Cheval de trois

Résolu
Bonjour,

mon pc a chopé un virus detecté par avast CHEVAL DE TROIS depuis mon pc et lourd et aussi j'entend du son en englais souvent d'un documentaire je sais pas eceque ya un raport avec le virus? si quelle qun sais comment s'endebarassé merci de votre aide.
Configuration: Windows XP
Internet Explorer 6.0

35 réponses

Résumé de la discussion

Un utilisateur signale qu'un virus détecté par Avast sur un PC Windows XP rend l'ordinateur lourd et produit des sons en anglais, suspectant une corrélation entre le malware et les symptômes. Des réponses recommandent des démarches de nettoyage et d'analyse avec HijackThis, SmitFraudFix et RSIT, ainsi que la mise à jour d'Internet Explorer pour clarifier l'origine et faciliter le nettoyage. En cas de doute, d'autres outils comme RSIT et SmitFraudFix peuvent être utilisés pour détecter les rootkits et les éléments persistants, avec des actions sur les fichiers et les clés de démarrage. D'autres échanges indiquent que le suivi des rapports et les redémarrages contrôlés font partie du processus, sans annonce formelle de résolution ni conclusion sur l'état du problème.

Bobot (l’IA à votre service)
  1. Modérateur
    Salut,

    - Télécharge HijackThis v2.0.2 sur ton Bureau :
    http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe

    - Double-clique sur HJTInstall afin de lancer l'installation.

    - Clique sur Install ensuite sur I Accept.

    - Clique sur Do a system scan and save a logfile.

    - Le bloc-notes s'ouvrira, fais un copier/coller de tout son contenu ici dans ton prochain message.
    1. bonjour
      merci d'avoir rependu je vais posté le raport.
    2. voila le raport merci de ton aide

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 16:42:48, on 16/10/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
      C:\APPS\Powercinema\PCMService.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\WINDOWS\VM_STI.EXE
      C:\Program Files\DS-3200 Wireless Optical Slimline Deskset\MouseDrv.exe
      C:\Program Files\DS-3200 Wireless Optical Slimline Deskset\PS2USBKbdDrv.exe
      C:\WINDOWS\system32\LVCOMSX.EXE
      C:\Program Files\Logitech\Video\CameraAssistant.exe
      C:\WINDOWS\system32\ElkCtrl.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      C:\Program Files\TomTom HOME\TomTomHOME.exe
      c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
      C:\APPS\SMP\SmpSys.exe
      C:\WINDOWS\system32\ctfmon.exe
      c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
      C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
      C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
      c:\APPS\Powercinema\Kernel\TV\CLSched.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=proxy.club-internet.fr:8080
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
      O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: (no name) - {DDA28099-DACF-415D-A5A8-BB134FCA3D6A} - (no file)
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
      O4 - HKLM\..\Run: [ATICCC] "c:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
      O4 - HKLM\..\Run: [DetectorApp] C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [PCMService] "c:\APPS\Powercinema\PCMService.exe"
      O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
      O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S6.tmp" /EF "HKLM"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
      O4 - HKLM\..\Run: [WireLessMouse] C:\Program Files\DS-3200 Wireless Optical Slimline Deskset\MouseDrv.exe
      O4 - HKLM\..\Run: [WireLessKeyboard] C:\Program Files\DS-3200 Wireless Optical Slimline Deskset\PS2USBKbdDrv.exe
      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
      O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
      O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
      O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
      O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series (Copie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_SD.tmp" /EF "HKLM"
      O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_SEE.tmp" /EF "HKLM"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
      O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
      O4 - HKCU\..\Run: [Instant Access] C:\WINDOWS\system32\mwsrvacc.exe /run
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
      O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
      O4 - HKCU\..\Run: [UpdateWin] C:\WINDOWS\system32\1031t.exe
      O4 - HKCU\..\RunServices: [UpdateWin] C:\WINDOWS\system32\1031t.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
      O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
      O4 - Startup: Présentation de Media Manager.lnk = C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\SPLASHA.EXE
      O4 - Global Startup: Picture Package Menu.lnk = ?
      O4 - Global Startup: Picture Package VCD Maker.lnk = ?
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O21 - SSODL: erpobmsw - {534464D0-0F22-4BB8-B26A-F42A9A09A6F2} - C:\WINDOWS\erpobmsw.dll (file missing)
      O21 - SSODL: adgpfoxs - {623746FA-EB8E-44B8-AB03-8E1DE7A0A983} - C:\WINDOWS\adgpfoxs.dll (file missing)
      O22 - SharedTaskScheduler: IPC Configuration Utility - IPC Configuration Utility - (no file)
      O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
      O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
      O23 - Service: CyberLink Media Library Service - Cyberlink - c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
      O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
    3. merci
  2. Modérateur
    - Télécharge SmitfraudFix (de de S!Ri, balltrap34 et moe31) :
    http://siri.urz.free.fr/Fix/SmitfraudFix.exe ou http://www.geekstogo.com/forum/files/file/6-smitfraudfix/

    - Enregistre-le sur le bureau

    - Double-clique sur SmitfraudFix.exe et choisis l'option 1 puis Entrée

    - Un rapport sera généré, poste-le dans ta prochaine réponse.

