/nt/ma/ma_geo_1.gif" width=259 border=0></a></div>
      O1 - Hosts: <div id="rightside"><div id="wlinks"><a href="https://smallbusiness.yahoo.com/">GeoCities Home</a> - <a href="https://fr.yahoo.com/?p=us">Yahoo!</a> - <a href="https://help.yahoo.com/kb/account">Help</a></div>
      O1 - Hosts: </div></div>
      O1 - Hosts: <div class="bodywrap">
      O1 - Hosts: <div class="bodycnt">
      O1 - Hosts: <div class="title">Sorry, this GeoCities site is currently unavailable.</div>
      O1 - Hosts: <p>The GeoCities web site you were trying to view has temporarily exceeded its data transfer limit. Please try again later. </p>
      O1 - Hosts: <p>Are you the site owner?
      O1 - Hosts: Avoid service interruptions in the future by increasing your data transfer limit!
      O1 - Hosts: <a href="https://help.yahoo.com/kb/account" target="_blank">Find out how.</a> </p>
      O1 - Hosts: <p><a href="https://help.yahoo.com/kb/account" target="_blank">Learn more about data transfer.</a></p>
      O1 - Hosts: </div>
      O1 - Hosts: <div class="adcnt">
      O1 - Hosts: <a target="_top" href="https://smallbusiness.yahoo.com/"><img src="http://us.i1.yimg.com/us.yimg.com/i/us/smbiz/b/geo_mast_small2.gif" alt="Yahoo! GeoCities" border="0" height="15" hspace="0" vspace="0" width="141"></a>
      O1 - Hosts: <div class="adsubt">SPONSORED LINKS</div>
      O1 - Hosts: <!--<table width="172" border="0" bgcolor="#FFFFFF" class="adtable"><tr><td align=left>-->
      O1 - Hosts: <div class="adtable">
      O1 - Hosts: <div class="adttl" title="Reliable plans include domain & 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27166/*https://smallbusiness.yahoo.com/hosting" target="_blank">Yahoo! Web Hosting<br>
      O1 - Hosts: $25 Setup Waived</a></div>
      O1 - Hosts: <div class="addescr" title="Reliable plans include domain & 24x7 support.">Reliable plans include domain & 24x7 support.</div>
      O1 - Hosts: <div class="adlink" title="Reliable plans include domain & 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27166/*https://smallbusiness.yahoo.com/hosting" target="_blank">webhosting.yahoo.com</a></div>
      O1 - Hosts: </div>
      O1 - Hosts: <div class="adtable">
      O1 - Hosts: <div class="adttl" title="Reliable plans include domain & 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27176/*https://smallbusiness.yahoo.com/domains" target="_blank">Domain Names from Yahoo! only $9.95/yr</a></div>
      O1 - Hosts: <div class="addescr" title="Includes starter web page, email & domain forwarding, 24x7 support.">Includes starter web page, email & domain forwarding, 24x7 support.</div>
      O1 - Hosts: <div class="adlink" title="Includes starter web page, email & domain forwarding, 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27176/*https://smallbusiness.yahoo.com/domains" target="_blank">domains.yahoo.com</a></div>
      O1 - Hosts: </div>
      O1 - Hosts: <div class="adtable">
      O1 - Hosts: <div class="adttl" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27184/*https://smallbusiness.yahoo.com/mail" target="_blank">Yahoo! Business Email<br> Domain Included</a></div>
      O1 - Hosts: <div class="addescr" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning.">Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning.</div>
      O1 - Hosts: <div class="adlink" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27184/*https://smallbusiness.yahoo.com/mail" target="_blank">smallbusiness.yahoo.com</a></div>
      O1 - Hosts: </div>
      O1 - Hosts: <div class="adtable">
      O1 - Hosts: <div class="adttl" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=/27190/*https://smallbusiness.yahoo.com/stores" target="_blank">Ecommerce from Yahoo!<br> 1 Month Free</a></div>
      O1 - Hosts: <div class="addescr" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support.">$50 setup fee waived. A reliable ecommerce plan, 24x7 support.</div>
      O1 - Hosts: <div class="adlink" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=/27190/*https://smallbusiness.yahoo.com/stores" target="_blank">smallbusiness.yahoo.com</a></div>
      O1 - Hosts: </div>
      O1 - Hosts: <div class="ybadge">
      O1 - Hosts: Get your own web site at <br><a target="_top" href="https://smallbusiness.yahoo.com/">Yahoo! GeoCities</a>
      O1 - Hosts: <a href="https://smallbusiness.yahoo.com/hosting" target="_top"><img src="http://us.i1.yimg.com/us.yimg.com/i/us/wh/gr/badge_hostedby_purp_2.gif" alt="Hosted by Yahoo! Web Hosting" align="middle" border="0" height="31" width="88"></a>
      O1 - Hosts: </div>
      O1 - Hosts: </div>
      O1 - Hosts: </div>
      O1 - Hosts: <div class=ftr>
      O1 - Hosts: <hr size=1 width=100%>
      O1 - Hosts: Copyright ©
      O1 - Hosts: 2005 Yahoo! Inc. All rights reserved<br>
      O1 - Hosts: <a href="https://www.verizonmedia.com/policies/">Privacy Policy</a>
      O1 - Hosts: - <a href="https://fr.yahoo.com/?p=us">Copyright Policy</a>
      O1 - Hosts: - <a href="https://fr.yahoo.com/?p=us">Guidelines</a>
      O1 - Hosts: - <a href="https://fr.yahoo.com/?p=us">Terms of Service</a>
      O1 - Hosts: - <a href="https://help.yahoo.com/kb/account">Help</a>
      O1 - Hosts: </div>
      O1 - Hosts: </div>
      O1 - Hosts: </body>
      O1 - Hosts: </html>
      O1 - Hosts: <!-- text below generated by server. PLEASE REMOVE --></object></layer></div></span></style></noscript></table></script></applet>
      O1 - Hosts: <IMG SRC="http://geo.yahoo.com/serv?s=19190039&t=1190909533&f=us-w72" ALT=1 WIDTH=1 HEIGHT=1>
      O2 - BHO: &Research - {037C7B8A-151A-49E6-BAED-CC05FCB50328} - C:\WINDOWS\system32\winsrc.dll
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: &Research - {0B014B81-4E12-46F9-806F-55867AF8FD3C} - C:\WINDOWS\system32\winsrc.dll
      O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\FICHIE~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: (no name) - {3896371c-7aa7-47f4-b085-663fe22f9c7e} - C:\WINDOWS\system32\borakari.dll (file missing)
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O4 - HKLM\..\Run: [CmPCIaudio] RunDll32 cmicnfg3.cpl,CMICtrlWnd
      O4 - HKLM\..\Run: [lxddmon.exe] "C:\Program Files\Lexmark 2500 Series\lxddmon.exe"
      O4 - HKLM\..\Run: [lxddamon] "C:\Program Files\Lexmark 2500 Series\lxddamon.exe"
      O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
      O4 - HKLM\..\Run: [LXDDCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDDtime.dll,_RunDLLEntry@16
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\disabled-wzcsldr2.exe
      O4 - HKLM\..\Run: [D-Link D-Link Wireless G DWA-510] C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [AXIS TONS THE MP3] C:\Documents and Settings\All Users\Application Data\Readme Live Axis Tons\Default grey.exe
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [liyoyosuvu] Rundll32.exe "C:\WINDOWS\system32\noyutumi.dll",s
      O4 - HKLM\..\Run: [CPM1b1c317f] Rundll32.exe "c:\windows\system32\zevihami.dll",a
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [CanalPlayer] C:\Program Files\Lecteur CANALPLAY\CanalPlayer.exe
      O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
      O4 - HKCU\..\Run: [Tok-Cirrhatus] "C:\Documents and Settings\fattah koudia\Local Settings\Application Data\smss.exe"
      O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
      O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [BurnRoad] C:\DOCUME~1\FATTAH~1\APPLIC~1\Idlelies\Wait store.exe
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [ieupdate] "C:\WINDOWS\system32\explorer32.exe"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [liyoyosuvu] Rundll32.exe "C:\WINDOWS\system32\noyutumi.dll",s (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
      O4 - Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\fattah koudia\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
      O4 - Global Startup: PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
      O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O15 - Trusted Zone: *.canalplay.com (HKLM)
      O15 - Trusted Zone: *.canalplusactive.com (HKLM)
      O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15031/CTSUEng.cab
      O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
      O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15035/CTPID.cab
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - AppInit_DLLs: C:\WINDOWS\system32\fatalofi.dll C:\WINDOWS\system32\fotuwutu.dll avgrsstx.dll C:\WINDOWS\system32\kafawagi.dll c:\windows\system32\zevihami.dll
      O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\zevihami.dll
      O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\zevihami.dll
      O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      O23 - Service: lxdd_device - - C:\WINDOWS\system32\lxddcoms.exe
      0
    2. @Abdelmuhsinben ya du boulot

