PC infecté

Résolu
Bonjour tous le monde
pouvez-vous m'aider SVP
je n'arrive pas à suprimé c'est virus:

Win32:Tiny-IF [Trj]
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\5FNO27VF\lkjh[1]

Win32:Agent-LAP [Trj]
C:\DOCUME~1\user\LOCALS~1\Temp\dscppjmk.exe

Win32:Vundo-gen49 [Adw]
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\NXSQNGFB\jaun_20070726[1]

Win32:Vundo-gen49 [Adw]
C:\DOCUME~1\user\LOCALS~1\Temp\aypkgcki.dll
MERCI
Configuration: HP PAVILION zd 8020 Windows XP SP2
Internet Explorer 7.0

43 réponses

Résumé de la discussion

Plusieurs malwares, notamment Win32:Tiny-IF, Win32:Agent-LAP et Win32:Vundo-gen49, compromettent des fichiers temporaires et des composants Internet Explorer 7 sur Windows XP SP2, rendant la suppression délicate. Les solutions proposées reposent sur VundoFix avec l’ajout manuel de fichiers infectés (ddayy.dll, efcdaww.dll, antycjno.exe), puis l’arrêt et la désactivation du service DomainService et l’analyse via HijackThis. D'autres recommandations évoquent OTMoveIt et VirtumundoBeGone, puis des rapports à poster (VundoFix, HijackThis), la désactivation temporaire d'un antivirus lors d'un scan en ligne, et le redémarrage si nécessaire. En cas de redémarrage, les étapes incluent la vérification des éléments détectés (services, BHO, Winlogon Notify), la suppression des fichiers restants et la vérification finale avec un scan en ligne.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    1/télécharge et installe le logiciel HijackThis
    http://pchelpbordeaux.free.fr/logiciels.html
    tuto pour l’utiliser
    regarde ici c'est parfaitement expliqué en images
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

    2/télécharge AVG Antispyware
    https://www.avg.com/en-ww/free-antivirus-download

    mode d'utilisation :
    Lance AVG Anti-Spyware, mets le à jour,
    Clique sur le bouton « Analyse » onglet « paramètres »
    Puis « Comment réagir », clique sur Actions recommandées. Sélectionne Quarantaine.

    3/ Télécharge : - CCleaner
    https://www.pcastuces.com/logitheque/ccleaner.htm
    ("Download Latest Version", sur la droite).
    Ce logiciel va permettre de supprimer tous les fichiers temporaires. Avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires". Ensuite, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. C'est tout.
    Un tuto
    http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

    4/ lance ccleaner , nettoyeur, et supprime tout ce qu'il trouve
    lance ccleaner, erreurs, et répare ce qu’il trouve. Accepte les sauvegardes !

    5/ lance avg antispyware
    Retour à l'onglet Analyse.
    Clique sur Analyse complète du système.
    A la fin du scan, choisis " Appliquer toutes les actions "
    Clique sur "Enregistrer le rapport". Le fichier texte se trouve dans le dossier Rapports du dossier d'AVG Anti-Spyware

    6/ lance hijack this et poste le rapport

    et tu feras aussi ceci
    Télécharge VundoFix.exe (par Atribune) sur ton Bureau
    http://www.atribune.org/ccount/click.php?id=4
    clic double sur VundoFix.exe afin de le lancer
    clic sur le bouton Scan for Vundo
    Lorsque le scan est complété, clic sur le bouton Remove Vundo
    Une invite te demandera si tu veux supprimer les fichiers, clic YES
    Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers
    Tu verras une invite qui t'annonce que ton PC va redémarrer;
    clic OK
    Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clic sur le bouton Scan for Vundo".
    Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis dans ta prochaine réponse

