Virus au travail!

Bonjour,
Voila je suis actuellement infecté par un virus qui me demande de travailler et d'arreter de surfer.
je pense que vous le connaissez, j'ai des messages qui arrive de nul part et ma page d'acccueil est travaillez plus .com ....

voici le rapport hijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:07:11, on 27/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\SYSTEM32\wscript.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\1XConfig.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\system32\BacsTray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\AOL\Screensaver\ygpsstra.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\DOCUME~1\Kieffer\LOCALS~1\Temp\ICEOWS\ViewUpd\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.dell.com/en-ca
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Travaillez plus.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.dell.com/en-ca
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Au travail !Arrêtez de surfer!
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\userinit.exe,C:\WINDOWS\SYSTEM32\wscript.exe C:\WINDOWS\SYSTEM32\antinul.vbe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [bacstray] BacsTray.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Ecran de veille] C:\Program Files\Fichiers communs\AOL\Screensaver\ygpsstra.exe
O4 - HKCU\..\Run: [MoodBook] "C:\Program Files\MoodBook\mb.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Gautier
O17 - HKLM\Software\..\Telephony: DomainName = Gautier
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Gautier
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Gautier
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = Gautier
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

--
End of file - 11819 bytes


Ensuite voici mon dernier rapport antivir :


Avira AntiVir Personal
Report file date: samedi 25 octobre 2008 20:07

Scanning for 1707541 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 3) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: GAUTIER

Version information:
BUILD.DAT : 8.2.0.334 16933 Bytes 16/10/2008 14:55:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 09:57:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 08:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 13:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 08:58:52
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 11:33:34
ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 14:54:15
ANTIVIR2.VDF : 7.0.7.59 4366336 Bytes 19/10/2008 19:30:33
ANTIVIR3.VDF : 7.0.7.92 192000 Bytes 25/10/2008 19:05:44
Engineversion : 8.2.0.9
AEVDF.DLL : 8.1.0.6 102772 Bytes 20/10/2008 19:31:06
AESCRIPT.DLL : 8.1.1.9 319867 Bytes 20/10/2008 19:31:05
AESCN.DLL : 8.1.1.3 123252 Bytes 20/10/2008 19:31:03
AERDL.DLL : 8.1.1.2 438644 Bytes 20/10/2008 19:31:02
AEPACK.DLL : 8.1.2.4 369014 Bytes 20/10/2008 19:30:58
AEOFFICE.DLL : 8.1.0.29 196988 Bytes 23/10/2008 20:07:49
AEHEUR.DLL : 8.1.0.63 1479032 Bytes 23/10/2008 20:07:47
AEHELP.DLL : 8.1.1.2 115062 Bytes 20/10/2008 19:30:45
AEGEN.DLL : 8.1.0.42 319861 Bytes 25/10/2008 19:05:46
AEEMU.DLL : 8.1.0.9 393588 Bytes 20/10/2008 19:30:40
AECORE.DLL : 8.1.2.8 172406 Bytes 25/10/2008 19:05:45
AEBB.DLL : 8.1.0.3 53618 Bytes 20/10/2008 19:30:37
AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 09:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 10:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 20/10/2008 19:30:36
AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 12:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 09:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 13:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 18:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 13:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 13:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 14:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 14:34:37

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: samedi 25 octobre 2008 20:07

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'DLG.exe' - '1' Module(s) have been scanned
Scan process 'iPodService.exe' - '1' Module(s) have been scanned
Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
Scan process 'ygpsstra.exe' - '1' Module(s) have been scanned
Scan process 'ApntEx.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'QTTask.exe' - '1' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
Scan process 'realplay.exe' - '1' Module(s) have been scanned
Scan process 'DMXLauncher.exe' - '1' Module(s) have been scanned
Scan process 'tfswctrl.exe' - '1' Module(s) have been scanned
Scan process 'ccApp.exe' - '1' Module(s) have been scanned
Scan process 'quickset.exe' - '1' Module(s) have been scanned
Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
Scan process 'BacsTray.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'Apoint.exe' - '1' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process '1XConfig.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'wscript.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'ZCfgSvc.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'symwsc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'RegSrvc.exe' - '1' Module(s) have been scanned
Scan process 'CCPROXY.EXE' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'ccEvtMgr.exe' - '1' Module(s) have been scanned
Scan process 'SNDSrvc.exe' - '1' Module(s) have been scanned
Scan process 'ccSetMgr.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'S24EvMon.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
52 processes with 52 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!