    [*] process.exe est détecté par certains antivirus comme étant un risktool. Il ne s'agit pas d'un virus mais d'un utilitaire destiné à mettre fin à des processus.[*]

    ** Ne fais l'étape 2 que si on te le demande, on doit d'abord examiner le premier rapport de SmitfraudFix
    1. voici le 2eme raport merci

      SmitFraudFix v2.362

      Rapport fait à 16:56:40,40, 16/10/2008
      Executé à partir de D:\Documents and Settings\adjiri\Bureau\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode normal

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
      C:\APPS\Powercinema\PCMService.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\WINDOWS\VM_STI.EXE
      C:\Program Files\DS-3200 Wireless Optical Slimline Deskset\MouseDrv.exe
      C:\Program Files\DS-3200 Wireless Optical Slimline Deskset\PS2USBKbdDrv.exe
      C:\WINDOWS\system32\LVCOMSX.EXE
      C:\Program Files\Logitech\Video\CameraAssistant.exe
      C:\WINDOWS\system32\ElkCtrl.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      C:\Program Files\TomTom HOME\TomTomHOME.exe
      c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
      C:\APPS\SMP\SmpSys.exe
      C:\WINDOWS\system32\ctfmon.exe
      c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
      C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
      C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
      c:\APPS\Powercinema\Kernel\TV\CLSched.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      D:\Documents and Settings\adjiri\Bureau\SmitfraudFix\Policies.exe
      C:\WINDOWS\system32\cmd.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      »»»»»»»»»»»»»»»»»»»»»»»» D:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

      C:\WINDOWS\system32\tdssservers.dat détecté, utilisez un scanner de Rootkit
      C:\WINDOWS\system32\tdssinit.dll détecté, utilisez un scanner de Rootkit

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\adjiri

      »»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\adjiri\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

      »»»»»»»»»»»»»»»»»»»»»»»» D:\DOCUME~1\adjiri\Favoris

      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      C:\Program Files\Applications\ PRESENT !
      C:\Program Files\MSX\ PRESENT !

      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

      »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      o4Patch
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      AntiXPVSTFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
      "IPC Configuration Utility"="IPC Configuration Utility"

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» RK

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: Realtek RTL8139/810x Family Fast Ethernet NIC - Miniport d'ordonnancement de paquets
      DNS Server Search Order: 192.168.1.1
      DNS Server Search Order: 192.168.1.1

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{3A7427EB-8E45-4611-9102-03F4900975B1}: DhcpNameServer=192.168.1.1 192.168.1.1
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{3A7427EB-8E45-4611-9102-03F4900975B1}: DhcpNameServer=192.168.1.1 192.168.1.1
      HKLM\SYSTEM\CS2\Services\Tcpip\..\{3A7427EB-8E45-4611-9102-03F4900975B1}: DhcpNameServer=192.168.1.1 192.168.1.1
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1

      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

      »»»»»»»»»»»»»»»»»»»»»»»» Fin
  3. Modérateur
    - Redémarre ton ordinateur en mode sans échec :
    https://blog.sosordi.net/

    - Double-clique sur SmitfraudFix.exe, choisis l'option 2 et Entrée

    - Réponds O(oui) à ces deux questions si elles te sont posées

    Voulez-vous nettoyer le registre ?
    Corriger le fichier infecté ?

    - Un rapport sera généré, sauvegarde-le sur le bureau

    - Redémarre en mode normal

    - Poste le rapport SmitfraudFix
    1. ok a tout de suite.
    2. ici le raport 3 en mode sans echec

      SmitFraudFix v2.362

      Rapport fait à 17:20:33,50, 16/10/2008
      Executé à partir de D:\Documents and Settings\adjiri\Bureau\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode sans echec

      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
      "IPC Configuration Utility"="IPC Configuration Utility"

      »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      127.0.0.1 localhost

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

      S!Ri's WS2Fix: LSP not Found.
      »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

      GenericRenosFix by S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

      C:\Program Files\Applications\ supprimé
      C:\Program Files\MSX\ supprimé

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

      AntiXPVSTFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» RK

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{3A7427EB-8E45-4611-9102-03F4900975B1}: DhcpNameServer=192.168.1.1 192.168.1.1
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{3A7427EB-8E45-4611-9102-03F4900975B1}: DhcpNameServer=192.168.1.1 192.168.1.1
      HKLM\SYSTEM\CS2\Services\Tcpip\..\{3A7427EB-8E45-4611-9102-03F4900975B1}: DhcpNameServer=192.168.1.1 192.168.1.1
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1

      »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

      Nettoyage terminé.

      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
      "IPC Configuration Utility"="IPC Configuration Utility"

      »»»»»»»»»»»»»»»»»»»»»»»» Fin
  4. Modérateur
    On va s'occuper de ton rootkit.

    * Télécharge SDFix (par Andy Manchesta) et sauvegarde-le sur ton bureau.
    http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

    * Double-clique sur SDFix.exe et choisis Install pour l'extraire dans son dossier sur le bureau.
    * Redémarre le PC en mode sans échec :
    https://blog.sosordi.net/
    * Choisis ton compte.