    poste les rapports demandés
    AVG antispyware
    Vundofix.txt
    Hijack this
    0
    1. voici les rapport demandés:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 20:38:06, on 28/09/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16512)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\MsPMSPSv.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {095B5BB4-7C75-4100-91B6-ACA7A96E7C29} - C:\WINDOWS\system32\awtsp.dll (file missing)
      O2 - BHO: (no name) - {3E5E3B10-EF94-4735-8DE7-4FA636F4B08C} - C:\WINDOWS\system32\ddayy.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\eoRezo\EoAdv\EoRezobho.dll (file missing)
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O2 - BHO: (no name) - {7A01BE58-AFDF-4D30-A599-EA0FB8CF2193} - C:\WINDOWS\system32\awtqp.dll (file missing)
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: (no name) - {A3624CF3-54E1-4FD0-88EF-F9BDF3979F3A} - C:\WINDOWS\system32\efcdaww.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O20 - Winlogon Notify: awtqp - C:\WINDOWS\system32\awtqp.dll (file missing)
      O20 - Winlogon Notify: efcdaww - C:\WINDOWS\SYSTEM32\efcdaww.dll
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\antycjno.exe (file missing)
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
      O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
      O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
      O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
      0
      1. bonjour papyber
        que faire maintenant svp?
        0
        1. Contributeur sécurité
          du travail a été fait
          vundo est souvent récalcitrant
          il en reste donc tu fais ceci en suivant bien les consignes
          Relance Vundofix
          attention ce n'est pas la même manip

          http://www.atribune.org/ccount/click.php?id=4

          * Ne clique pas sur "Scan for a vundo"
          * Clique droit au milieu de la fenêtre
          * Clique sur Add more files ?
          * Copie/colle les fichiers ci-dessous ( un par case) :

          C:\WINDOWS\system32\ddayy.dll
          C:\WINDOWS\system32\efcdaww.dll
          C:\WINDOWS\system32\antycjno.exe

          * Clique sur Add files
          * Ensuite clique sur Close Windows
          * Enfin, clique sur Remove Vundo ( les fichiers précédents doivent apparaitre dans la fenêtre principale)
          * Si l'outils demande un redémarrage, accepte

          Démarrer "Exécuter…" puis Tape "services.msc"
          et valide par OK
          la fenêtre des Services s'ouvre
          vérifier dans la partie inférieure que l'onglet "Etendu" est bien sélectionné, sinon faites le.

          - Dans la colonne "Nom", DOUBLE CLIQUE sur le service noté en GRAS ci dessous, pour faire apparaître "Propriétés".

          DomainService

          - Vérifie dans "Chemin d'accès des fichiers exécutables" qu'il s'agit bien de l'emplacement souligné.
          C:\WINDOWS\system32\antycjno.exe

          - Puis clique sur Arrêter
          - Dans le menu déroulant "Type de démarrage", sélectionne "Désactivé".
          - valide la modification par OK
          - Ferme la fenêtre des Services.

          lance hijack pour un scan et coche les lignes suivantes si encore présentes
          O2 - BHO: (no name) - {095B5BB4-7C75-4100-91B6-ACA7A96E7C29} - C:\WINDOWS\system32\awtsp.dll (file missing)
          O2 - BHO: (no name) - {3E5E3B10-EF94-4735-8DE7-4FA636F4B08C} - C:\WINDOWS\system32\ddayy.dll
          O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\eoRezo\EoAdv\EoRezobho.dll (file missing)
          O2 - BHO: (no name) - {7A01BE58-AFDF-4D30-A599-EA0FB8CF2193} - C:\WINDOWS\system32\awtqp.dll (file missing)
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: (no name) - {A3624CF3-54E1-4FD0-88EF-F9BDF3979F3A} - C:\WINDOWS\system32\efcdaww.dll
          O20 - Winlogon Notify: awtqp - C:\WINDOWS\system32\awtqp.dll (file missing)
          O20 - Winlogon Notify: efcdaww - C:\WINDOWS\SYSTEM32\efcdaww.dll
          O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\antycjno.exe (file missing)
          ferme toutes tes fenêtres y compris internet et clique sur fixer l'objet
          · Poste le rapport Vundofix, ainsi qu'un nouveau log hijackthis
          0
          1. Bonjour,
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 23:01:51, on 28/09/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16512)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Defender\MsMpEng.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\system32\spoolsv.exe
            c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\MsPMSPSv.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\WINDOWS\system32\mmc.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
            O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\quunlcvj.dll",sitypnow
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
            O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
            O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
            O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
            0
            1. Bonjour,
              merci pour tous
              faut il redémarrer mon pc?
              0
              1. Contributeur sécurité
                il en reste encore !!!on tient le méchant!!!
                j'aimerais bien les rapports de vundofix!!!