      redemarre ton pc sans echec f8 au demarrage aprés l'apparition du bios

      redemarre Smitfraud "de preference sans echec" et fait l'option nettoyage "2"
      Réponds O aux deux questions suivantes:
      Voulez-vous nettoyer le registre ?
      Corriger le fichier infecté ?
      Un rapport.txt sera généré et tu le sauve tu redemarre et tu le postes

      télechargez Malwarebyte's ici http://www.malwarebytes.org/mbam/program/mbam-setup.exe
      le programme va se mettre automatiquement a jour.

      Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

      Click maintenant sur l´onglet recherche et coche la case : "executer un examen rapide".

      Puis click sur "rechercher".

      Laisse le scanner le pc...

      Si des elements on ete trouvés > click sur supprimer la selection.

      si il t´es demandé de redemarrer > click sur "yes".

      A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

      Copie et colle le rapport stp.

      PS : les rapport sont aussi rangé dans l onglet rapport/log
      0
    3. @sherredVoici le nouveau rapport Smitfraud:

      SmitFraudFix v2.388

      Rapport fait à 20:40:08,62, 07/01/2009
      Executé à partir de C:\Documents and Settings\fattah koudia\Bureau\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode sans echec

      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
      "{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"="STS"

      [HKEY_CLASSES_ROOT\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
      @="c:\windows\system32\zevihami.dll"

      [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
      @="c:\windows\system32\zevihami.dll"

      »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
      "http://www.w3.org/TR/html4/loose.dtd">
      <html>
      <head>
      <script LANGUAGE="JavaScript">
      <!--
      if (window != top)
      top.location.href = location.href;
      // -->
      </script>
      <title>Site Unavailable</title>
      ...

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

      S!Ri's WS2Fix: LSP not Found.

      »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

      GenericRenosFix by S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

      C:\WINDOWS\system32\a.exe supprimé
      C:\WINDOWS\system32\ieupdates.exe supprimé
      C:\WINDOWS\system32\winsrc.dll supprimé
      C:\Documents and Settings\fattah koudia\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk supprimé
      C:\DOCUME~1\FATTAH~1\MENUDM~1\Antivirus 2009 supprimé

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

      Agent.OMZ.Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» RK

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{DA939196-1071-49EC-B597-3C578E19B63A}: DhcpNameServer=212.27.40.240 212.27.40.241
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{DA939196-1071-49EC-B597-3C578E19B63A}: DhcpNameServer=212.27.40.240 212.27.40.241
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{DA939196-1071-49EC-B597-3C578E19B63A}: DhcpNameServer=212.27.40.240 212.27.40.241
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241

      »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

      Nettoyage terminé.

      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
      "{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"="STS"

      [HKEY_CLASSES_ROOT\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
      @="c:\windows\system32\zevihami.dll"

      [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
      @="c:\windows\system32\zevihami.dll"

      »»»»»»»»»»»»»»»»»»»»»»»» Fin
      0
    4. @sherredet le rapport Malwarebytes:

      Malwarebytes' Anti-Malware 1.32
      Version de la base de données: 1629
      Windows 5.1.2600 Service Pack 3

      07/01/2009 21:31:04
      mbam-log-2009-01-07 (21-31-04).txt

      Type de recherche: Examen rapide
      Eléments examinés: 56941
      Temps écoulé: 9 minute(s), 8 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 1
      Clé(s) du Registre infectée(s): 8
      Valeur(s) du Registre infectée(s): 7
      Elément(s) de données du Registre infecté(s): 6
      Dossier(s) infecté(s): 1
      Fichier(s) infecté(s): 21

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      c:\WINDOWS\system32\zevihami.dll (Trojan.Vundo.H) -> Delete on reboot.