    Déroule la liste des instructions ci-dessous :
    * Ouvre le dossier SDFix qui vient d'être créé sur le bureau et double-clique sur RunThis.bat pour lancer le script.
    * Appuie sur Y pour commencer le nettoyage.
    * Quand il te le demandera, appuie sur une touche pour redémarrer le PC.
    * Ton système sera plus long à redémarrer car l'outil va continuer à s'exécuter et supprimer des fichiers.
    * Après le chargement du bureau, l'outil aura terminé et affichera Finished.
    * Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton bureau.
    * Le rapport SDFix s'ouvrira et il sera enregistré dans le dossier SDFix sous le nom Report.txt.
    * Enfin, copie/colle le rapport du fichier Report.txt.
    1. salut voici le raport

      [b]SDFix: Version 1.236 [/b]
      Run by adjiri on 16/10/2008 at 17:55

      Microsoft Windows XP [version 5.1.2600]
      Running From: C:\SDFix

      [b]Checking Services [/b]:

      Restoring Default Security Values
      Restoring Default Hosts File

      Rebooting

      [b]Checking Files [/b]:

      Trojan Files Found:

      D:\Documents and Settings\adjiri\Application Data\ViewerApp.dat - Deleted
      C:\WINDOWS\system32\blackster.scr - Deleted
      C:\WINDOWS\system32\ctfmonb.bmp - Deleted
      C:\WINDOWS\system32\tdssinit.dll - Deleted
      C:\WINDOWS\system32\tdssservers.dat - Deleted

      Folder D:\Documents and Settings\adjiri\Application Data\AXPFixer - Removed

      Removing Temp Files

      [b]ADS Check [/b]:

      [b]Final Check [/b]:

      catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-10-16 18:03:32
      Windows 5.1.2600 Service Pack 2 NTFS

      scanning hidden processes ...

      scanning hidden services & system hive ...

      scanning hidden registry entries ...

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD96C556-65A3-11D0-983A-00C04FC29E36}\iexplore]
      "Type"=dword:00000001
      "Flags"=dword:00000000
      "Count"=dword:00000073
      "Blocked"=dword:00000073

      scanning hidden files ...

      scan completed successfully
      hidden processes: 0
      hidden services: 0
      hidden files: 0

      [b]Remaining Services [/b]:

      Authorized Application Key Export:

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
      "%ProgramFiles%\\AOL 9.0\\aol.exe"="%ProgramFiles%\\AOL 9.0\\aol.exe:*:Enabled:AOL"
      "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"="%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe:*:Enabled:SPLINTER CELL PANDORA"
      "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"="%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe:*:Enabled:PANDORA"
      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "C:\\APPS\\Inventime\\my.exe"="C:\\APPS\\Inventime\\my.exe:*:Enabled:INVENTIME"
      "C:\\Program Files\\Corel\\Graphics10\\Register\\NAVBrowser.exe"="C:\\Program Files\\Corel\\Graphics10\\Register\\NAVBrowser.exe:*:Enabled:NAVBrowser"
      "C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL 9.0"
      "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
      "C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Disabled:RealPlayer"
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
      "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
      "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
      "C:\\APPS\\skype\\Phone\\Skype.exe"="C:\\APPS\\skype\\Phone\\Skype.exe:*:Enabled:Skype"
      "C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
      "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
      "C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"="C:\\Program Files\\VideoLAN\\VLC\\vlc.exe:*:Disabled:VLC media player"
      "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
      "C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
      "C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Ex‚cuter une DLL en tant qu'application"
      "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL 9.0"
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
      "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
      "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

      [b]Remaining Files [/b]:

      File Backups: - C:\SDFix\backups\backups.zip

      [b]Files with Hidden Attributes [/b]:

      Fri 7 Jul 2006 215 A.SHR --- "C:\BOOT.BAK"
      Tue 31 May 2005 54,384 A..H. --- "C:\Program Files\AOL 9.0\aolphx.exe"
      Tue 31 May 2005 156,784 A..H. --- "C:\Program Files\AOL 9.0\aoltray.exe"
      Tue 31 May 2005 31,344 A..H. --- "C:\Program Files\AOL 9.0\RBM.exe"
      Sun 25 Nov 2007 10,022 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
      Sun 12 Oct 2008 40,448 A.SHR --- "C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP426\A0244397.exe"
      Thu 8 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\BIT1.tmp"
      Tue 31 May 2005 106,496 A..H. --- "C:\Program Files\Fichiers communs\aolshare\shell\fr\shellext.dll"

      [b]Finished![/b]
      1. Modérateur
        - Télécharge Navilog1 (de IL-MAFIOSO) et enregistre-le sur le bureau :
        http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

        - Double-clique sur Navilog1.exe afin de lancer l'installation

        - Si le fix ne lance pas automatiquement après son installation, double-clique sur Navilog1 présent sur le bureau

        - Appuie sur F ou f puis valide par Entrée

        - Appuie sur une touche de ton clavier à chaque fois que cela est demandé, tu arriveras au menu des options

        - Choisis l'option 1 et appuie sur la touche Entrée pour valider ton choix

        - Patiente jusqu'au message : *** Analyse terminée le ..... ***

        - Le scan fini, le bloc-notes contenant le rapport sera affiché, poste le contenu de ce rapport dans ta prochaine réponse

        - Si le résultat du scan ne s'affiche pas, tu le trouveras dans C:\fixnavi.txt

        N'utilise pas l'option 2, 3 et 4 sans notre accord, des fichiers légitimes peuvent être inclus dans ce scan.
        1. voici le raport merci.

