Infection : Win32/Heur + Win32/agent.AO

Résolu
Bonjour,
Mon Pc a était infecté par un virus Win32/Junk:Poly d'aprés mes petites connaisances ce virus a téléchager d'autre virus et trojans ...
Quand j'analyse avec Avast il détécte les infections il les supprimes mais lors du redémarage sa revient encore, AVG lui aussi il arrive pas a supprimer, Hijackthis ne détécte meme pas :S, et maintenant g 16 processus nommée svhost.exe éxécuté par le system alors que je n'avais que 6 processus avec se nom.
Besoin de votre aide et merci d'avance :)
Configuration: Windows XP Pro (Service pack 2)
Avast Edition Familial
AVG Professionnel
Internet Explorer 6.0

17 réponses

  1. Contributeur sécurité
    pour moi..et pour beaucoup d'autres..c'est
    pour installer Antivir en français

    le tuto

    mais c'est surtout ta manière de surfer sur le net qui est prépondérante

    plus d'info ici
    Prévention & Sécurité sur le net(Format pdf)
    1
    1. Contributeur sécurité
      Hijackthis ne détécte meme pas :S

      colle nous le rapport stp
      0
      1. Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 11:51:00, on 13/03/2009
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\PROGRA~1\AVG\AVG8\avgemc.exe
        C:\PROGRA~1\AVG\AVG8\avgrsx.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\AVG\AVG8\avgcsrvx.exe
        C:\WINDOWS\system32\wbem\wmiapsrv.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\svchost.exe
        C:\PROGRA~1\AVG\AVG8\avgtray.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\TeamSpeak3\TeamSpeak.exe
        C:\WINDOWS\system32\Restore\rstrui.exe
        C:\Program Files\AVG\AVG8\avgscanx.exe
        C:\Program Files\AVG\AVG8\avgcsrvx.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\Program Files\AVG\AVG8\avgui.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\windres.exe,userinit.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\undname.exe,C:\WINDOWS\system32\ndetect.exe,
        O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
        O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
        O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
        O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
        O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        0
        1. Contributeur sécurité
          cela me semble un peu court comme log...!!??

          Télécharge random's system information tool (RSIT) par random/random et sauvegarde-le sur le Bureau.
          http://images.malwareremoval.com/random/RSIT.exe
          Double-clique sur RSIT.exe afin de lancer RSIT.
          Clique Continue à l'écran Disclaimer.
          Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
          Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (<<qui sera affiché)
          ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).
          NB : Les rapports sont sauvegardés dans le dossier C:\rsit
          0
          1. info.txt logfile of random's system information tool 1.05 2009-03-13 11:54:57
            ======Uninstall list======