      Clé(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3896371c-7aa7-47f4-b085-663fe22f9c7e} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{3896371c-7aa7-47f4-b085-663fe22f9c7e} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
      HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{037c7b8a-151a-49e6-baed-cc05fcb50328} (Trojan.BHO) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.

      Valeur(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\liyoyosuvu (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm1b1c317f (Trojan.Vundo.H) -> Delete on reboot.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo.H) -> Delete on reboot.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AXIS TONS THE MP3 (Trojan.Agent) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\mysearchnow.com (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\www.mysearchnow.com (Malware.Trace) -> Quarantined and deleted successfully.

      Elément(s) de données du Registre infecté(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\zevihami.dll -> Delete on reboot.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\zevihami.dll -> Delete on reboot.
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\devopaha.dll -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo) -> Data: c:\windows\system32\kafawagi.dll -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo) -> Data: system32\kafawagi.dll -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

      Dossier(s) infecté(s):
      C:\Program Files\Antivirus 2009 (Rogue.Antivirus 2009) -> Quarantined and deleted successfully.

      Fichier(s) infecté(s):
      C:\WINDOWS\system32\beyobusu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\usuboyeb.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\zevihami.dll (Trojan.Vundo.H) -> Delete on reboot.
      C:\WINDOWS\system32\rumusipa.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\vajapohu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\nupikufo.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\devopaha.dll (Trojan.Vundo) -> Delete on reboot.
      C:\WINDOWS\system32\jafijohe.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\jaweviyi.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\hekazezi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\wobezozu.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\trzC.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\kafawagi.dll (Trojan.Vundo) -> Delete on reboot.
      C:\WINDOWS\system32\explorer32.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\fatalofi.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\yonugese.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\huzisopo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\vogapasa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\napokoku.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\judinoyo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\yavafike.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

      Il y a encore d'autres choses a faire?
      0
    5. mon nom Steve le pirate et ton nom,si tu veux toujours de mon aide
      0
  2. bon boulot

    Télécharge combofix.exe
    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    clique combofix.exe.
    touche 1 (Yes) pour démarrer le scan.
    une fois fini un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
    Le rapport se trouve également ici : C:\Combofix.txt
    0
    1. pour la chere c'est sure c'est chere ...mais..tendre ? on a la meme! hehe
      0
  3. Donc juskici tout va bien????

    Voici le rapport Combofix

    ComboFix 09-01-07.02 - fattah koudia 2009-01-08 15:51:13.1 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.447.120 [GMT 1:00]
    Lancé depuis: c:\documents and settings\fattah koudia\Bureau\ComboFix.exe
    * Un nouveau point de restauration a été créé
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
    c:\windows\Downloaded Program Files\setup.inf
    c:\windows\system32\404Fix.exe
    c:\windows\system32\apesisuk.ini
    c:\windows\system32\ariwaluh.ini
    c:\windows\system32\asudevin.ini
    c:\windows\system32\baborefe.dll
    c:\windows\system32\binuvete.dll
    c:\windows\system32\bobebeji.dll
    c:\windows\system32\daneteki.dll
    c:\windows\system32\dayavuhe.dll
    c:\windows\system32\dedunuba.dll
    c:\windows\system32\delahiru.dll
    c:\windows\system32\deporare.dll
    c:\windows\system32\devajusi.dll
    c:\windows\system32\dezudesu.dll
    c:\windows\system32\diwajame.dll
    c:\windows\system32\dodegomi.dll
    c:\windows\system32\dumphive.exe
    c:\windows\system32\efikedow.ini
    c:\windows\system32\ehemifak.ini
    c:\windows\system32\erupinep.ini
    c:\windows\system32\ewurasap.ini
    c:\windows\system32\ezililob.ini
    c:\windows\system32\feyavezi.dll
    c:\windows\system32\fibufeti.dll
    c:\windows\system32\fitelote.dll
    c:\windows\system32\fizawawe.dll
    c:\windows\system32\fonugile.dll
    c:\windows\system32\fopihofu.dll
    c:\windows\system32\fuweyuni.dll
    c:\windows\system32\garavebu.dll
    c:\windows\system32\gavedewu.dll
    c:\windows\system32\gipidiwu.dll
    c:\windows\system32\gitenayi.dll
    c:\windows\system32\gohifodi.dll
    c:\windows\system32\gomuzidi.dll
    c:\windows\system32\habanuvo.dll
    c:\windows\system32\hemudapa.dll
    c:\windows\system32\hetiguta.dll
    c:\windows\system32\hevipezo.dll
    c:\windows\system32\higihape.dll
    c:\windows\system32\hiyusago.dll
    c:\windows\system32\hodaluho.dll
    c:\windows\system32\IEDFix.C.exe
    c:\windows\system32\IEDFix.exe
    c:\windows\system32\imujomid.ini
    c:\windows\system32\ipezahuf.ini
    c:\windows\system32\ituyober.ini
    c:\windows\system32\ivaveyez.ini
    c:\windows\system32\janufini.dll
    c:\windows\system32\jarizasu.dll
    c:\windows\system32\jaweviyi.dll
    c:\windows\system32\jazoloya.dll
    c:\windows\system32\jedepona.dll
    c:\windows\system32\jimekaju.dll
    c:\windows\system32\jojufoho.dll
    c:\windows\system32\jukohani.dll
    c:\windows\system32\kidoyera.dll
    c:\windows\system32\kirasahi.dll
    c:\windows\system32\kiyubipo.dll
    c:\windows\system32\layekanu.dll
    c:\windows\system32\ledamine.dll
    c:\windows\system32\lelasuba.dll
    c:\windows\system32\lifosiyo.dll
    c:\windows\system32\litilifu.dll
    c:\windows\system32\luruwono.dll
    c:\windows\system32\luyiwiya.dll
    c:\windows\system32\majediyi.dll
    c:\windows\system32\matizava.dll
    c:\windows\system32\mazihihe.dll
    c:\windows\system32\metunale.dll
    c:\windows\system32\misahavu.dll
    c:\windows\system32\monigula.dll
    c:\windows\system32\moriwami.dll
    c:\windows\system32\namiroto.dll
    c:\windows\system32\negimeka.dll
    c:\windows\system32\nubobevu.dll
    c:\windows\system32\nuhiteso.dll
    c:\windows\system32\nuzeroto.dll
    c:\windows\system32\o4Patch.exe
    c:\windows\system32\papororo.dll
    c:\windows\system32\pipuduse.dll
    c:\windows\system32\pomijowu.dll
    c:\windows\system32\Process.exe
    c:\windows\system32\pufajahe.dll
    c:\windows\system32\pupamawe.dll
    c:\windows\system32\rahohipa.dll
    c:\windows\system32\razusula.dll
    c:\windows\system32\refemope.dll
    c:\windows\system32\reregako.dll
    c:\windows\system32\rikojine.dll
    c:\windows\system32\rimudovo.dll
    c:\windows\system32\ritibiji.dll
    c:\windows\system32\sawupima.dll
    c:\windows\system32\soziredo.dll
    c:\windows\system32\SrchSTS.exe
    c:\windows\system32\sulumetu.dll
    c:\windows\system32\sunapija.dll
    c:\windows\system32\tajopava.dll
    c:\windows\system32\teyasoge.dll
    c:\windows\system32\tijawani.dll
    c:\windows\system32\tipukuvu.dll
    c:\windows\system32\tisitora.dll
    c:\windows\system32\tmp.reg
    c:\windows\system32\tohagugu.dll
    c:\windows\system32\tubivabo.dll
    c:\windows\system32\tudopupa.dll
    c:\windows\system32\tukugave.dll
    c:\windows\system32\tupaleke.dll
    c:\windows\system32\ujadowep.ini
    c:\windows\system32\urihikat.ini
    c:\windows\system32\utigogit.ini
    c:\windows\system32\uzehiven.ini
    c:\windows\system32\VACFix.exe
    c:\windows\system32\VCCLSID.exe
    c:\windows\system32\volizita.dll
    c:\windows\system32\vulojedu.dll
    c:\windows\system32\wifenoho.dll
    c:\windows\system32\wifokuvi.dll
    c:\windows\system32\WS2Fix.exe
    c:\windows\system32\wuleluzu.dll
    c:\windows\system32\yalemera.dll
    c:\windows\system32\yawewune.dll
    c:\windows\system32\yerofata.dll
    c:\windows\system32\yijazowi.dll
    c:\windows\system32\yotenodo.dll
    c:\windows\system32\yumaluso.dll
    c:\windows\system32\yupititi.dll
    c:\windows\system32\zayiveva.dll
    c:\windows\system32\zayiyahu.dll
    c:\windows\system32\zerakede.dll
    c:\windows\system32\zoluvomo.dll