Starting to scan the registry.
The registry was scanned ( '71' files ).

Starting the file scan:

Begin scan in 'C:\'
C:\hiberfil.sys
[WARNING] The file could not be opened!
C:\pagefile.sys
[WARNING] The file could not be opened!

End of the scan: samedi 25 octobre 2008 21:03
Used time: 55:15 Minute(s)

The scan has been done completely.

5901 Scanning directories
318466 Files were scanned
0 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
318464 Files not concerned
3343 Archives were scanned
2 Warnings
0 Notes


et pour finir le dernier rapport de malwarebytes

Malwarebytes' Anti-Malware 1.29
Version de la base de données: 1298
Windows 5.1.2600 Service Pack 3

21/10/2008 07:10:09
mbam-log-2008-10-21 (07-10-09).txt

Type de recherche: Examen complet (C:\|)
Eléments examinés: 128428
Temps écoulé: 1 hour(s), 16 minute(s), 39 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 7

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\WINDOWS\b.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\regedit.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\cmd.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\ping.com (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\netstat.com (Worm.Alcra) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\tasklist.com (Worm.Alcra) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\tracert.com (Worm.Alcra) -> Quarantined and deleted successfully.

Je pense que je suis infecté par plusieurs choses, mais comme tout ce qui est susmentionné me depasse je demande votre aide. Merci
Configuration: Windows XP
Internet Explorer 7.0

26 réponses

Résumé de la discussion

Le fil expose une infection qui modifie la page d'accueil et les pages de recherche, et pousse l'utilisateur à travailler sans surfer, comme en témoignent les rapports HijackThis et les scans Avira. Le rapport HijackThis montre des paramètres modifiés (Start Page, Search Page) et de multiples extensions ou modules (BHO, barres d'outils) associant des processus système et des services tiers. L'analyse antivirus Avira confirme un système infecté avec des éléments résidents et des éléments de sécurité actifs, puis révèle une activité multiple liée à divers outils et services. D'autres détails techniques, tels que les listes de processus et les entrées de démarrage, soulignent la présence de barres d'outils et de programmes potentiellement indésirables devant être nettoyés.

Bobot (l’IA à votre service)
  1. ok

    relance SmitfraudFix et fait le nettoyage avec l'option 2 mais en mode sans echec par contre

    Démarre en mode sans échec :
    Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
    Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
    Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
    (Si F8 ne marche pas utilise la touche F5).

    http://www.coupdepoucepc.com/modules/news/article.php?storyid=253
    https://www.micro-astuce.com/depannage/demarrer-mode-sans-echec.php

    ensuite en mode normal

    à lire jusqu'en bas

    Clique sur ce lien
    http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
    pour télécharger le fichier d'installation d'HijackThis.

    Enregistre HJTInstall.exe sur ton bureau.

    Double-clique sur HJTInstall.exe pour lancer le programme

    Par défaut, il s'installera là :
    C:\Program Files\Trend Micro\HijackThis

    Accepte la license en cliquant sur le bouton "I Accept"

    Choisis l'option "Do a system scan and save a log file"

    Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note

    Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

    Colle le rapport que tu viens de copier sur ce forum

    Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement

    IMPORTANT

    Rends toi sur ton PC ici "C:\ programme file\Trend Micro\HijackThis\HijackThis.exe"<---clik droit sur ce dernier
    et choisis "renommer" : tapes eden et valide . FAIRE AVANT TOUT LANCEMENT DE HIJACKTHIS