                relance le
                Ne clique pas sur "Scan for a vundo"
                * Clique droit au milieu de la fenêtre
                * Clique sur Add more files ?
                * Copie/colle les fichiers ci-dessous ( un par case) :

                C:\WINDOWS\system32\quunlcvj.dll

                * Clique sur Add files
                * Ensuite clique sur Close Windows
                * Enfin, clique sur Remove Vundo ( les fichiers précédents doivent apparaitre dans la fenêtre principale)
                * Si l'outils demande un redémarrage, accepte
                poste un rapport hijack this ainsi que le rapport vundofix
                tu le trouves ici
                C:\vundofic.txt
                à demain pour la suite

                 faut il redémarrer mon pc?

                si l'outil te le demande, oui bien sur

                ton rapport hijack this a bien "maigri", qui t'a fait supprimer toutes ces lignes....
                tu as supprimé ceci, je ne te l'avais pas demandé...une raison particulière?

                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

                .
                0
                1. c'est peut etre 1 erreur de ma part, mais je pensais que ces fichiers n'etaient pas utile oupss!! lol
                  je poste le rapport vundo
                  encore merci pour ts
                  0
                  1. Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 00:19:02, on 29/09/2007
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16512)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Windows Defender\MsMpEng.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\MsPMSPSv.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                    C:\WINDOWS\system32\rundll32.exe
                    C:\WINDOWS\system32\NOTEPAD.EXE
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                    O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
                    O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
                    O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
                    0
                    1. Contributeur sécurité
                      visiblement il y a un problème avec VundoFix, il n'a pas pu tout supprimer
                      on va faire autrement
                      Télécharge combofix.exe (par sUBs) sur ton Bureau
                      http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                      Double clique combofix.exe.
                      Tape sur la touche Y (Yes) pour démarrer le scan.
                      Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse
                      NOTE : Le rapport se trouve également ici : C:\Combofix.txt
                      il me faut absolument le rapport obtenu, car il me permet de voir si l'infection est ou pas enlevée et s'il reste ou pas des fichiers infectés
                      donc
                      rapport combofix
                      et un rapport hijack this après passage de l'outil
                      0
                      1. Bonjour, je double clique combofix et voila ce quil me dit
                        Freeware implementation of REG.EXE a rencontré un problème et doit fermer. Nous vous prions de nous excuser pour le désagrément encouru.
                        0
                        1. bonjour,
                          je n'arrive pas à ouvrir combofix! que faire? svp
                          0
                          1. ça est il c'est lancer!
                            rapport ds le prochain msg
                            0
                            1. Contributeur sécurité
                              supprime le,à ne faire que si combofix ne fonctionne pas

                              Télécharge OTMoveIt (de Old_Timer) sur ton Bureau.
                              http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

                              clic double sur OTMoveIt.exe pour le lancer.
                              copie la liste qui se trouve en citation ci-dessous,
                              et colle-la dans le cadre de gauche de OTMoveIt :
                              Paste List of Files/Folders to be moved.

                              C:\WINDOWS\system32\awtqp.dll
                              C:\WINDOWS\system32\cjxpucyo.dll
                              C:\WINDOWS\system32\efcdaww.dll
                              C:\WINDOWS\system32\oycupxjc.ini
                              C:\WINDOWS\system32\ddayy.dll
                              C:\WINDOWS\system32\jkceboos.ini
                              C:\WINDOWS\system32\soobeckj.dll
                              C:\WINDOWS\system32\usxryimp.dll
                              C:\WINDOWS\system32\quunlcvj.dll
                              C:\WINDOWS\system32\antycjno.exe

                              clique sur MoveIt! pour lancer la suppression.
                              le résultat apparaîtra dans le cadre Results.
                              clique sur Exit pour fermer.
                              poste le rapport situé dans C:\\\_OTMoveIt\MovedFiles.