            -->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
            -->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
            -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
            -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
            -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
            -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
            -->C:\WINDOWS\UNRecode.exe /UNINSTALL
            -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{107254A0-0ADF-11D4-9397-00D0B7020B38}\setup.exe"
            -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
            7-Zip 4.65-->"C:\Program Files\7-Zip\Uninstall.exe"
            Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
            Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
            Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
            Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
            Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
            Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
            Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
            Adobe Color Common Settings-->MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
            Adobe Color EU Recommended Settings-->MsiExec.exe /I{73B5D990-04EA-4751-B10F-5534770B91F2}
            Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
            Adobe Color NA Extra Settings-->MsiExec.exe /I{FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}
            Adobe Default Language CS3-->MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
            Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
            Adobe ExtendScript Toolkit 2-->C:\Program Files\Fichiers communs\Adobe\Installers\3e054d2218e7aa282c2369d939e58ff\Setup.exe
            Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}
            Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
            Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
            Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{58BAA8D0-404E-4585-9FD3-ED1BB72AC2EE}
            Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{685A56F8-75B6-44AD-B3DA-FB0A3266B47C}
            Adobe Fonts All-->MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
            Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
            Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
            Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
            Adobe Photoshop CS3-->C:\Program Files\Fichiers communs\Adobe\Installers\32e9033392a51340b32fdc6ad893ab7\Setup.exe
            Adobe Photoshop CS3-->MsiExec.exe /I{BF794769-8875-4E01-B7BE-E00104604F4A}
            Adobe Reader 8.1.3-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81300000003}
            Adobe Setup-->MsiExec.exe /I{926DEB4E-2B0A-4C5C-AE4A-BF6C06949702}
            Adobe Setup-->MsiExec.exe /I{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}
            Adobe Shockwave Player 11-->C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
            Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
            Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
            Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
            Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
            Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
            Adobe XMP Panels CS3-->MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
            AMX Mod X Installer 1.8.1-->C:\Program Files\AMX Mod X\uninst.exe
            Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
            Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
            avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
            AVG 8.0-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
            CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
            CleanUp!-->C:\Program Files\CleanUp!\uninstall.exe
            Code de la Route-->MsiExec.exe /X{A37A26D5-8444-4862-933B-478371D0299D}
            Counter-Strike-->"C:\Program Files\Steam\steam.exe" steam://uninstall/10
            Decal Converter-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5BB207D6-0E1E-11D5-9B6A-00C04F7EC248}\Setup.exe"
            DoNaut 2.0.1-->C:\Program Files\Xponaut\DoNaut\uninst.exe
            eMule-->"C:\Program Files\eMule\Uninstall.exe"
            FileZilla Client 3.2.2-->C:\Program Files\FileZilla FTP Client\uninstall.exe
            Half-Life Dedicated Server Update Tool-->E:\HLDS\UNWISE.EXE E:\HLDS\INSTALL.LOG
            High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
            HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
            HLSW v1.3.1-->"C:\Program Files\HLSW\unins000.exe"
            Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
            Intel(R) Integrator Toolkit FE-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A67B3991-7226-404B-B5F6-71962D3F2376}\Setup.exe"
            Internet Download Manager-->C:\Program Files\Internet Download Manager\Uninstall.exe
            Java(TM) 6 Update 12-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF}
            la version d'évaluation de Namo WebEdiotor 6-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EF3FA287-2622-4340-AAF6-0AD29F21A691}\setup.exe" -l0x40c
            Ma-Config.com-->MsiExec.exe /X{8AFB8FC4-3EBA-4C67-943F-CF43DB2180F1}
            Macromedia Extension Manager-->MsiExec.exe /I{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}
            Macromedia Flash 8-->MsiExec.exe /I{2BD5C305-1B27-4D41-B690-7A61172D2FEB}
            Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
            Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - FRA-->MsiExec.exe /I{3F7924B9-D148-3141-87B1-68F36043A940}
            Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
            Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - FRA-->MsiExec.exe /I{511DF669-2930-30C0-8EB6-552887E29EC8}
            Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
            Microsoft .NET Framework 3.5 Language Pack - fra-->MsiExec.exe /I{5B76AEA2-D4E5-3B55-B965-ACC36AE0EAFC}
            Microsoft .NET Framework 3.5-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\setup.exe
            Microsoft .NET Framework 3.5-->MsiExec.exe /I{2FC099BD-AC9B-33EB-809C-D332E1B27C40}
            Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
            Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
            mIRC-->C:\Program Files\mIRC\uninstall.exe _?=C:\Program Files\mIRC
            Module linguistique Microsoft .NET Framework 3.5 - fra-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack - fra\setup.exe
            Mozilla Firefox (3.0.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
            MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
            Nero 8 Ultra Edition HD-->MsiExec.exe /X{D6C9AF27-9414-46C8-B9D8-D878BA041036}
            neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
            No-IP.com DUC (remove only)-->"C:\Program Files\No-IP\DUC20.exe" -uninstall
            Pack Vista Inspirat 2 1.0-->C:\WINDOWS\BricoPacks\Vista Inspirat 2\Remove.exe
            PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
            PhotoFiltre Studio-->"C:\Program Files\PhotoFiltre Studio\Uninst.exe"
            QuickTime-->MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
            REALTEK GbE & FE Ethernet PCI-E NIC Driver-->"C:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe" -runfromtemp -l0x040c -removeonly
            Realtek High Definition Audio Driver-->RtlUpd.exe -r -m -nrg2709
            Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
            SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
            TeamSpeak Client-->"C:\Program Files\TeamSpeak3\unins000.exe"
            TrackMania Nations Forever-->"C:\Program Files\Steam\steam.exe" steam://uninstall/11020
            VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
            VDownloader 0.77-->"C:\Program Files\VDOWNLOADER\unins000.exe"
            VLC media player 0.9.2-->C:\Program Files\VideoLAN\VLC\uninstall.exe
            Wallpachange-->C:\Program Files\Wallpachange\Uninstal.exe
            WampServer 2.0-->"c:\wamp\unins000.exe"
            Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
            Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
            Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
            Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
            Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
            Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
            WinHTTrack Website Copier 3.43-2-->"C:\Program Files\WinHTTrack\unins000.exe"
            XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
            Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE

            =====HijackThis Backups=====

            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?SearchSource=10&ctid=CT2102473
            O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
            O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
            R3 - URLSearchHook: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHPN.dll
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.fr/?gws_rd=ssl
            O3 - Toolbar: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHPN.dll
            O2 - BHO: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHPN.dll
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 91.121.112.151:3128
            O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
            O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
            O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 193.55.112.41:3128
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.files-ftp.com/~unicorni/phpBB2/index.php
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
            O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
            O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
            O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
            O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O4 - HKCU\..\Run: [DoNaut] "C:\Program Files\Xponaut\DoNaut\DoNaut.exe" --minimized
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 193.55.112.41:3128
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
            O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
            O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.32\bin\mysqld.exe
            O23 - Service: CSIScanner - Prevx - C:\Program Files\Prevx\prevx.exe
            O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\MaG\reader_s.exe (User 'SYSTEM')
            O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
            O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
            O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
            O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
            O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

            ======Hosts File======

            127.0.0.1 jL.chura.pl

            ======Security center information======

            AV: AVG Anti-Virus
            AV: avast! antivirus 4.8.1335 [VPS 090312-0] (disabled)

            ======Environment variables======

            "ComSpec"=%SystemRoot%\system32\cmd.exe
            "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
            "windir"=%SystemRoot%
            "FP_NO_HOST_CHECK"=NO
            "OS"=Windows_NT
            "PROCESSOR_ARCHITECTURE"=x86
            "PROCESSOR_LEVEL"=6
            "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 2, GenuineIntel
            "PROCESSOR_REVISION"=0f02
            "NUMBER_OF_PROCESSORS"=2
            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
            "TEMP"=%SystemRoot%\TEMP
            "TMP"=%SystemRoot%\TEMP
            "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
            "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

            -----------------EOF-----------------

            Log.txt =
            Logfile of random's system information tool 1.05 (written by random/random)
            Run by MaG at 2009-03-13 11:54:52
            Microsoft Windows XP Professionnel Service Pack 2
            System drive C: has 39 GB (65%) free of 60 GB
            Total RAM: 1012 MB (51% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 11:54:54, on 13/03/2009
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\PROGRA~1\AVG\AVG8\avgemc.exe
            C:\PROGRA~1\AVG\AVG8\avgrsx.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\AVG\AVG8\avgcsrvx.exe
            C:\WINDOWS\system32\wbem\wmiapsrv.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\svchost.exe
            C:\PROGRA~1\AVG\AVG8\avgtray.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\WINDOWS\system32\Restore\rstrui.exe
            C:\Program Files\AVG\AVG8\avgscanx.exe
            C:\Program Files\AVG\AVG8\avgcsrvx.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Documents and Settings\MaG\Bureau\RSIT.exe
            C:\Program Files\Trend Micro\HijackThis\MaG.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\windres.exe,userinit.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\undname.exe,C:\WINDOWS\system32\ndetect.exe,
            O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
            O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
            O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
            O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
            O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
            O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
            0
            1. Contributeur sécurité
              bon,y a du taf en vue

              et ton rapport n'est pas complet

              Télécharge SDfix (créé par AndyManchesta) et sauvegarde le sur ton Bureau. Tu peux suivre le tutorial SDFix de Malekal pour t'aider :

              Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
              Redémarre ton ordinateur
              Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
              A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
              Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
              Choisis ton compte.

              Déroule la liste des instructions ci-dessous :
              Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
              Appuie sur Y pour commencer le nettoyage.

              Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
              Appuie sur une touche pour redémarrer le PC.
              Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
              Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.

              Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
              Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
              Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !

              Si SDFix ne se lance pas
              Clique sur Démarrer > Exécuter
              Copie/colle ceci :
              %systemroot%\system32\cmd.exe /K %systemdrive%\SDFix\apps\FixPath.exe

              Clique sur Ok.
              Redémarre et essaie de relance SDFix.

              ensuite

              Télécharge SmitFraudfix de S!Ri, balltrap34 et moe31
              http://siri.urz.free.fr/Fix/SmitfraudFix.zip -
              en cas de problème avec le premier lien,
              mirroir: http://72.232.135.12/siri/SmitfraudFix.php

              voila à quoi cela ressemble : http://siri.urz.free.fr/Fix/SmitfraudFix.php
              une aide en vidéo (merci à balltrap34)
              http://pagesperso-orange.fr/rginformatique/section%20virus/smitfraudfix.htm

              Désactive les logiciels de protections(antivirus et antispyware)
              -- Fais un clic droit puis Extraire tout sur le fichier SmitfraudFix.zip, cela va tout décompresser dans un nouveau dossier SmitFraudfix
              -- Ouvre le dossier SmitfraudFix double-clique sur SmitfraudFix.cmd (le .cmd peut ne pas être présent)
              -- Choisis l'option 1 et appuie sur Entrée
              -- Réponds o (Oui) aux deux questions suivantes si elles sont posées
              -- Un rapport sera généré; sauvegarde le dans un dossier.
              -- Copie/colle le contenu du rapport ici
              0
              1. Report.txt[b]SDFix: Version 1.240 [/b]
                Run by MaG on 13/03/2009 at 12:16

                Microsoft Windows XP [version 5.1.2600]
                Running From: C:\SDFix

                [b]Checking Services [/b]:

                [b]Name [/b]:
                restore

                [b]Path [/b]:
                \??\C:\WINDOWS\system32\drivers\restore.sys

                restore - Deleted

                Restoring Default Security Values
                Restoring Default Hosts File

                Rebooting

                [b]Checking Files [/b]:

                Trojan Files Found:

                C:\WINDOWS\system32\3.tmp - Deleted
                C:\WINDOWS\system32\4.tmp - Deleted
                C:\WINDOWS\system32\5.tmp - Deleted
                C:\WINDOWS\system32\6.tmp - Deleted
                C:\WINDOWS\system32\7.tmp - Deleted
                C:\WINDOWS\system32\8.tmp - Deleted
                C:\WINDOWS\system32\9.tmp - Deleted
                C:\WINDOWS\system32\A.tmp - Deleted
                C:\WINDOWS\system32\B.tmp - Deleted
                C:\WINDOWS\system32\C.tmp - Deleted
                C:\WINDOWS\system32\D.tmp - Deleted
                C:\WINDOWS\system32\E.tmp - Deleted
                C:\WINDOWS\system32\F.tmp - Deleted
                C:\WINDOWS\system32\10.tmp - Deleted
                C:\WINDOWS\system32\11.tmp - Deleted
                C:\WINDOWS\system32\12.tmp - Deleted
                C:\WINDOWS\services.exe - Deleted

                Removing Temp Files

                [b]ADS Check [/b]:

                [b]Final Check [/b]:

                catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2009-03-13 13:37:42
                Windows 5.1.2600 Service Pack 2 NTFS

                detected NTDLL code modification:
                ZwOpenFile

                scanning hidden processes ...

                scanning hidden services & system hive ...

                scanning hidden registry entries ...

                scanning hidden files ...

                scan completed successfully
                hidden processes: 0
                hidden services: 0
                hidden files: 0

                [b]Remaining Services [/b]:

                Authorized Application Key Export:

                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
                "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                "\\??\\C:\\WINDOWS\\system32\\winlogon.exe"="\\??\\C:\\WINDOWS\\system32\\winlogon.exe:*:enabled:@shell32.dll,-1"

                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

                [b]Remaining Files [/b]:

                File Backups: - C:\SDFix\backups\backups.zip

                [b]Files with Hidden Attributes [/b]:

                Thu 26 Feb 2009 1,386 ...H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\Colored Flash\colored_flashbangs.sma.bak"
                Thu 26 Feb 2009 4,302 ...H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\Country Plugin\GHW_connect.sma.bak"
                Wed 25 Feb 2009 4,033 ...H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\Fire in The Holl Color\descriptive_fire_in_the_hole.sma.bak"
                Wed 11 Mar 2009 1,768 ...H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\Radio\shamusi_music_plugin.sma.bak"
                Wed 11 Mar 2009 2,743 ...H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\SpecT List\speclist.sma.bak"
                Wed 4 Mar 2009 3,767 A..H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\Unstuckin\stuck.sma.bak"
                Wed 25 Feb 2009 11,984 A..H. --- "C:\Documents and Settings\MaG\Bureau\Plugins\Hats Plugin\Hats08.sma.bak"