    Tutoriaux : http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm (ne fixe rien pour le moment !!)
    http://cybersecurite.xooit.com/t138-HijackThis-2-0-2.htm
    2
    1. bon il fait de la résistance

      Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
      http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
      https://www.malekal.com/slenfbot-still-an-other-irc-bot/

      Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
      • Redémarre ton ordinateur
      http://www.coupdepoucepc.com/modules/news/article.php?storyi­d=253
      http://www.micro-astuce.com/depannage/demarrer-mode-sans-ech­ec

      • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
      • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
      • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
      • Choisis ton compte.
      Déroule la liste des instructions ci-dessous :
      • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
      • Appuie sur Y pour commencer le processus de nettoyage.
      • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
      • Appuie sur une touche pour redémarrer le PC.
      • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
      • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
      • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
      • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
      • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum,

      1
      1. voila le rapport demandé:
        SmitFraudFix v2.367

        Rapport fait à 14:57:44,33, 27/10/2008
        Executé à partir de C:\Documents and Settings\Kieffer\Bureau\SmitfraudFix
        OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
        Le type du système de fichiers est NTFS
        Fix executé en mode normal

        »»»»»»»»»»»»»»»»»»»»»»»» Process

        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\S24EvMon.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
        C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
        C:\WINDOWS\system32\RegSrvc.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
        C:\WINDOWS\system32\ZCfgSvc.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\SYSTEM32\wscript.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\1XConfig.exe
        C:\Program Files\Apoint\Apoint.exe
        C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        C:\WINDOWS\system32\BacsTray.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\Program Files\Dell\QuickSet\quickset.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
        C:\WINDOWS\system32\dla\tfswctrl.exe
        C:\Program Files\Dell\Media Experience\DMXLauncher.exe
        C:\Program Files\Real\RealPlayer\RealPlay.exe
        C:\Program Files\Apoint\Apntex.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\QuickTime\QTTask.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Fichiers communs\AOL\Screensaver\ygpsstra.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Digital Line Detect\DLG.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Windows Live\Messenger\usnsvc.exe
        C:\Documents and Settings\Kieffer\Bureau\SmitfraudFix\Policies.exe
        C:\WINDOWS\system32\cmd.exe

        »»»»»»»»»»»»»»»»»»»»»»»» hosts

        »»»»»»»»»»»»»»»»»»»»»»»» C:\

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Kieffer

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Kieffer\Application Data

        »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

        »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Kieffer\Favoris

        »»»»»»»»»»»»»»»»»»»»»»»» Bureau

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

        »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

        »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

        »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        o4Patch
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        IEDFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» VACFix
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        VACFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        404Fix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        AntiXPVSTFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
        "AppInit_DLLs"=""

        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
        "Userinit"="C:\\WINDOWS\\SYSTEM32\\userinit.exe,C:\\WINDOWS\\SYSTEM32\\wscript.exe C:\\WINDOWS\\SYSTEM32\\antinul.vbe"
        "System"=""

        »»»»»»»»»»»»»»»»»»»»»»»» RK

        »»»»»»»»»»»»»»»»»»»»»»»» DNS

        HKLM\SYSTEM\CS2\Services\Tcpip\..\{9242BB59-CB16-499F-B59F-6FEE36A523ED}: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CS3\Services\Tcpip\..\{9242BB59-CB16-499F-B59F-6FEE36A523ED}: DhcpNameServer=194.206.126.253 194.206.126.53
        HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=194.206.126.253 194.206.126.53

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

        »»»»»»»»»»»»»»»»»»»»»»»» Fin
        0
        1. voila le rapport demandé:
          SmitFraudFix v2.367

          Rapport fait à 14:57:44,33, 27/10/2008
          Executé à partir de C:\Documents and Settings\Kieffer\Bureau\SmitfraudFix
          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
          Le type du système de fichiers est NTFS
          Fix executé en mode normal