                              il te sera peut-être demandé de redémarrer le pc pour achever la suppression.
                              si c'est le cas accepte par Yes.

                              fais un scan en ligne ici et poste le rapport obtenu
                              https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                              0
                              1. Bonjour,
                                combofix c'est arreter a l'étape 25 avec la meme erreur que précédemment:
                                Freeware implementation of REG.EXE a rencontré un problème et doit fermer. Nous vous prions de nous excuser pour le désagrément encouru.
                                0
                                1. Contributeur sécurité
                                  supprime Combofix
                                  fais la manip avec OTMoveIT et poste le rapport que je vois si les fichiers ont été trouvés puis éradiqués
                                  0
                                  1. Bonjour,
                                    rapport OTMoveIt:

                                    File/Folder C:\WINDOWS\system32\awtqp.dll not found.
                                    LoadLibrary failed for C:\WINDOWS\system32\cjxpucyo.dll
                                    C:\WINDOWS\system32\cjxpucyo.dll NOT unregistered.
                                    C:\WINDOWS\system32\cjxpucyo.dll moved successfully.
                                    DllUnregisterServer procedure not found in C:\WINDOWS\system32\efcdaww.dll
                                    C:\WINDOWS\system32\efcdaww.dll NOT unregistered.
                                    File move failed. C:\WINDOWS\system32\efcdaww.dll scheduled to be moved on reboot.
                                    C:\WINDOWS\system32\oycupxjc.ini moved successfully.
                                    LoadLibrary failed for C:\WINDOWS\system32\ddayy.dll
                                    C:\WINDOWS\system32\ddayy.dll NOT unregistered.
                                    C:\WINDOWS\system32\ddayy.dll moved successfully.
                                    File/Folder C:\WINDOWS\system32\jkceboos.ini not found.
                                    File/Folder C:\WINDOWS\system32\soobeckj.dll not found.
                                    File/Folder C:\WINDOWS\system32\usxryimp.dll not found.
                                    File/Folder C:\WINDOWS\system32\quunlcvj.dll not found.
                                    File/Folder C:\WINDOWS\system32\antycjno.exe not found.

                                    Created on 09-29-2007 12:50:21

                                    KASPERSKY ON-LINE SCANNER REPORT
                                    Saturday, September 29, 2007 1:52:40 PM
                                    Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
                                    Kaspersky On-line Scanner version : 5.0.83.0
                                    Dernière mise à jour de la base antivirus Kaspersky : 29/09/2007
                                    Enregistrements dans la base antivirus Kaspersky : 399253

                                    Paramètres d'analyse
                                    Analyser avec la base antivirus suivante standard
                                    Analyser les archives vrai
                                    Analyser les bases de messagerie vrai

                                    Cible de l'analyse Zones critiques
                                    C:\WINDOWS
                                    C:\DOCUME~1\user\LOCALS~1\Temp\

                                    Statistiques de l'analyse
                                    Total d'objets analysés 18952
                                    Nombre de virus trouvés 2
                                    Nombre d'objets infectés 8 / 0
                                    Nombre d'objets suspects 0
                                    Durée de l'analyse 00:17:31

                                    Nom de l'objet infecté Nom du virus Dernière action
                                    C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré

                                    C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré

                                    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré

                                    C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\config\Antivirus.Evt L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\config\default L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\config\ODiag.evt L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\config\OSession.evt L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\config\software L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\config\system L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\ljyxvxla.exe Infecté : Trojan.Win32.Agent.bck ignoré