          Search Navipromo version 3.6.6 commencé le 16/10/2008 à 18:24:42,64

          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
          !!! Postez ce rapport sur le forum pour le faire analyser !!!
          !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

          Outil exécuté depuis C:\Program Files\navilog1
          Session actuelle : "adjiri"

          Mise à jour le 29.09.2008 à 17h30 par IL-MAFIOSO

          Microsoft Windows XP [version 5.1.2600]
          Internet Explorer : 6.0.2900.2180
          Système de fichiers : NTFS

          Recherche executé en mode normal

          *** Recherche Programmes installés ***

          Instant Access

          *** Recherche dossiers dans "C:\WINDOWS" ***

          *** Recherche dossiers dans "C:\Program Files" ***

          ...\Instant Access trouvé !

          *** Recherche dossiers dans "D:\Documents and Settings\All Users\menudm~1\progra~1" ***

          *** Recherche dossiers dans "D:\Documents and Settings\All Users\menudm~1" ***

          *** Recherche dossiers dans "d:\docume~1\alluse~1\applic~1" ***

          *** Recherche dossiers dans "D:\Documents and Settings\adjiri\applic~1" ***

          *** Recherche dossiers dans "D:\Documents and Settings\adjiri\locals~1\applic~1" ***

          *** Recherche dossiers dans "D:\Documents and Settings\adjiri\menudm~1\progra~1" ***

          *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
          pour + d'infos : http://www.gmer.net

          *** Recherche avec GenericNaviSearch ***
          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
          !!! A vérifier impérativement avant toute suppression manuelle !!!

          * Recherche dans "C:\WINDOWS\system32" *

          * Recherche dans "D:\Documents and Settings\adjiri\locals~1\applic~1" *

          *** Recherche fichiers ***

          C:\WINDOWS\dialerexe.ini trouvé !
          C:\WINDOWS\tmlpcert2007 trouvé !
          C:\WINDOWS\system32\nvs2.inf trouvé !

          *** Recherche clés spécifiques dans le Registre ***

          HKEY_CURRENT_USER\Software\Lanconfig trouvé !

          *** Module de Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Recherche nouveaux fichiers Instant Access :

          2)Recherche Heuristique :

          * Dans "C:\WINDOWS\system32" :

          apyovrefd.dat trouvé !
          apyovrefd_nav.dat trouvé !
          apyovrefd_navps.dat trouvé !
          gnzaqqq.dat trouvé !
          gnzaqqq_nav.dat trouvé !
          gnzaqqq_navps.dat trouvé !
          tdkzrc.dat trouvé !
          tdkzrc_nav.dat trouvé !
          tdkzrc_navps.dat trouvé !
          vnjxqpsj.dat trouvé !
          vnjxqpsj_nav.dat trouvé !
          vnjxqpsj_navup.dat trouvé !
          vnjxqpsj_navps.dat trouvé !
          ylwpmbu.dat trouvé !
          ylwpmbu_nav.dat trouvé !
          ylwpmbu_navup.dat trouvé !
          ylwpmbu_navps.dat trouvé !

          * Dans "D:\Documents and Settings\adjiri\locals~1\applic~1" :

          3)Recherche Certificats :

          Certificat Egroup trouvé !
          Certificat Electronic-Group trouvé !
          Certificat Montorgueil absent !
          Certificat OOO-Favorit trouvé !
          Certificat Sunny-Day-Design-Ltd absent !

          4)Recherche fichiers connus :

          *** Analyse terminée le 16/10/2008 à 18:27:00,15 ***
          1. Modérateur
            Ne réinstalle pas Instant Access.

            ---> Relance Navilog1, fais l'option 2 et poste le rapport.
            1. le voici

              Clean Navipromo version 3.6.6 commencé le 16/10/2008 à 18:31:46,98

              Outil exécuté depuis C:\Program Files\navilog1
              Session actuelle : "adjiri"

              Mise à jour le 29.09.2008 à 17h30 par IL-MAFIOSO

              Microsoft Windows XP [version 5.1.2600]
              Internet Explorer : 6.0.2900.2180
              Système de fichiers : NTFS

              Mode suppression automatique
              avec prise en charge résultats Catchme et GNS

              Nettoyage exécuté au redémarrage de l'ordinateur

              *** fsbl1.txt non trouvé ***
              (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

              *** Suppression avec sauvegardes résultats GenericNaviSearch ***

              * Suppression dans "C:\WINDOWS\System32" *

              * Suppression dans "D:\Documents and Settings\adjiri\locals~1\applic~1" *

              *** Suppression dossiers dans "C:\WINDOWS" ***

              *** Suppression dossiers dans "C:\Program Files" ***

              ...\Instant Access ...suppression...
              ...\Instant Access supprimé !

              *** Suppression dossiers dans "D:\Documents and Settings\All Users\menudm~1\progra~1" ***

              *** Suppression dossiers dans "D:\Documents and Settings\All Users\menudm~1" ***

              *** Suppression dossiers dans "d:\docume~1\alluse~1\applic~1" ***

              *** Suppression dossiers dans "D:\Documents and Settings\adjiri\applic~1" ***

              *** Suppression dossiers dans "D:\Documents and Settings\adjiri\locals~1\applic~1" ***

              *** Suppression dossiers dans "D:\Documents and Settings\adjiri\menudm~1\progra~1" ***

              *** Suppression fichiers ***

              C:\WINDOWS\dialerexe.ini supprimé !
              C:\WINDOWS\tmlpcert2007 supprimé !
              C:\WINDOWS\system32\nvs2.inf supprimé !