          »»»»»»»»»»»»»»»»»»»»»»»» Process

          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\S24EvMon.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
          C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
          C:\WINDOWS\system32\RegSrvc.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
          C:\WINDOWS\system32\ZCfgSvc.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\SYSTEM32\wscript.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\1XConfig.exe
          C:\Program Files\Apoint\Apoint.exe
          C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
          C:\WINDOWS\system32\BacsTray.exe
          C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
          C:\Program Files\Dell\QuickSet\quickset.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
          C:\WINDOWS\system32\dla\tfswctrl.exe
          C:\Program Files\Dell\Media Experience\DMXLauncher.exe
          C:\Program Files\Real\RealPlayer\RealPlay.exe
          C:\Program Files\Apoint\Apntex.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\QuickTime\QTTask.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Fichiers communs\AOL\Screensaver\ygpsstra.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Digital Line Detect\DLG.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\Documents and Settings\Kieffer\Bureau\SmitfraudFix\Policies.exe
          C:\WINDOWS\system32\cmd.exe

          »»»»»»»»»»»»»»»»»»»»»»»» hosts

          »»»»»»»»»»»»»»»»»»»»»»»» C:\

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Kieffer

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Kieffer\Application Data

          »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Kieffer\Favoris

          »»»»»»»»»»»»»»»»»»»»»»»» Bureau

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

          »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

          »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

          »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          o4Patch
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          IEDFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» VACFix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          VACFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          404Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          AntiXPVSTFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLs"=""

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "Userinit"="C:\\WINDOWS\\SYSTEM32\\userinit.exe,C:\\WINDOWS\\SYSTEM32\\wscript.exe C:\\WINDOWS\\SYSTEM32\\antinul.vbe"
          "System"=""

          »»»»»»»»»»»»»»»»»»»»»»»» RK

          »»»»»»»»»»»»»»»»»»»»»»»» DNS

          HKLM\SYSTEM\CS2\Services\Tcpip\..\{9242BB59-CB16-499F-B59F-6FEE36A523ED}: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS3\Services\Tcpip\..\{9242BB59-CB16-499F-B59F-6FEE36A523ED}: DhcpNameServer=194.206.126.253 194.206.126.53
          HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=194.206.126.253 194.206.126.53

          »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

          »»»»»»»»»»»»»»»»»»»»»»»» Fin
          0
          1. Alors comme demandé ligne 2 en mode sans echec , je colle le rapport :
            SmitFraudFix v2.367

            Rapport fait à 15:24:13,83, 27/10/2008
            Executé à partir de C:\Documents and Settings\Kieffer\Bureau\SmitfraudFix
            OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
            Le type du système de fichiers est NTFS
            Fix executé en mode sans echec

            »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            127.0.0.1 localhost

            »»»»»»»»»»»»»»»»»»»»»»»» VACFix

            VACFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

            S!Ri's WS2Fix: LSP not Found.

            »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

            GenericRenosFix by S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

            »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

            IEDFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

            404Fix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

            AntiXPVSTFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» RK

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{9242BB59-CB16-499F-B59F-6FEE36A523ED}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{9242BB59-CB16-499F-B59F-6FEE36A523ED}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS2\Services\Tcpip\..\{9242BB59-CB16-499F-B59F-6FEE36A523ED}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

            »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "System"=""

            »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

            Nettoyage terminé.