    ----- BITS: Il y a peut-être des sites infectés -----

    hxxp://77.74.48.105
    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2008-12-08 au 2009-01-08 ))))))))))))))))))))))))))))))))))))
    .

    2009-01-07 21:16 . 2009-01-07 21:16 <REP> d-------- c:\documents and settings\fattah koudia\Application Data\Malwarebytes
    2009-01-07 21:15 . 2009-01-07 21:15 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-01-07 15:20 . 2009-01-07 15:20 <REP> d-------- c:\program files\Trend Micro
    2009-01-07 15:06 . 2008-12-12 00:57 78,336 --a------ c:\windows\system32\Agent.OMZ.Fix.exe
    2009-01-06 22:21 . 2009-01-07 22:02 <REP> d-------- c:\program files\Navilog1
    2009-01-06 20:09 . 2009-01-06 20:59 <REP> d--h----- C:\$AVG8.VAULT$
    2009-01-06 19:54 . 2009-01-06 19:54 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
    2009-01-06 19:54 . 2009-01-06 19:54 76,040 --a------ c:\windows\system32\drivers\avgtdix.sys
    2009-01-06 19:54 . 2009-01-06 19:54 10,520 --a------ c:\windows\system32\avgrsstx.dll
    2009-01-06 19:53 . 2009-01-07 20:08 <REP> d-------- c:\windows\system32\drivers\Avg
    2009-01-06 19:53 . 2009-01-06 19:53 <REP> d-------- c:\program files\AVG
    2009-01-06 19:53 . 2009-01-06 20:27 <REP> d-------- c:\documents and settings\fattah koudia\Application Data\AVGTOOLBAR
    2009-01-06 19:53 . 2009-01-06 19:53 <REP> d-------- c:\documents and settings\All Users\Application Data\avg8
    2009-01-06 13:01 . 2009-01-06 13:01 <REP> d-------- c:\program files\Kaspersky Lab
    2009-01-01 11:19 . 2009-01-01 11:19 6,078 ---hs---- c:\windows\system32\dilifori.dll
    2009-01-01 11:19 . 2009-01-01 11:19 6,076 ---hs---- c:\windows\system32\wutakizu.dll
    2008-12-31 12:25 . 2008-12-31 12:25 2,724 ---hs---- c:\windows\system32\gatotafi.dll
    2008-12-27 09:58 . 2008-12-27 09:58 6,077 ---hs---- c:\windows\system32\mirikiri.dll
    2008-12-27 09:58 . 2008-12-27 09:58 6,077 ---hs---- c:\windows\system32\jipilere.dll
    2008-12-24 08:55 . 2008-12-24 08:55 4,096 ---hs---- c:\windows\system32\yuhodose.dll
    2008-12-15 08:37 . 2008-12-19 17:48 <REP> d-------- c:\windows\system32\Service
    2008-12-12 11:50 . 2008-12-12 11:50 <REP> d-------- c:\documents and settings\fattah koudia\Application Data\HiYo