              *** Suppression fichiers temporaires ***

              Nettoyage contenu C:\WINDOWS\Temp effectué !
              Nettoyage contenu D:\Documents and Settings\adjiri\locals~1\Temp effectué !

              *** Traitement Recherche complémentaire ***
              (Recherche fichiers spécifiques)

              1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

              2)Recherche, création sauvegardes et suppression Heuristique :

              * Dans "C:\WINDOWS\system32" *

              apyovrefd.dat trouvé !
              Copie apyovrefd.dat réalisée avec succès !
              apyovrefd.dat supprimé !

              apyovrefd_nav.dat trouvé !
              Copie apyovrefd_nav.dat réalisée avec succès !
              apyovrefd_nav.dat supprimé !

              apyovrefd_navps.dat trouvé !
              Copie apyovrefd_navps.dat réalisée avec succès !
              apyovrefd_navps.dat supprimé !

              gnzaqqq.dat trouvé !
              Copie gnzaqqq.dat réalisée avec succès !
              gnzaqqq.dat supprimé !

              gnzaqqq_nav.dat trouvé !
              Copie gnzaqqq_nav.dat réalisée avec succès !
              gnzaqqq_nav.dat supprimé !

              gnzaqqq_navps.dat trouvé !
              Copie gnzaqqq_navps.dat réalisée avec succès !
              gnzaqqq_navps.dat supprimé !

              tdkzrc.dat trouvé !
              Copie tdkzrc.dat réalisée avec succès !
              tdkzrc.dat supprimé !

              tdkzrc_nav.dat trouvé !
              Copie tdkzrc_nav.dat réalisée avec succès !
              tdkzrc_nav.dat supprimé !

              tdkzrc_navps.dat trouvé !
              Copie tdkzrc_navps.dat réalisée avec succès !
              tdkzrc_navps.dat supprimé !

              vnjxqpsj.dat trouvé !
              Copie vnjxqpsj.dat réalisée avec succès !
              vnjxqpsj.dat supprimé !

              vnjxqpsj_nav.dat trouvé !
              Copie vnjxqpsj_nav.dat réalisée avec succès !
              vnjxqpsj_nav.dat supprimé !

              vnjxqpsj_navps.dat trouvé !
              Copie vnjxqpsj_navps.dat réalisée avec succès !
              vnjxqpsj_navps.dat supprimé !

              vnjxqpsj_navup.dat trouvé !
              Copie vnjxqpsj_navup.dat réalisée avec succès !
              vnjxqpsj_navup.dat supprimé !

              ylwpmbu.dat trouvé !
              Copie ylwpmbu.dat réalisée avec succès !
              ylwpmbu.dat supprimé !

              ylwpmbu_nav.dat trouvé !
              Copie ylwpmbu_nav.dat réalisée avec succès !
              ylwpmbu_nav.dat supprimé !

              ylwpmbu_navps.dat trouvé !
              Copie ylwpmbu_navps.dat réalisée avec succès !
              ylwpmbu_navps.dat supprimé !

              ylwpmbu_navup.dat trouvé !
              Copie ylwpmbu_navup.dat réalisée avec succès !
              ylwpmbu_navup.dat supprimé !

              * Dans "D:\Documents and Settings\adjiri\locals~1\applic~1" *

              *** Sauvegarde du Registre vers dossier Safebackup ***

              sauvegarde du Registre réalisée avec succès !

              *** Nettoyage Registre ***

              Nettoyage Registre Ok

              *** Certificats ***

              Certificat Egroup supprimé !
              Certificat Electronic-Group supprimé !
              Certificat Montorgueil absent !
              Certificat OOO-Favorit supprimé !
              Certificat Sunny-Day-Design-Ltdt absent !

              *** Nettoyage terminé le 16/10/2008 à 18:35:25,48 ***
              1. Modérateur
                ---> Supprime SmitFraudFix