            »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» Fin

            apres cela : mode normal et le rapport demandé

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 15:37:32, on 27/10/2008
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16735)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\S24EvMon.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
            C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
            C:\WINDOWS\system32\RegSrvc.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\ZCfgSvc.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\SYSTEM32\wscript.exe
            C:\WINDOWS\system32\1XConfig.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Apoint\Apoint.exe
            C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
            C:\WINDOWS\system32\BacsTray.exe
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\Program Files\Dell\QuickSet\quickset.exe
            C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
            C:\Program Files\Apoint\Apntex.exe
            C:\WINDOWS\system32\dla\tfswctrl.exe
            C:\Program Files\Dell\Media Experience\DMXLauncher.exe
            C:\Program Files\Real\RealPlayer\RealPlay.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\QuickTime\QTTask.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Fichiers communs\AOL\Screensaver\ygpsstra.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\Digital Line Detect\DLG.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
            C:\WINDOWS\system32\wscntfy.exe
            C:\Program Files\Trend Micro\HijackThis\eden.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Travaillez plus.com
            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.dell.com/en-ca
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Au travail !Arrêtez de surfer!
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
            F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\userinit.exe,C:\WINDOWS\SYSTEM32\wscript.exe C:\WINDOWS\SYSTEM32\antinul.vbe
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
            O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
            O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
            O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
            O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
            O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
            O4 - HKLM\..\Run: [bacstray] BacsTray.exe
            O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
            O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
            O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
            O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
            O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
            O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
            O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [Ecran de veille] C:\Program Files\Fichiers communs\AOL\Screensaver\ygpsstra.exe
            O4 - HKCU\..\Run: [MoodBook] "C:\Program Files\MoodBook\mb.exe" /startup
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: Digital Line Detect.lnk = ?
            O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
            O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Gautier
            O17 - HKLM\Software\..\Telephony: DomainName = Gautier
            O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Gautier
            O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Gautier
            O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
            O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
            O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
            O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
            O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
            O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
            O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
            O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
            O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
            O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
            0
            1. Alors comme demandé ligne 2 en mode sans echec , je colle le rapport :
              SmitFraudFix v2.367

              Rapport fait à 15:24:13,83, 27/10/2008
              Executé à partir de C:\Documents and Settings\Kieffer\Bureau\SmitfraudFix
              OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
              Le type du système de fichiers est NTFS
              Fix executé en mode sans echec

              »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll

              »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

              »»»»»»»»»»»»»»»»»»»»»»»» hosts

              127.0.0.1 localhost

              »»»»»»»»»»»»»»»»»»»»»»»» VACFix

              VACFix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

              S!Ri's WS2Fix: LSP not Found.

              »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

              GenericRenosFix by S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

              »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

              IEDFix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

              404Fix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

              AntiXPVSTFix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» RK

              »»»»»»»»»»»»»»»»»»»»»»»» DNS

              HKLM\SYSTEM\CCS\Services\Tcpip\..\{9242BB59-CB16-499F-B59F-6FEE36A523ED}: DhcpNameServer=192.168.1.1
              HKLM\SYSTEM\CS1\Services\Tcpip\..\{9242BB59-CB16-499F-B59F-6FEE36A523ED}: DhcpNameServer=192.168.1.1
              HKLM\SYSTEM\CS2\Services\Tcpip\..\{9242BB59-CB16-499F-B59F-6FEE36A523ED}: DhcpNameServer=192.168.1.1
              HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
              HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
              HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

              »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
              "System"=""

              »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

              Nettoyage terminé.

              »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll

              »»»»»»»»»»»»»»»»»»»»»»»» Fin

              apres cela : mode normal et le rapport demandé

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 15:37:32, on 27/10/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16735)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\S24EvMon.exe
              C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
              C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
              C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
              C:\WINDOWS\system32\RegSrvc.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\ZCfgSvc.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\SYSTEM32\wscript.exe
              C:\WINDOWS\system32\1XConfig.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Apoint\Apoint.exe
              C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
              C:\WINDOWS\system32\BacsTray.exe
              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              C:\Program Files\Dell\QuickSet\quickset.exe
              C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
              C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
              C:\Program Files\Apoint\Apntex.exe
              C:\WINDOWS\system32\dla\tfswctrl.exe
              C:\Program Files\Dell\Media Experience\DMXLauncher.exe
              C:\Program Files\Real\RealPlayer\RealPlay.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\QuickTime\QTTask.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Fichiers communs\AOL\Screensaver\ygpsstra.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\Program Files\Digital Line Detect\DLG.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
              C:\WINDOWS\system32\wscntfy.exe
              C:\Program Files\Trend Micro\HijackThis\eden.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Travaillez plus.com
              R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.dell.com/en-ca
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Au travail !Arrêtez de surfer!
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
              F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\userinit.exe,C:\WINDOWS\SYSTEM32\wscript.exe C:\WINDOWS\SYSTEM32\antinul.vbe
              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
              O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
              O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
              O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
              O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
              O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
              O4 - HKLM\..\Run: [bacstray] BacsTray.exe
              O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
              O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
              O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
              O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
              O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
              O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
              O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
              O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [Ecran de veille] C:\Program Files\Fichiers communs\AOL\Screensaver\ygpsstra.exe
              O4 - HKCU\..\Run: [MoodBook] "C:\Program Files\MoodBook\mb.exe" /startup
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - Global Startup: Digital Line Detect.lnk = ?
              O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
              O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Gautier
              O17 - HKLM\Software\..\Telephony: DomainName = Gautier
              O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Gautier
              O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Gautier
              O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
              O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
              O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
              O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
              O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
              O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
              O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
              O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
              O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
              O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
              O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
              O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
              O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
              0
              1. voila le rapport...