                [b]Finished![/b]
                0
                1. <gras>rapport.txt (Smitfraudfix)</gras>

                  SmitFraudFix v2.403

                  Rapport fait à 13:44:04,67, 13/03/2009
                  Executé à partir de C:\Documents and Settings\MaG\Bureau\SmitfraudFix\SmitfraudFix
                  OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                  Le type du système de fichiers est NTFS
                  Fix executé en mode normal

                  »»»»»»»»»»»»»»»»»»»»»»»» Process

                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  C:\PROGRA~1\AVG\AVG8\avgemc.exe
                  C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                  C:\Program Files\AVG\AVG8\avgcsrvx.exe
                  C:\WINDOWS\system32\wscntfy.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\AVG\AVG8\avgscanx.exe
                  C:\Program Files\AVG\AVG8\avgcsrvx.exe
                  C:\WINDOWS\system32\notepad.exe
                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                  C:\WINDOWS\system32\cmd.exe

                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\MaG

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MaG\LOCALS~1\Temp

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\MaG\Application Data

                  »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MaG\Favoris

                  »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                  »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                  »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                  "Source"="About:Home"
                  "SubscribedURL"="About:Home"
                  "FriendlyName"="Ma page d'accueil"

                  »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  o4Patch
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  Agent.OMZ.Fix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                  "AppInit_DLLs"=""
                  "LoadAppInit_DLLs"=dword:00000001

                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                  "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,C:\\WINDOWS\\system32\\windres.exe,userinit.exe,C:\\WINDOWS\\system32\\deviceemulator.exe,C:\\WINDOWS\\system32\\undname.exe,C:\\WINDOWS\\system32\\ndetect.exe,C:\\WINDOWS\\system32\\codeblocks.exe,"
                  "System"=""

                  »»»»»»»»»»»»»»»»»»»»»»»» RK

                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                  Description: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC - Miniport d'ordonnancement de paquets
                  DNS Server Search Order: 192.168.2.1

                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                  HKLM\SYSTEM\CS1\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                  HKLM\SYSTEM\CS2\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                  HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                  HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                  HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Fin
                  0
                  1. Contributeur sécurité
                    Redémarre l'ordinateur en mode sans échec .
                    Comment aller en Mode sans échec
                    1) Redémarre ton ordi
                    2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                    3) Tu verras un écran avec options de démarrage apparaître
                    4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                    5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
                    ( ps : n'oublies pas , en mode sans échec , pas de connexion ! Donc copie ou imprime bien les infos ci-dessous ...)

                    *Double click sur SmitfraudFix.exe

                    * Sélectionnes 2 et presses "Entrée" dans le menu pour supprimer les fichiers responsables de l'infection.

                    * A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et presse Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection.

                    ( Le correctif déterminera si le fichier wininet.dll est infecté.)

                    * A la question: "Corriger le fichier infecté ?" répondre O (oui) et presser Entrée
                    pour remplacer le fichier corrompu.

                    * Un redémarrage sera peut être nécessaire pour terminer la procédure de nettoyage ( sinon fais le manuellement )

                    Le rapport se trouve à la racine de C\:
                    (dans le fichier "rapport.txt")

                    Poste ce dernier rapport accompagné, dans la même réponse, d'un nouveau rapport hijackthis ( fais en mode normal )
                    0
                    1. SmitFraudFix v2.403

                      Rapport fait à 14:02:25,12, 13/03/2009
                      Executé à partir de C:\Documents and Settings\MaG\Bureau\Anti-Virus\SmitfraudFix
                      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                      Le type du système de fichiers est NTFS
                      Fix executé en mode sans echec

                      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                      »»»»»»»»»»»»»»»»»»»»»»»» hosts

                      127.0.0.1 jL.chura.pl
                      127.0.0.1 localhost

                      »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                      VACFix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                      S!Ri's WS2Fix: LSP not Found.

                      »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                      GenericRenosFix by S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                      IEDFix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

                      Agent.OMZ.Fix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                      404Fix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» RK

                      »»»»»»»»»»»»»»»»»»»»»»»» DNS

                      HKLM\SYSTEM\CCS\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                      HKLM\SYSTEM\CS1\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                      HKLM\SYSTEM\CS2\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

                      »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                      "System"=""

                      »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                      Nettoyage terminé.