                ---> Désinstalle Navilog1

                ---> Poste un nouveau rapport HijackThis
                1. ok
                2. comment desinstalé SmitfraudFix
              2. Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 18:47:19, on 16/10/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\spoolsv.exe
                c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
                c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
                C:\APPS\Powercinema\PCMService.exe
                C:\Program Files\Real\RealPlayer\RealPlay.exe
                C:\Program Files\QuickTime\qttask.exe
                C:\WINDOWS\VM_STI.EXE
                C:\Program Files\DS-3200 Wireless Optical Slimline Deskset\MouseDrv.exe
                C:\Program Files\DS-3200 Wireless Optical Slimline Deskset\PS2USBKbdDrv.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\LVCOMSX.EXE
                C:\Program Files\Logitech\Video\CameraAssistant.exe
                C:\WINDOWS\system32\ElkCtrl.exe
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\WINDOWS\RTHDCPL.EXE
                C:\Program Files\TomTom HOME\TomTomHOME.exe
                C:\APPS\SMP\SmpSys.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
                C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
                C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=proxy.club-internet.fr:8080
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
                O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O3 - Toolbar: (no name) - {DDA28099-DACF-415D-A5A8-BB134FCA3D6A} - (no file)
                O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                O4 - HKLM\..\Run: [ATICCC] "c:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
                O4 - HKLM\..\Run: [DetectorApp] C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
                O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                O4 - HKLM\..\Run: [PCMService] "c:\APPS\Powercinema\PCMService.exe"
                O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
                O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S6.tmp" /EF "HKLM"
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
                O4 - HKLM\..\Run: [WireLessMouse] C:\Program Files\DS-3200 Wireless Optical Slimline Deskset\MouseDrv.exe
                O4 - HKLM\..\Run: [WireLessKeyboard] C:\Program Files\DS-3200 Wireless Optical Slimline Deskset\PS2USBKbdDrv.exe
                O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
                O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
                O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
                O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series (Copie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_SD.tmp" /EF "HKLM"
                O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_SEE.tmp" /EF "HKLM"
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
                O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
                O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
                O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                O4 - Startup: Présentation de Media Manager.lnk = C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\SPLASHA.EXE
                O4 - Global Startup: Picture Package Menu.lnk = ?
                O4 - Global Startup: Picture Package VCD Maker.lnk = ?
                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
                O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                O22 - SharedTaskScheduler: IPC Configuration Utility - IPC Configuration Utility - (no file)
                O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                O23 - Service: CyberLink Media Library Service - Cyberlink - c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
                1. Modérateur
                  - Télécharge et installe MalwareByte's Anti-Malware :
                  http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm

                  - Mets-le à jour

                  - Redémarre en mode sans échec (Recommandé) :
                  https://blog.sosordi.net/

                  - Choisis ta session habituelle

                  - Fais un scan complet avec MalwareByte's Anti-Malware

                  - Supprime tout ce que le logiciel trouve, enregistre le rapport

                  - Redémarre en mode normal et poste le rapport ici

                  Tutorial :
                  https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                  1. le voici

                    Malwarebytes' Anti-Malware 1.28
                    Version de la base de données: 1276
                    Windows 5.1.2600 Service Pack 2

                    16/10/2008 19:29:37
                    mbam-log-2008-10-16 (19-29-37).txt

                    Type de recherche: Examen rapide
                    Eléments examinés: 49098
                    Temps écoulé: 20 minute(s), 28 second(s)

                    Processus mémoire infecté(s): 0
                    Module(s) mémoire infecté(s): 0
                    Clé(s) du Registre infectée(s): 79
                    Valeur(s) du Registre infectée(s): 0
                    Elément(s) de données du Registre infecté(s): 0
                    Dossier(s) infecté(s): 25
                    Fichier(s) infecté(s): 4