                [b]SDFix: Version 1.238 [/b]
                Run by Kieffer on 27/10/2008 at 16:00

                Microsoft Windows XP [version 5.1.2600]
                Running From: C:\SDFix

                [b]Checking Services [/b]:

                Restoring Default Security Values
                Restoring Default Hosts File

                Rebooting

                [b]Checking Files [/b]:

                Trojan Files Found:

                C:\WINDOWS\SYSTEM32\TASKKILL.EXE - Deleted
                C:\WINDOWS\system32\taskkill.com - Deleted

                Removing Temp Files

                [b]ADS Check [/b]:

                [b]Final Check [/b]:

                catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-10-27 16:20:49
                Windows 5.1.2600 Service Pack 3 NTFS

                scanning hidden processes ...

                scanning hidden services & system hive ...

                scanning hidden registry entries ...

                scanning hidden files ...

                scan completed successfully
                hidden processes: 0
                hidden services: 0
                hidden files: 0

                [b]Remaining Services [/b]:

                Authorized Application Key Export:

                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                "C:\\Program Files\\Messenger\\MSMSGS.EXE"="C:\\Program Files\\Messenger\\MSMSGS.EXE:*:Enabled:Windows Messenger"
                "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
                "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                "C:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"="C:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe:*:Enabled:Sony Ericsson Media Manager 1.0"
                "C:\\Documents and Settings\\Kieffer\\Bureau\\Counter-Strike Source\\hl2.exe"="C:\\Documents and Settings\\Kieffer\\Bureau\\Counter-Strike Source\\hl2.exe:*:Enabled:hl2"
                "C:\\Program Files\\Pro Evolution Soccer 2008\\PES2008.exe"="C:\\Program Files\\Pro Evolution Soccer 2008\\PES2008.exe:*:Enabled:Pro Evolution Soccer 2008"
                "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

                [b]Remaining Files [/b]:

                File Backups: - C:\SDFix\backups\backups.zip

                [b]Files with Hidden Attributes [/b]:

                Tue 25 Apr 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
                Sat 26 Apr 2008 32,768 ...H. --- "C:\Documents and Settings\Kieffer\Bureau\~WRL1037.tmp"
                Thu 2 Oct 2008 29,184 ...H. --- "C:\Documents and Settings\Kieffer\Bureau\~WRL2468.tmp"
                Tue 19 Feb 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
                Thu 9 Oct 2008 81,448,803 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\download\BIT32.tmp"