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-01-08 14:58 --------- d-----w c:\program files\Lx_cats
    2009-01-08 14:57 --------- d-----w c:\documents and settings\fattah koudia\Application Data\OpenOffice.org2
    2009-01-07 21:03 --------- d-----w c:\program files\Astonsoft
    2008-12-21 16:44 --------- d-----w c:\program files\inSpeak
    2008-12-21 16:44 --------- d-----w c:\documents and settings\fattah koudia\Application Data\inSpeak
    2008-12-14 17:47 --------- d-----w c:\documents and settings\fattah koudia\Application Data\Apple Computer
    2008-12-02 20:49 --------- d-----w c:\program files\Circle Developement
    2008-12-02 14:50 --------- d-----w c:\program files\Fichiers communs\McAfee
    2008-12-02 14:50 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
    2008-12-02 14:10 --------- d-----w c:\documents and settings\fattah koudia\Application Data\Idlelies
    2008-12-02 14:09 --------- d-----w c:\documents and settings\All Users\Application Data\Readme Live Axis Tons
    2008-12-02 14:00 --------- d-----w c:\program files\Alwil Software
    2008-11-30 15:54 --------- d-----w c:\program files\CDex_150
    2008-11-27 10:56 --------- d-----w c:\program files\Messenger Plus! Live
    2008-11-27 10:56 --------- d-----w c:\program files\Idlelies
    2008-11-27 09:29 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
    2008-11-26 17:56 --------- d-----w c:\documents and settings\LocalService\Application Data\SACore
    2008-11-25 13:15 --------- d-----w c:\documents and settings\fattah koudia\Application Data\LimeWire
    2008-11-24 11:01 --------- d-----w c:\program files\eMule
    2008-11-21 22:17 --------- d-----w c:\program files\iTunes
    2008-11-21 22:17 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
    2008-11-21 22:16 --------- d-----w c:\program files\iPod
    2008-11-21 22:16 --------- d-----w c:\program files\Bonjour
    2008-11-21 22:16 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
    2008-11-21 22:14 --------- d-----w c:\program files\QuickTime
    2008-11-21 22:12 --------- d-----w c:\program files\Apple Software Update
    2008-11-21 22:11 --------- d-----w c:\program files\Fichiers communs\Apple
    2008-11-21 22:11 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
    2008-11-20 09:40 --------- d-----w c:\documents and settings\NetworkService\Application Data\SACore
    2008-11-19 21:27 --------- d-----w c:\program files\MSXML 4.0
    2007-05-13 11:17 8 ----a-w c:\documents and settings\fattah koudia\Application Data\usb.dat.bin
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "LightScribe Control Panel"="c:\program files\Fichiers communs\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
    "CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 868352]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "lxddmon.exe"="c:\program files\Lexmark 2500 Series\lxddmon.exe" [2007-02-13 291760]
    "lxddamon"="c:\program files\Lexmark 2500 Series\lxddamon.exe" [2007-02-06 20480]
    "FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2007-02-13 312240]
    "LXDDCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXDDtime.dll" [2007-01-22 102400]
    "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-09-28 185872]
    "D-Link D-Link Wireless G DWA-510"="c:\program files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe" [2007-05-04 1662976]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-06 1261336]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

    c:\documents and settings\fattah koudia\Menu D‚marrer\Programmes\D‚marrage\
    OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
    Outil de notification Live Search.lnk - c:\documents and settings\fattah koudia\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe [2008-11-26 143360]

    c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
    PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [2008-05-08 10452992]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "msacm.l3acm"= l3codecp.acm
    "vidc.DIV3"= DivXc32.dll
    "vidc.DIV4"= DivXc32f.dll
    "msacm.divxa32"= DivXa32.acm
    "msacm.speex32"= speex32.acm

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UpdatesDisableNotify"=dword:00000001
    "AntiVirusOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\eMule\\emule.exe"=
    "c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
    "c:\\WINDOWS\\system32\\lxddcoms.exe"=
    "c:\\Program Files\\Lexmark 2500 Series\\lxddamon.exe"=
    "c:\\Program Files\\Lexmark 2500 Series\\App4R.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Fichiers communs\\Real\\Update_OB\\realsched.exe"=
    "c:\\Program Files\\D-Link\\D-Link Wireless G DWA-510\\AirGCFG.exe"=
    "c:\\Program Files\\inSpeak\\inSpeak.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\usnsvc.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "17056:TCP"= 17056:TCP:NortonAV
    "14305:TCP"= 14305:TCP:NortonAV
    "16984:TCP"= 16984:TCP:NortonAV
    "15570:TCP"= 15570:TCP:NortonAV
    "15055:TCP"= 15055:TCP:NortonAV
    "17930:TCP"= 17930:TCP:NortonAV
    "13695:TCP"= 13695:TCP:NortonAV
    "16848:TCP"= 16848:TCP:NortonAV
    "18527:TCP"= 18527:TCP:NortonAV
    "13334:TCP"= 13334:TCP:NortonAV
    "13132:TCP"= 13132:TCP:NortonAV

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-01-06 97928]
    R4 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-06 875288]
    R4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-06 231704]
    R4 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-01-06 76040]
    R4 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe -service --> c:\windows\system32\lxddcoms.exe -service [?]
    S3 3xHybrid;TerraTec BDA capture service;c:\windows\system32\drivers\3xHybrid.sys [2007-05-11 908160]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
    \Shell\Auto\command - K:\AdobeR.exe e
    \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{901dc97c-fcdc-11db-8e86-000fea3de308}]
    \Shell\AutoRun\command - J:\ReadMe.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "c:\program files\Fichiers communs\LightScribe\LSRunOnce.exe"
    .
    Contenu du dossier 'Tâches planifiées'

    2009-01-08 c:\windows\Tasks\AA024C8B9101C313.job
    - c:\docume~1\fattah~1\applic~1\idlelies\Axis Safe Name.exe []

    2009-01-06 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
    .
    - - - - ORPHELINS SUPPRIMES - - - -

    BHO-{0B014B81-4E12-46F9-806F-55867AF8FD3C} - c:\windows\system32\winsrc.dll
    WebBrowser-{4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
    HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
    HKCU-Run-CanalPlayer - c:\program files\Lecteur CANALPLAY\CanalPlayer.exe
    HKCU-Run-PcSync - c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe
    HKCU-Run-WOOKIT - c:\progra~1\Wanadoo\Shell.exe
    HKCU-Run-BurnRoad - c:\docume~1\FATTAH~1\APPLIC~1\Idlelies\Wait store.exe
    HKLM-Run-ANIWZCS2Service - c:\program files\ANI\ANIWZCS2 Service\disabled-wzcsldr2.exe
    HKLM-Run-CmPCIaudio - cmicnfg3.cpl