                    Processus mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Module(s) mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Clé(s) du Registre infectée(s):
                    HKEY_CLASSES_ROOT\hbtcoresrv.hbtcoreservices (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbtcoresrv.hbtcoreservices.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbtcoresrv.lfgax (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbtcoresrv.lfgax.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbthostol.hbtmailanim (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbthostol.hbtmailanim.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbthostol.hbtwebmailsend (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbthostol.hbtwebmailsend.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbtinstie.hbinstobj (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbtinstie.hbinstobj.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbtools.hbtcommband (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbtools.hbtcommband.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbtsrv.hbtcoreservices (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbtsrv.hbtcoreservices.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbttoolbar.hbthtmlmenuui (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbttoolbar.hbthtmlmenuui.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbttoolbar.hbttoolbarctl (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbttoolbar.hbttoolbarctl.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbttools.hbmain (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\hbttools.hbmain.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\seekmotoolbar.seekmotoolband (Adware.180Solutions) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\seekmotoolbar.seekmotoolband.1 (Adware.180Solutions) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\wxdbpfvo.bfbx (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\wxdbpfvo.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{175816a5-219e-4079-b2f9-53c501c409ba} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{1c1793e0-1034-4cac-837d-aa545f6961bf} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{27c4569f-8728-4958-a920-a607cae8153c} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{38370864-346f-4afa-8c4b-4fbff518c0bb} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{397a208b-3d09-4b3e-93e8-ca171886612e} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{421745e9-16df-4ee4-a758-d51f939c49cb} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{4331ec56-0aab-499e-8757-dd2ee44ad671} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{54286c3a-e044-4e65-bd44-528d6ae28a18} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{5d16197a-1eaa-45af-b29a-69f1aa055e87} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{5f2b9de7-f878-4762-8cfe-e9c58f082f0e} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{601a9784-1114-4089-9b3e-cbd70dafc6ad} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{8a61a950-c325-4f44-ba64-273180ff3464} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{8d5c4ec6-af8e-4b85-ba27-64babe410510} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{8e98faf8-794f-47f9-af90-15305564ed81} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{af15975b-1498-4740-8e6c-90af78e4198c} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{b53d4cd4-406d-43cc-8244-7893d72236dd} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{b671426c-5c1a-48ac-9652-bc9402b1c404} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{b9bb3219-f84c-4060-966b-4a1e73e24226} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{bc8c2e5f-d8b4-4997-bce3-8775c3707956} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{d082721f-4bd4-4b8b-bb82-06753ee6174f} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{d24f9d3c-5d4c-47f8-9ab7-632b44ad6a0d} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{ec9c872e-ad0f-45aa-be2b-657fa2c1fd8d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{f43ec88b-b6c8-4969-a763-e2bf55602cce} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Interface\{f786cb18-3809-4e49-bc99-9a66da47db8b} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\CLSID\{0ab71193-ec19-4d70-85c2-e46e2ff02755} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\CLSID\{31a59636-0fa3-4a56-954d-db7ad02840d8} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\CLSID\{3fa917b9-df69-477f-9e4f-b60d929de79f} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\CLSID\{420c35c9-e4f2-49f9-bf67-2be1ecf86989} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\CLSID\{460ac4db-b0de-4626-a0f0-175dd84dcb9b} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\CLSID\{7e66936c-fea0-4984-ad26-7b6661ac5b2e} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\CLSID\{8c875948-9c60-4381-9248-0df180542d53} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\CLSID\{90b5a95a-afd5-4d11-b9bd-a69d53d22226} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\CLSID\{a14c0d8d-e753-4e73-9e2b-4070791d8940} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\CLSID\{c2baa4c9-ae1e-4605-ae2f-a1c49a30d881} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\CLSID\{ed8525ea-2bfc-4440-bd8a-20efb9d5e541} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\CLSID\{fa16bce1-5e36-472a-8466-e0cdd5ce00e6} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\CLSID\{53e0b6e8-a51d-448b-b692-40b67b285543} (Adware.180Solutions) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Typelib\{45397063-d7d0-47c2-9508-26487608a298} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Typelib\{4cf5a3c1-07a2-4336-9b54-6870452ebde1} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Typelib\{71e9cf40-af72-4b55-bd3f-1fea2a0eaea6} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Typelib\{71efe583-62fe-4419-9918-ca3b683f7b36} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Typelib\{793af621-5cd0-4b92-b765-6712f6aaf48e} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Typelib\{9967a873-40f3-4c7e-9239-6c8760f19f61} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Typelib\{b9f51d42-cca0-4408-bb02-d433d1865a3a} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\Typelib\{f8ee014f-b34c-4544-8e45-95a7971d323b} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\AppID\{0507fdde-f3b7-49f5-9e8f-c557e991f39b} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{7e66936c-fea0-4984-ad26-7b6661ac5b2e} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{90b5a95a-afd5-4d11-b9bd-a69d53d22226} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8109fd3d-d891-4f80-8339-50a4913ace6f} (Adware.Zango) -> Quarantined and deleted successfully.
                    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{7e66936c-fea0-4984-ad26-7b6661ac5b2e} (Adware.Hotbar) -> Quarantined and deleted successfully.
                    HKEY_LOCAL_MACHINE\SOFTWARE\shc19bj0e38n (Rogue.Multiple) -> Quarantined and deleted successfully.
                    HKEY_LOCAL_MACHINE\SOFTWARE\AXPDefender (Rogue.AdvancedXPDefender) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\AppID\seekmotoolbar.seekmotoolband (Adware.Seekmo) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\AppID\seekmotoolbar.seekmotoolband.1 (Adware.Seekmo) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\AppID\WeatherOnTray.EXE (Adware.Hotbar) -> Quarantined and deleted successfully.

                    Valeur(s) du Registre infectée(s):
                    (Aucun élément nuisible détecté)

                    Elément(s) de données du Registre infecté(s):
                    (Aucun élément nuisible détecté)

                    Dossier(s) infecté(s):
                    C:\Program Files\Hotbar (Adware.Hotbar) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\AXPDefender (Rogue.AdvancedXPDefender) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\AXPDefender\AXPDefender (Rogue.AdvancedXPDefender) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\AXPDefender\AXPDefender\Quarantine (Rogue.AdvancedXPDefender) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\AXPDefender\AXPDefender\Quarantine\Autorun (Rogue.AdvancedXPDefender) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\AXPDefender\AXPDefender\Quarantine\Autorun\HKCU (Rogue.AdvancedXPDefender) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\AXPDefender\AXPDefender\Quarantine\Autorun\HKCU\RunOnce (Rogue.AdvancedXPDefender) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\AXPDefender\AXPDefender\Quarantine\Autorun\HKLM (Rogue.AdvancedXPDefender) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\AXPDefender\AXPDefender\Quarantine\Autorun\HKLM\RunOnce (Rogue.AdvancedXPDefender) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\AXPDefender\AXPDefender\Quarantine\Autorun\StartMenuAllUsers (Rogue.AdvancedXPDefender) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\AXPDefender\AXPDefender\Quarantine\Autorun\StartMenuCurrentUser (Rogue.AdvancedXPDefender) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\AXPDefender\AXPDefender\Quarantine\BrowserObjects (Rogue.AdvancedXPDefender) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\AXPDefender\AXPDefender\Quarantine\Packages (Rogue.AdvancedXPDefender) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\shc19bj0e38n (Rogue.Multiple) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\shc19bj0e38n\Quarantine (Rogue.Multiple) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\shc19bj0e38n\Quarantine\Autorun (Rogue.Multiple) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\shc19bj0e38n\Quarantine\Autorun\HKCU (Rogue.Multiple) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\shc19bj0e38n\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\shc19bj0e38n\Quarantine\Autorun\HKLM (Rogue.Multiple) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\shc19bj0e38n\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\shc19bj0e38n\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\shc19bj0e38n\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\shc19bj0e38n\Quarantine\BrowserObjects (Rogue.Multiple) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\shc19bj0e38n\Quarantine\Packages (Rogue.Multiple) -> Quarantined and deleted successfully.
                    C:\WINDOWS\system32\768890 (Trojan.BHO) -> Quarantined and deleted successfully.