                      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      »»»»»»»»»»»»»»»»»»»»»»»» Fin

                      Hijackthis.log

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 14:13:33, on 13/03/2009
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                      C:\PROGRA~1\AVG\AVG8\avgemc.exe
                      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                      C:\Program Files\AVG\AVG8\avgcsrvx.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\wscntfy.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Program Files\AVG\AVG8\avgscanx.exe
                      C:\Program Files\AVG\AVG8\avgcsrvx.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\windres.exe,userinit.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\undname.exe,C:\WINDOWS\system32\ndetect.exe,C:\WINDOWS\system32\codeblocks.exe,C:\WINDOWS\system32\c++.exe,
                      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                      O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
                      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                      O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
                      O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                      O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                      0
                      1. Contributeur sécurité
                        mmmm!

                        poste moi un nouveau rapport rsit stp

                        uniquement log.txt
                        0
                        1. Logfile of random's system information tool 1.05 (written by random/random)
                          Run by MaG at 2009-03-13 14:40:49
                          Microsoft Windows XP Professionnel Service Pack 2
                          System drive C: has 44 GB (73%) free of 60 GB
                          Total RAM: 1012 MB (40% free)

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 14:41:15, on 13/03/2009
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                          C:\PROGRA~1\AVG\AVG8\avgemc.exe
                          C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                          C:\Program Files\AVG\AVG8\avgcsrvx.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\wscntfy.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\AVG\AVG8\avgscanx.exe
                          C:\Program Files\AVG\AVG8\avgcsrvx.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\Program Files\uTorrent\uTorrent.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Documents and Settings\MaG\Bureau\Anti-Virus\RSIT.exe
                          C:\Program Files\Trend Micro\HijackThis\MaG.exe
                          C:\Program Files\Internet Download Manager\IDMan.exe

                          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\windres.exe,userinit.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\undname.exe,C:\WINDOWS\system32\ndetect.exe,C:\WINDOWS\system32\codeblocks.exe,C:\WINDOWS\system32\c++.exe,
                          O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                          O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
                          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\eMule.exe -AutoStart
                          O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
                          O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                          O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
                          O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                          O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                          0
                          1. Contributeur sécurité
                            bon,

                            tes dans le caca...

                            ---- C:\WINDOWS\system32\reader_s.exe c'est du virut

                            avant de continuer ta désinfection,tu dois impérativement faire un scan en ligne pour voir si ton OS est touché!

                            virut est un virus polymorphe;n'ouvre plus aucun fichier .exe il serait inmanquablement contaminé

                            **désactive ton antivirus, logiciels de protections et logiciels pouvant bloquer les popups (barres Google, barres Yahoo etc..).**

                            Ouvre internet explorer --> Outils --> Options internet --> onglet "sécurité" --> Valide "niveau par défaut".
                            Toujours sur Internet explorer --> Outils --> Options internet --> onglet "avancé" --> valide "Paramètres par défaut".

                            Scan en ligne avec Kaspersky :
                            - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr en utilisant Internet Explorer et pas Firefox, ça ne marchera pas!.
                            - Si tu es perdu, tu peux suivre l'aide pour les scans en ligne https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId291566

                            AIDE : Configurer le contrôle des ActiveX < http://www.inoculer.com/activex.php3 >
                            Tuto ici si problème : http://www.vista-xp.fr/forum/topic109.html , ou là : https://forum.pcastuces.com/sujet.asp?f=25&s=37641 (par Morgane & nico_dodo)

                            - Au moment de choisir la cible à analyser, clique sur le bouton Paramètres d'analyse
                            - Dans la nouvelle fenêtre, coche "étendu" au milieu puis clique sur OK.
                            - Choisis le poste de travail dans la cible à analyser
                            - Copie/colle le rapport du scan ici

                            NOTE : Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner,
                            reconnecte-toi sur le site de Kaspersky pour retenter le scan en ligne.

                            ensuite

                            Va par le panneau de configuration dans Options d'alimentation et mets "jamais" partout; le pc ne DOIT pas se mettre en veille.

                            Télécharge le dernier AVP de la liste ( en bas): ftp://ftp.kaspersky.com/devbuilds/AVPTool/ Enregistre-le sur le bureau.

                            Tu ne vas pas devoir le surveiller, tu n'as qu'à choisir "Disinfect" et " apply to all" et l'outil poursuivra son travail tout seul pendant que tu dormiras.