    .
    ------- Examen supplémentaire -------
    .
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = *.local
    Trusted Zone: *.canalplay.com
    Trusted Zone: *.canalplusactive.com
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-01-08 15:58:23
    Windows 5.1.2600 Service Pack 3 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    LXDDCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXDDtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************
    .
    ------------------------ Autres processus actifs ------------------------
    .
    c:\windows\system32\rundll32.exe
    c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\OpenOffice.org 2.4\program\soffice.exe
    c:\program files\OpenOffice.org 2.4\program\soffice.bin
    c:\documents and settings\fattah koudia\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\windows\system32\CTSVCCDA.EXE
    c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
    c:\progra~1\AVG\AVG8\avgrsx.exe
    c:\windows\system32\lxddcoms.exe
    c:\program files\Microsoft LifeCam\MSCamS32.exe
    c:\program files\Windows Media Player\wmpnetwk.exe
    c:\program files\iPod\bin\iPodService.exe
    .
    **************************************************************************
    .
    Heure de fin: 2009-01-08 16:03:26 - La machine a redémarré
    ComboFix-quarantined-files.txt 2009-01-08 15:03:14

    Avant-CF: 14 932 660 224 octets libres
    Après-CF: 16,360,271,872 octets libres

    WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

    351 --- E O F --- 2008-11-20 19:43:59
    0
    1. tu peu me refaire un hijack

      et me dire comment se comporte ta machine ?
      0
      1. Voici le nouveau rapport HiJack:

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 09:14:07, on 09/01/2009
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16762)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Lexmark 2500 Series\lxddmon.exe
        C:\Program Files\Lexmark 2500 Series\lxddamon.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\PROGRA~1\AVG\AVG8\avgtray.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
        C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Windows Media Player\WMPNSCFG.exe
        C:\Documents and Settings\fattah koudia\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
        C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
        C:\Documents and Settings\fattah koudia\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
        C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\WINDOWS\system32\CTsvcCDA.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
        C:\WINDOWS\system32\lxddcoms.exe
        C:\Program Files\Microsoft LifeCam\MSCamS32.exe
        C:\WINDOWS\system32\svchost.exe
        C:\PROGRA~1\AVG\AVG8\avgrsx.exe
        C:\PROGRA~1\AVG\AVG8\avgemc.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Program Files\Windows Live\Messenger\usnsvc.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\FICHIE~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
        O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
        O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
        O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
        O4 - HKLM\..\Run: [lxddmon.exe] "C:\Program Files\Lexmark 2500 Series\lxddmon.exe"
        O4 - HKLM\..\Run: [lxddamon] "C:\Program Files\Lexmark 2500 Series\lxddamon.exe"
        O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
        O4 - HKLM\..\Run: [LXDDCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDDtime.dll,_RunDLLEntry@16
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [D-Link D-Link Wireless G DWA-510] C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
        O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
        O4 - Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\fattah koudia\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
        O4 - Global Startup: PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O15 - Trusted Zone: *.canalplay.com (HKLM)
        O15 - Trusted Zone: *.canalplusactive.com (HKLM)
        O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15031/CTSUEng.cab
        O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
        O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
        O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15035/CTPID.cab
        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
        O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
        O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
        O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
        O23 - Service: lxdd_device - - C:\WINDOWS\system32\lxddcoms.exe
        0
      2. @Abdelmuhsinje te conseil avira
        mais on a pas fini

        Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
        https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

        * Lance l'installation du programme en exécutant le fichier téléchargé.
        * Double-clique maintenant sur le raccourci de Toolbar-S&D.
        * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
        * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
        * Poste le rapport généré. (C:\TB.txt)

        et

        0
    2. Ya encore bcp de truc a faire (tout ça pour avoir tapé OK sur une fenetre ke je m'en veu)

      le rapport de TB

      -----------\\ ToolBar S&D 1.2.8 XP/Vista

      Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
      X86-based PC ( Uniprocessor Free : AMD Sempron(tm) Processor 3100+ )
      BIOS : Award Modular BIOS v6.00PG
      USER : fattah koudia ( Administrator )
      BOOT : Normal boot
      Antivirus : AVG Anti-Virus Free 8.0 (Activated)
      C:\ (Local Disk) - NTFS - Total:72 Go (Free:14 Go)
      D:\ (Local Disk) - NTFS - Total:73 Go (Free:73 Go)
      E:\ (USB)
      F:\ (USB)
      G:\ (USB)
      H:\ (USB)
      I:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)

      "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
      Option : [1] ( 09/01/2009|17:51 )

      -----------\\ Recherche de Fichiers / Dossiers ...

      -----------\\ [..\Internet Explorer\Main]

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
      "Local Page"="C:\\windows\\system32\\blank.htm"
      "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
      "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
      "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
      "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
      "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
      "Local Page"="C:\\windows\\system32\\blank.htm"
      "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"

      --------------------\\ Recherche d'autres infections

      Aucune autre infection trouvée !

      1 - "C:\ToolBar SD\TB_1.txt" - 09/01/2009|17:52 - Option : [1]

      -----------\\ Fin du rapport a 17:52:56,96
      0
      1. autant faire les choses bien
        apres on nettoyera les outils utilisés ,et on y mettra un bonne protection
        enfin c'est toi qui decide

        Télécharges AD-Remover ( de Cyrildu17 / C_XX ) sur ton bureau :

        http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe
        /!\ Déconnectes toi et fermes toutes applications en cours

        ● Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
        ● Double clique sur l'icône Ad-removersituée sur ton bureau
        ● Au menu principal choisi l'option "A"
        ● Postes le rapport qui apparait à la fin .

        ( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

        (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
        0
        1. Ok pas de souci comme jtai di moi jy connai rien

          Voici le rapport

          ------- Logfile of AD-Remover 1.0.8.7 by C_XX | ONLY XP/VISTA -------

          # START at: 9:52:24 | Sam 10/01/2009 | Microsoft® Windows XP™ SP3 (v5.1.2600)
          # BOOT MODE: Normal
          # OPTION: Scan | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
          # PC: FATTAH-12B1FD8C | USER: fattah koudia ( Current user is an administrator)
          # DRIVE(S):
          - C:\ (File System: NTFS)
          - D:\ (File System: NTFS)
          # Internet Explorer v7.0.5730.11

          # RUNNING PROCESSES: 46

          +-----------------------| Boonty/Boonty Games Elements found :

          .
          .