                    Fichier(s) infecté(s):
                    C:\RECYCLER\S-1-5-21-2180703008-587160991-2776592955-1006\Dc1.dll (Trojan.BHO) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\config.cfg (Malware.Trace) -> Quarantined and deleted successfully.
                    D:\Documents and Settings\adjiri\Application Data\~tmp.html (Malware.Trace) -> Quarantined and deleted successfully.
                    C:\bulletin.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                2. restaure ton système si par chance tu avait créer un point de restauration avant de chopé le virus
                  1. Modérateur
                    ---> Relance MBAM, va dans Quarantaine et supprime tout.

                    ---> Télécharge Toolbar S&D (Team IDN) sur ton Bureau.
                    https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

                    * Lance l'installation du programme en exécutant le fichier téléchargé.
                    * Double-clique maintenant sur le raccourci de Toolbar-S&D.
                    * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
                    * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
                    * Poste le rapport généré. (C:\TB.txt)
                    1. le voila le raport merci.

                      -----------\\ ToolBar S&D 1.2.2 XP/Vista

                      Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
                      X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.06GHz )
                      BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
                      USER : adjiri ( Administrator )
                      BOOT : Normal boot
                      Antivirus : avast! antivirus 4.8.1229 [VPS 081015-0] 4.8.1229 (Activated)
                      Firewall : Norton Internet Worm Protection 2006 (Not Activated)
                      C:\ (Local Disk) - NTFS - Total : 29 Go Free : 21 Go
                      D:\ (Local Disk) - NTFS - Total : 148 Go Free : 120 Go
                      E:\ (CD or DVD)
                      F:\ (Local Disk) - NTFS - Total : 7 Go Free : 7 Go

                      "C:\ToolBar SD" ( MAJ : 04-10-2008|21:00 )
                      Option : [1] ( 16/10/2008|19:41 )

                      -----------\\ Recherche de Fichiers / Dossiers ...

                      C:\Program Files\Hbtools
                      C:\Program Files\Hbtools\Bin
                      C:\Program Files\Hbtools\HBTV
                      C:\Program Files\Seekmo Programs
                      C:\Program Files\Seekmo Programs\Seekmo Toolbar

                      -----------\\ Extensions

                      (Program Files) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

                      -----------\\ [..\Internet Explorer\Main]

                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                      "Local Page"="C:\\windows\\system32\\blank.htm"
                      "Start Page"="https://www.google.com/?gws_rd=ssl"
                      "Search Page"="https://www.google.com/?gws_rd=ssl"
                      "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                      "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                      "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                      "Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
                      "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                      "Local Page"="C:\\windows\\system32\\blank.htm"
                      "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"

                      --------------------\\ Recherche d'autres infections

                      Aucune autre infection trouvée !

                      1 - "C:\ToolBar SD\TB_1.txt" - 16/10/2008|19:43 - Option : [1]

                      -----------\\ Fin du rapport a 19:43:10,18
                      1. Modérateur
                        ---> Relance Toolbar S&D, fais l'option 2 et poste le rapport.
                        1. -----------\\ ToolBar S&D 1.2.2 XP/Vista

                          Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
                          X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.06GHz )
                          BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
                          USER : adjiri ( Administrator )
                          BOOT : Normal boot
                          Antivirus : avast! antivirus 4.8.1229 [VPS 081015-0] 4.8.1229 (Activated)
                          Firewall : Norton Internet Worm Protection 2006 (Not Activated)
                          C:\ (Local Disk) - NTFS - Total : 29 Go Free : 21 Go
                          D:\ (Local Disk) - NTFS - Total : 148 Go Free : 120 Go
                          E:\ (CD or DVD)
                          F:\ (Local Disk) - NTFS - Total : 7 Go Free : 7 Go

                          "C:\ToolBar SD" ( MAJ : 04-10-2008|21:00 )
                          Option : [2] ( 16/10/2008|19:56 )

                          -----------\\ SUPPRESSION

                          Supprime! - C:\Program Files\Hbtools\Bin
                          Supprime! - C:\Program Files\Hbtools\HBTV
                          Supprime! - C:\Program Files\Seekmo Programs\Seekmo Toolbar
                          Supprime! - C:\Program Files\Hbtools
                          Supprime! - C:\Program Files\Seekmo Programs

                          -----------\\ Recherche de Fichiers / Dossiers ...

                          -----------\\ Extensions

                          (Program Files) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

                          -----------\\ [..\Internet Explorer\Main]

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                          "Local Page"="C:\\windows\\system32\\blank.htm"
                          "Start Page"="https://www.google.com/?gws_rd=ssl"
                          "Search Page"="https://www.google.com/?gws_rd=ssl"
                          "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                          "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                          "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                          "Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
                          "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                          "Local Page"="C:\\windows\\system32\\blank.htm"
                          "Start Page"="https://www.msn.com/fr-fr/"

                          --------------------\\ Recherche d'autres infections

                          Aucune autre infection trouvée !

                          1 - "C:\ToolBar SD\TB_1.txt" - 16/10/2008|19:43 - Option : [1]
                          2 - "C:\ToolBar SD\TB_2.txt" - 16/10/2008|19:57 - Option : [2]

                          -----------\\ Fin du rapport a 19:57:25,56
                          • 1
                          • 2