                [b]Finished![/b]
                0
                1. reposte un log hijackthis stp
                  0
                  1. Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 16:32:30, on 27/10/2008
                    Platform: Windows XP SP3 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\S24EvMon.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                    C:\WINDOWS\system32\RegSrvc.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                    C:\WINDOWS\system32\ZCfgSvc.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\SYSTEM32\wscript.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\1XConfig.exe
                    C:\Program Files\Apoint\Apoint.exe
                    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                    C:\Program Files\Apoint\Apntex.exe
                    C:\WINDOWS\system32\BacsTray.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    C:\Program Files\Dell\QuickSet\quickset.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                    C:\WINDOWS\system32\dla\tfswctrl.exe
                    C:\Program Files\Dell\Media Experience\DMXLauncher.exe
                    C:\Program Files\Real\RealPlayer\RealPlay.exe
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\Program Files\iPod\bin\iPodService.exe
                    C:\Program Files\QuickTime\QTTask.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Fichiers communs\AOL\Screensaver\ygpsstra.exe
                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    C:\Program Files\Digital Line Detect\DLG.exe
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                    C:\Program Files\Windows Live\Messenger\usnsvc.exe
                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                    C:\Program Files\Trend Micro\HijackThis\eden.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Travaillez plus.com
                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.dell.com/en-ca
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Au travail !Arrêtez de surfer!
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                    F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\userinit.exe,C:\WINDOWS\SYSTEM32\wscript.exe C:\WINDOWS\SYSTEM32\antinul.vbe
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
                    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                    O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                    O4 - HKLM\..\Run: [bacstray] BacsTray.exe
                    O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
                    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
                    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                    O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
                    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                    O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
                    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
                    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [Ecran de veille] C:\Program Files\Fichiers communs\AOL\Screensaver\ygpsstra.exe
                    O4 - HKCU\..\Run: [MoodBook] "C:\Program Files\MoodBook\mb.exe" /startup
                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O4 - Global Startup: Digital Line Detect.lnk = ?
                    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
                    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Gautier
                    O17 - HKLM\Software\..\Telephony: DomainName = Gautier
                    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Gautier
                    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Gautier
                    O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
                    O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
                    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
                    O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
                    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
                    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
                    0
                    1. bon passons au chose sérieuse

                      A LIRE JUSQU'EN BAS

                      Télécharges ComboFix à partir d'un de ces liens :
                      En premier
                      http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                      http://www.geekstogo.com/forum/files/file/197-combofix-by-subs/

                      A lire
                      https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                      Et important, enregistre le sur le bureau.

                      Avant d'utiliser ComboFix :

                      ? Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

                      ? Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

                      Une fois fait, sur ton bureau double-clic sur Combofix.exe.

                      - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

                      /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

                      - En fin de scan il est possible que ComboFix ait besoin de redémarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

                      - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

                      ? Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

                      ? Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
                      0
                      1. shion-ares, le lundi 27 octobre 2008 à 16:36:42bon passons au chose sérieuse ?
                        peux tu m'expliquer un peu ceque tume fais faire? penses tu que j'ai une solution pr ce virus qui me dit au travail! arretez de surfer!?
                        tu ne connais pas de precedant?
                        dsl mais bon j'ai l'impression que je te livre tt mon ordi par ces manip?
                        di moi en plus stp
                        0
                        1. bien sur voici la ligne qui pose probleme

                          F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\userinit.exe,C:\WINDOWS\SYSTEM3­2\wscript.exe C:\WINDOWS\SYSTEM32\antinul.vbe

                          malgre les deux fix passé qui au passage a trouvé des saloperies la ligne reste toujours

                          dsl mais bon j'ai l'impression que je te livre tt mon ordi par ces manip?
                          et ne t'inquiete pas je ne suis pas la pour espionner mais pour aider
                          0
                          1. voila le rapport de combo fix
                            ComboFix 08-10-26.01 - Kieffer 2008-10-27 17:00:22.1 - NTFSx86
                            Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.308 [GMT 1:00]
                            * Un nouveau point de restauration a été créé

                            [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
                            .

                            (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                            .

                            C:\Program Files\outlook
                            C:\WINDOWS\system32\bszip.dll
                            C:\WINDOWS\system32\drivers\fad.sys
                            C:\WINDOWS\system32\MSINET.oca

                            .
                            ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                            .

                            -------\Legacy_BOONTY_GAMES
                            -------\Service_Boonty Games

                            ((((((((((((((((((((((((((((( Fichiers créés du 2008-09-27 au 2008-10-27 ))))))))))))))))))))))))))))))))))))
                            .