          +-----------------------| Eorezo Elements found :

          .
          HKCR\EoRezoBHO.EoBho
          HKCR\EoRezoBHO.EoBho.1
          HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
          HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
          HKCU\SOFTWARE\EoRezo
          HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
          HKLM\SOFTWARE\EoRezo
          HKLM\SOFTWARE\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
          .
          C:\Documents and Settings\fattah koudia\Application Data\EoRezo
          C:\Documents and Settings\fattah koudia\Application Data\EoRezo\cmhost.cyp
          C:\Documents and Settings\fattah koudia\Application Data\EoRezo\ConfMedia.cyp
          C:\Documents and Settings\fattah koudia\Application Data\EoRezo\ConfMedia.cyp.old
          C:\Documents and Settings\fattah koudia\Application Data\EoRezo\db
          C:\Documents and Settings\fattah koudia\Application Data\EoRezo\eoDesktop
          C:\Documents and Settings\fattah koudia\Application Data\EoRezo\host.cyp
          C:\Documents and Settings\fattah koudia\Application Data\EoRezo\user.cyp
          C:\Documents and Settings\fattah koudia\Application Data\EoRezo\db\cat.cyp
          C:\Documents and Settings\fattah koudia\Application Data\EoRezo\eoDesktop\config.xml
          C:\Documents and Settings\fattah koudia\Application Data\EoRezo\eoDesktop\eoDesktop.html
          C:\Documents and Settings\fattah koudia\Application Data\EoRezo\eoDesktop\userConfig.xml

          +-----------------------| Everest Poker Elements found :

          .
          .

          +-----------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements found :

          .
          .

          +-----------------------| It's TV Elements found :

          HKCU\SOFTWARE\ItsLabel
          HKLM\SOFTWARE\ItsLabel
          .
          C:\Documents and Settings\fattah koudia\Application Data\ItsLabel
          C:\Documents and Settings\fattah koudia\Application Data\ItsLabel\ItsTV
          C:\Documents and Settings\fattah koudia\Application Data\ItsLabel\ItsTV\itsTV.xml

          +-----------------------| Sweetim Elements found :

          .
          .

          +-----------------------| ADDED SCAN :

          +--[HKEY_CURRENT_USER\..\Internet Explorer\MAIN]

          Start Page : hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

          +--[HKEY_LOCAL_MACHINE\..\Internet Explorer\MAIN]

          Start Page : hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home

          +---------------------------------------------------------------------------+

          [~3005 bytes] - "C:\AD-report-Scan-10.01.2009.log"

          # END at: 9:52:51 | 10/01/2009 - Time elapsed: 27.8 seconds

          +---------------------------------------------------------------------------+
          +------------------------------- [ E.O.F - 59 lines ]
          +---------------------------------------------------------------------------+
          0
      2. bon on y va je te previens j'ai mis la dose

        en 1er.......................................................................................
        Déconnectes toi et fermes toutes applications en cours !

        * Relances "Ad-remover" : au menu principal choisi l'option "B" . clean
        puis
        tu refait A supprimer tout

        --> le programme va travailler ...

        * Postes le rapport qui apparait à la fin

        ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

        /!\ Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides) /!\

        en 2.............................................................................................
        tu re demarre hijacthis et tu coche ces lignes
        O15 - Trusted Zone: *.canalplay.com (HKLM)
        O15 - Trusted Zone: *.canalplusactive.com (HKLM)
        tu clic sur fix checked

        en 3.............................................................................................
        telecharge SpywareBlaster qui va t'aider à completer la protection de ton navigateur
        https://www.01net.com/outils/telecharger/windows/Securite/anti-spyware/fiches/tele28872.html
        Lancer SpywareBlaster, sélection de l'onglet Updates

        "puis cliquer sur Check for Updates
        pour la mise à jour des définitions comportant une base de données
        de signatures des contrôles AvtiveX hostiles connus"

        Après le téléchargement, cliquer sur Enable Protection for All Unprotected Items
        Ou lors d'une premier installation sans mise à jour de la base des définitions,
        cliquer sur Protection Status puis sur Enable All Protection ,
        Un fois que cela est fini vous allez voir 0 items have protections disabled

        en 4.............................................................................................
        Ccleaner http://www.commentcamarche.net/telecharger/telechargement 168 ccleaner
        tu fait le nettoyage
        Fichiers temporaires de Windows
        Cookies, cache, historique d'Internet Explorer, Opera et Firefox
        Documents récents de Windows
        et ensuite reparation de la base de registre.

        en 5............................................................................................
        ToolsCleaner, merci A.Rothstein & Dj Quiou,
        http://www.commentcamarche.net/telecharger/telechargement 34055291 toolscleaner
        qui va désinstaller les outils que l'on a utilisés
        qui peuvent être dangereux pour ton PC

        en 6...........................................................................................
        puis tu telecharge http://sd-1.archive-host.com/membres/up/13923697555885739/sherred/RACCOURCIcDOS.rar
        executer
        "ce sont mes raccourcis rien que pour toi"
        tu ouvre le dossier et tu double clic sur "nettoyage prefetch"
        tape o

        en 7............................................................................................
        toujours dans raccourcicdos tu double clic sur "utilitaire de configuration"
        dans l'onglé demarrage tu décoche tout sauf ton antivirus et pare feu " si tu les vois dedans"

        enfin en 8....................................................................................
        telecharge spyware terminator
        https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/41933.html
        il est suffisament efficace
        par contre lors de l'installation decoche "crawler"
        ca encombre inutilement

        et pour un meilleur rendement ...si tu a du temp devant toi
        dans le poste de travail
        fait un clic droit sur le disque c
        puis proprietés
        onglé outils
        défragmenter maintenant

        0
        1. alors voici le rapport Ad Remover

          ------- Logfile of AD-Remover 1.0.8.7 by C_XX | ONLY XP/VISTA -------

          *** Limited to ***

          Boonty/BoontyGames
          Eorezo
          Everest Poker
          Funwebproduct/MyWay/MyWebsearch
          It's TV
          Sweetim

          ******************

          # START at: 14:37:47 | Dim 11/01/2009 | Microsoft® Windows XP™ SP3 (v5.1.2600)
          # BOOT MODE: Normal
          # OPTION: Clean | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
          # PC: FATTAH-12B1FD8C | USER: fattah koudia ( Current user is an administrator)
          # DRIVE(S):
          - C:\ (File System: NTFS)
          - D:\ (File System: NTFS)
          - I:\ (File System: CDFS)
          # Internet Explorer v7.0.5730.11

          # RUNNING PROCESSES: 46

          (!) ---- IE start pages reset

          +-----------------------| Boonty/Boonty Games Elements Deleted :

          .
          .