                            Ne coche surtout pas la case DELETE!!!

                            Le scan est plus ou moins long selon la puissance des pc et du nombre de fichiers à analyser.

                            Le rapport étant très lourd, tu ne devras poster que le début qui parle des découvertes et traitements effectués.

                            Si tu avais un problème avec ce rapport, sauvegarde-le quel que soit son poids, je te donnerai un lien pour l'héberger.

                            SCANNER AVEC AVP TOOL

                            Le scan va s'effectuer en Mode Sans Echec: comme tu n'auras pas accès à Internet, je te conseille d'imprimer cette procédure.
                            Télécharge et enregistre sur ton Bureau le scanner portable AVP TOOL (sélectionne-la à partir des dates) en cliquant sur le lien:
                            http://downloads5.kaspersky-labs.com/devbuilds/AVPTool/

                            Redémarre en mode sans échec, pour cela, redémarre l'ordinateur, avant le logo Windows, tapote sur la touche F8, un menu va apparaître,
                            choisis Mode sans échec et appuye sur la touche entrée du clavier.

                            Choisis ton compte.
                            Connecte éventuellement tes clés USB et disques externes.

                            Lance l'exécutable intitulé "setup_7.0xxxxx" en double-cliquant dessus
                            Réponds "Oui" à la question "Do you want to continue installation?"
                            Clique sur "Next" pour les deux fenêtres suivantes: AVP TOOL s'installe sur ton Bureau dans un dossier nommé "Kaspersky Lab Tool"
                            Si nécessaire, branche tes périphériques amovibles (clés USB, disque dur externe...)
                            L'outil se lance tout seul: coche toutes les cases dans l'onglet "Automatic Scan".
                            Clique maintenant sur "Security Level": une fenêtre de configuration s'ouvre: paramètre le scanner comme ceci:

                            Dans "security level" laisse le curseur sur "Recommended"

                            Dans "Action"
                            coche "Prompt for action when the scan is complète"
                            coche "Disinfect" et "Delete if disinfection fails"

                            Dans "Self-defense options"
                            coche "Disable external service control"

                            Valide avec "Apply" puis "OK"
                            L'outil est maintenant configuré: dans la fenêtre principale, clique sur "Scan".
                            Le scan commence, une nouvelle fenêtre s'ouvre indiquant la progression du balayage en pourcentage.
                            A la fin du scan, AVP Tool signale les objets infectés par l'intermédiaire d'une pop-up: coche alors "Apply to all" et clique sur "Delete" ou "Disinfect" selon ce que propose la fenêtre:

                            Une fois les infections traitées par l'intermédiaire des pop-ups, il se peut que des fichiers malsains n'aient pas été supprimés: ils apparaissent en rouge dans la liste: clique alors sur le bouton "Neutralize all" de la fenêtre de progression du scan: si une pop-up indique qu'il faut redémarrer, accepte en cliquant sur "OK"
                            Rends-toi maintenant dans l'onglet "Events" de la fenêtre de progression du scan, et décoche "Show all events"
                            Clique enfin sur "Reports" puis "Save to file" et enregistre le rapport sur ton Bureau sous le nom Rapport AVP TOOL
                            Ferme les fenêtres d'AVP Tool: un message apparaît proposant de désinstaller le logiciel: choisis "YES"

                            Un message d'alerte indique que le PC doit être redémarré pour finir la désinstallation:

                            A la question "Would you like to restart now", répond "OUI" et redémarre ton ordinateur en Mode normal.
                            Poste le contenu du rapport dans ta prochaine réponse

                            Un conseil: désinfecte ce qui peut l'être, sinon "Delete".
                            NB: l'outil doit être désinstallé quand il le demandera car il ne peut pas rester sur l'ordi; il causerait des conflits.
                            0
                            1. Merci pour ta méthode mon Pc est Clean maintenant :)
                              0
                              1. Contributeur sécurité
                                ah bin tant mieux,mais poste les rapports quand même,cette crasse de virut est vachement tenace...
                                0
                                1. J'ai fini kan meme par reformater mon PC, psk la vrm tt les logiciels sont désinfécter et donc ils marchent plus :S
                                  Mais jte demande aprés ke j'ai formater kel Antivirus Gratuit prendre ?
                                  0
                                  1. Merci pour ton aide Chimay. +1 :)
                                    0