                                    C:\WINDOWS\system32\mynoxhkf.exe Infecté : Trojan.Win32.Agent.bck ignoré

                                    C:\WINDOWS\system32\roawsaiq.exe Infecté : Trojan-Downloader.Win32.Tiny.id ignoré

                                    C:\WINDOWS\system32\sqylqtiy.exe Infecté : Trojan.Win32.Agent.bck ignoré

                                    C:\WINDOWS\system32\tqdxoflw.exe Infecté : Trojan.Win32.Agent.bck ignoré

                                    C:\WINDOWS\system32\unxxpuhc.exe Infecté : Trojan.Win32.Agent.bck ignoré

                                    C:\WINDOWS\system32\vfvpxmik.exe Infecté : Trojan.Win32.Agent.bck ignoré

                                    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré

                                    C:\WINDOWS\system32\wsrbsdnu.exe Infecté : Trojan.Win32.Agent.bck ignoré

                                    C:\WINDOWS\Temp\Perflib_Perfdata_62c.dat L'objet est verrouillé ignoré

                                    C:\WINDOWS\Temp\_avast4_\Webshlock.txt L'objet est verrouillé ignoré

                                    C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré

                                    C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré

                                    C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré

                                    C:\DOCUME~1\user\LOCALS~1\Temp\~DFF7DE.tmp L'objet est verrouillé ignoré

                                    C:\DOCUME~1\user\LOCALS~1\Temp\~DFF821.tmp L'objet est verrouillé ignoré

                                    C:\DOCUME~1\user\LOCALS~1\Temp\~DFFA8.tmp L'objet est verrouillé ignoré

                                    C:\DOCUME~1\user\LOCALS~1\Temp\~DFFB8.tmp L'objet est verrouillé ignoré

                                    Analyse terminée.

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 13:59, on 2007-09-29
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v7.00 (7.00.6000.16512)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\Ati2evxx.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\Program Files\Windows Defender\MsMpEng.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\MsPMSPSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    C:\WINDOWS\system32\Ati2evxx.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                    C:\Program Files\MSN Messenger\msnmsgr.exe
                                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                    O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\ychjsxpn.dll",sitypnow
                                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
                                    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
                                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
                                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                                    O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
                                    O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
                                    O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
                                    0
                                    1. Contributeur sécurité
                                      relance OTMoveIT
                                      copie la liste qui se trouve en citation ci-dessous,
                                      et colle-la dans le cadre de gauche de OTMoveIt :
                                      Paste List of Files/Folders to be moved.

                                      C:\WINDOWS\system32\ljyxvxla.exe
                                      C:\WINDOWS\system32\mynoxhkf.exe
                                      C:\WINDOWS\system32\roawsaiq.exe
                                      C:\WINDOWS\system32\sqylqtiy.exe
                                      C:\WINDOWS\system32\tqdxoflw.exe
                                      C:\WINDOWS\system32\unxxpuhc.exe
                                      C:\WINDOWS\system32\vfvpxmik.exe
                                      C:\WINDOWS\system32\wsrbsdnu.exe
                                      C:\WINDOWS\system32\ychjsxpn.dll

                                      clique sur MoveIt! pour lancer la suppression.
                                      le résultat apparaîtra dans le cadre Results.
                                      clique sur Exit pour fermer.
                                      poste le rapport situé dans C:\\\_OTMoveIt\MovedFiles.

                                      il te sera peut-être demandé de redémarrer le pc pour achever la suppression.
                                      si c'est le cas accepte par Yes.

                                      fais un scan en ligne ici et poste le rapport obtenu
                                      http://pandasoftware.fr
                                      si ton antivirus réagit, désactive le le temps du scan, et réactive le dès que le scan est terminé
                                      0
                                      1. Bonjour,
                                        C:\WINDOWS\system32\ljyxvxla.exe moved successfully.
                                        C:\WINDOWS\system32\mynoxhkf.exe moved successfully.
                                        C:\WINDOWS\system32\roawsaiq.exe moved successfully.
                                        C:\WINDOWS\system32\sqylqtiy.exe moved successfully.
                                        C:\WINDOWS\system32\tqdxoflw.exe moved successfully.
                                        C:\WINDOWS\system32\unxxpuhc.exe moved successfully.
                                        C:\WINDOWS\system32\vfvpxmik.exe moved successfully.
                                        C:\WINDOWS\system32\wsrbsdnu.exe moved successfully.
                                        LoadLibrary failed for C:\WINDOWS\system32\ychjsxpn.dll
                                        C:\WINDOWS\system32\ychjsxpn.dll NOT unregistered.
                                        C:\WINDOWS\system32\ychjsxpn.dll moved successfully.