          +-----------------------| Eorezo Elements Deleted :

          .
          HKCR\EoRezoBHO.EoBho
          HKCR\EoRezoBHO.EoBho.1
          HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
          HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
          HKCU\SOFTWARE\EoRezo
          HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
          HKLM\SOFTWARE\EoRezo
          HKLM\SOFTWARE\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
          .
          C:\Documents and Settings\fattah koudia\Application Data\EoRezo

          +-----------------------| Everest Poker Elements Deleted :

          .
          .

          +-----------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements Deleted :

          .
          .

          +-----------------------| It's TV Elements Deleted :

          HKCU\SOFTWARE\ItsLabel
          HKLM\SOFTWARE\ItsLabel
          .
          C:\Documents and Settings\fattah koudia\Application Data\ItsLabel

          +-----------------------| Sweetim Elements Deleted :

          .
          .

          (!) ---- Temp files deleted.
          (!) ---- Recycle bin emptied in all drives.

          +-----------------------| ADDED SCAN :

          +---------------------------------------------------------------------------+

          +--[HKEY_CURRENT_USER\..\Internet Explorer\MAIN]

          Start Page : hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

          +--[HKEY_LOCAL_MACHINE\..\Internet Explorer\MAIN]

          Start Page : hxxp://fr.msn.com/

          +---------------------------------------------------------------------------+

          [~2276 bytes] - "C:\AD-report-Clean-11.01.2009.log"
          [~3339 bytes] - "C:\AD-report-Scan-10.01.2009.log"

          # END at: 14:40:51 | 11/01/2009 - Time elapsed: 3 minutes, 4 seconds

          +---------------------------------------------------------------------------+
          +------------------------------- [ E.O.F - 59 lines ]
          +---------------------------------------------------------------------------+

          et le nouveau HJT

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 14:41:51, on 11/01/2009
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16762)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Lexmark 2500 Series\lxddmon.exe
          C:\Program Files\Lexmark 2500 Series\lxddamon.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\PROGRA~1\AVG\AVG8\avgtray.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
          C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
          C:\Program Files\Windows Media Player\WMPNSCFG.exe
          C:\Documents and Settings\fattah koudia\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
          C:\Documents and Settings\fattah koudia\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
          C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\WINDOWS\system32\CTsvcCDA.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          C:\WINDOWS\system32\lxddcoms.exe
          C:\Program Files\Microsoft LifeCam\MSCamS32.exe
          C:\WINDOWS\system32\svchost.exe
          C:\PROGRA~1\AVG\AVG8\avgrsx.exe
          C:\PROGRA~1\AVG\AVG8\avgemc.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\WINDOWS\explorer.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\FICHIE~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
          O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
          O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
          O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
          O4 - HKLM\..\Run: [lxddmon.exe] "C:\Program Files\Lexmark 2500 Series\lxddmon.exe"
          O4 - HKLM\..\Run: [lxddamon] "C:\Program Files\Lexmark 2500 Series\lxddamon.exe"
          O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
          O4 - HKLM\..\Run: [LXDDCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDDtime.dll,_RunDLLEntry@16
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [D-Link D-Link Wireless G DWA-510] C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
          O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
          O4 - Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\fattah koudia\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
          O4 - Global Startup: PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O15 - Trusted Zone: *.canalplay.com (HKLM)
          O15 - Trusted Zone: *.canalplusactive.com (HKLM)
          O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15031/CTSUEng.cab
          O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
          O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
          O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15035/CTPID.cab
          O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
          O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
          O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
          O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          O23 - Service: lxdd_device - - C:\WINDOWS\system32\lxddcoms.exe
          0
          1. Voila il me reste la defragmentation que je vais laner un peu plus tard...
            0
        2. les lignes
          O15 - Trusted Zone: *.canalplay.com (HKLM)
          O15 - Trusted Zone: *.canalplusactive.com (HKLM)

          toujours la ?
          0
          1. Dans HJT??? non elles ont disparues
            0
          2. @Abdelmuhsinelle sont tourjours là, dans ton dernier rapport
            0
        3. Voici ce ke jai maintenant:

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 08:50:33, on 12/01/2009
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16762)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Lexmark 2500 Series\lxddmon.exe
          C:\Program Files\Lexmark 2500 Series\lxddamon.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\PROGRA~1\AVG\AVG8\avgtray.exe
          C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
          C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Windows Media Player\WMPNSCFG.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
          C:\Documents and Settings\fattah koudia\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
          C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\WINDOWS\system32\CTsvcCDA.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          C:\Documents and Settings\fattah koudia\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
          C:\WINDOWS\system32\lxddcoms.exe
          C:\Program Files\Microsoft LifeCam\MSCamS32.exe
          C:\Program Files\Spyware Terminator\sp_rsser.exe
          C:\WINDOWS\system32\svchost.exe
          C:\PROGRA~1\AVG\AVG8\avgrsx.exe
          C:\PROGRA~1\AVG\AVG8\avgemc.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\FICHIE~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
          O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
          O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
          O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
          O4 - HKLM\..\Run: [lxddmon.exe] "C:\Program Files\Lexmark 2500 Series\lxddmon.exe"
          O4 - HKLM\..\Run: [lxddamon] "C:\Program Files\Lexmark 2500 Series\lxddamon.exe"
          O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
          O4 - HKLM\..\Run: [LXDDCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDDtime.dll,_RunDLLEntry@16
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [D-Link D-Link Wireless G DWA-510] C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
          O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
          O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: OpenOffice.org 2.4.lnk
          O4 - Startup: Outil de notification Live Search.lnk
          O4 - Global Startup: PalTalk.lnk
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15031/CTSUEng.cab
          O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
          O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
          O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15035/CTPID.cab
          O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
          O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
          O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
          O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          O23 - Service: lxdd_device - - C:\WINDOWS\system32\lxddcoms.exe
          O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
          0
          1. MERCI MERCI MERCI MERCI MERCI MERCI..
            0