                                        Created on 09-29-2007 14:29:52

                                        This action will cancel the scan
                                        Are you sure you want to cancel the scan?

                                        Generate results report...Español | English Sign in | Sign up | My account | Sign out Home| What is TotalScan?| We love feedback!| FAQ
                                        Quick scan: Searching for malicious software
                                        Scanning
                                        Searching 2,271,787 viruses, spyware, Trojans and other threats. It also uses heuristic technologies to detect unknown viruses.

                                        100%

                                        Item in progress:
                                        Items scanned:
                                        0

                                        Items with viruses, spyware, Trojans... detected:
                                        0

                                        Suspicious files detected:
                                        0

                                        Results
                                        Congratulations!
                                        No viruses, spyware, Trojans, or any other ACTIVE or LATENT threats have been detected on your PC.
                                        We detected that avast! antivirus 4.7.1043 [VPS 000777-2] is enabled and up-to-date.
                                        El texto que corresponda en cada momento
                                        After a quick scan of your PC, we have not detected any ACTIVE or LATENT malicious software.
                                        Become a TotalScan Pro member
                                        Includes disinfection!

                                        < Back to home

                                        Scan details
                                        High danger level (0)

                                        Medium danger level (3)

                                        Low danger level (1)

                                        <<
                                        1
                                        2
                                        3
                                        4
                                        5
                                        >>

                                        Suspicious files (3)

                                        <<
                                        1
                                        2
                                        3
                                        4
                                        5
                                        >>
                                        Recommendations
                                        Disinfect
                                        Send suspicious files to laboratory
                                        Install permanent protection
                                        Enable your permanent protection

                                        Update your permanent protection

                                        How can I do this?

                                        You should periodically carry out a FULL scan of your PC with TotalScan. That way you will reduce the chances of infection.

                                        El % of other users' computers were infected and we have disinfected %
                                        Check the Key features and the minimum requirements
                                        Become a TotalScan member. It's FREE.
                                        Benefits: 1. Customized scan 2. Scan history

                                        Disinfection of this type of threat is
                                        exclusive to TotalScan members Pro.
                                        TotalScan Pro Members

                                        It seems that you have registered previously and your account is still active. You cannot register again with the same account. Enter your account using your e-mail and password. Forgotten your password?

                                        E-mail
                                        Please enter this information

                                        Password
                                        Please enter this information

                                        Repeat password
                                        Please enter this information

                                        Remember e-mail and password

                                        I want to receive the latest news about NanoScan or TotalScan. I would also like to receive information on relevant promotions from Panda Security and/or its international representatives.

                                        * Panda Security will send this information via e-mail or other equivalent form of communication (e.g. SMS).

                                        I do not want to receive any type of information.

                                        Have you forgotten your password?

                                        You have not registered yet? Register now FREE
                                        Still not a member?

                                        Become a TotalScan Pro member and benefit from its maximum detection and disinfection capacity:

                                        Detects over 1,100,000 viruses, spyware, Trojans and other threats.
                                        Continuous updates: over 2,500 new viruses every day.
                                        Includes disinfection.

                                        Buy TotalScan Pro and become a member.

                                        Use of TotalScan is subject to acceptance of the Terms and conditions of use
                                        This is a Panda project
                                        0
                                    2. Bonjour,
                                      c'est pas un virus, mais le diable qui habite mon PC!!!!
                                      0
                                      • 1
                                      • 2
                                      • 3