                            2008-10-27 15:59 . 2008-10-27 15:59 579,584 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\user32.dll
                            2008-10-27 15:57 . 2008-10-27 15:57 <REP> d-------- C:\WINDOWS\ERUNT
                            2008-10-27 15:51 . 2008-10-27 16:24 <REP> d-------- C:\SDFix
                            2008-10-27 15:35 . 2008-10-27 15:35 <REP> d-------- C:\Program Files\Trend Micro
                            2008-10-27 14:56 . 2008-10-27 15:24 3,526 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
                            2008-10-27 14:55 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\SYSTEM32\VCCLSID.exe
                            2008-10-27 14:55 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\SYSTEM32\SrchSTS.exe
                            2008-10-27 14:55 . 2008-09-08 22:38 88,576 --a------ C:\WINDOWS\SYSTEM32\AntiXPVSTFix.exe
                            2008-10-27 14:55 . 2008-10-01 14:51 87,552 --a------ C:\WINDOWS\SYSTEM32\VACFix.exe
                            2008-10-27 14:55 . 2008-10-10 07:58 82,944 --a------ C:\WINDOWS\SYSTEM32\o4Patch.exe
                            2008-10-27 14:55 . 2008-05-18 20:40 82,944 --a------ C:\WINDOWS\SYSTEM32\IEDFix.exe
                            2008-10-27 14:55 . 2008-10-10 07:58 82,944 --a------ C:\WINDOWS\SYSTEM32\IEDFix.C.exe
                            2008-10-27 14:55 . 2008-08-18 11:19 82,432 --a------ C:\WINDOWS\SYSTEM32\404Fix.exe
                            2008-10-27 14:55 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\SYSTEM32\Process.exe
                            2008-10-27 14:55 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\SYSTEM32\dumphive.exe
                            2008-10-27 14:55 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\SYSTEM32\WS2Fix.exe
                            2008-10-26 11:23 . 2008-10-26 11:23 <REP> d-------- C:\Program Files\MSECache
                            2008-10-25 18:34 . 2008-10-15 17:35 337,408 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\netapi32.dll
                            2008-10-20 21:56 . 2008-10-20 21:57 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                            2008-10-20 21:56 . 2008-10-20 21:56 <REP> d-------- C:\Documents and Settings\Kieffer\Application Data\Malwarebytes
                            2008-10-20 21:56 . 2008-10-20 21:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                            2008-10-20 21:56 . 2008-10-16 20:25 38,496 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys
                            2008-10-20 21:56 . 2008-10-16 20:25 15,504 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
                            2008-10-20 21:29 . 2008-10-20 21:30 44,032 --ahs---- C:\WINDOWS\Thumbs.db
                            2008-10-20 20:26 . 2008-10-20 20:26 <REP> d-------- C:\Program Files\Avira
                            2008-10-20 20:26 . 2008-10-20 20:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
                            2008-10-18 17:27 . 2008-08-14 14:23 2,191,232 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ntoskrnl.exe
                            2008-10-18 17:27 . 2008-08-14 14:23 2,147,328 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ntkrnlmp.exe
                            2008-10-18 17:27 . 2008-08-14 14:23 2,068,096 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ntkrnlpa.exe
                            2008-10-18 17:27 . 2008-08-14 14:23 2,025,984 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ntkrpamp.exe
                            2008-10-18 17:26 . 2008-09-08 11:41 333,824 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\srv.sys
                            2008-10-18 17:25 . 2008-09-15 16:26 1,846,528 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\win32k.sys
                            2008-10-16 12:49 . 2008-10-16 12:49 <REP> d-------- C:\WINDOWS\SYSTEM32\fr
                            2008-10-16 12:49 . 2008-10-16 12:49 <REP> d-------- C:\WINDOWS\SYSTEM32\bits
                            2008-10-16 12:49 . 2008-10-16 12:49 <REP> d-------- C:\WINDOWS\l2schemas
                            2008-10-16 12:44 . 2008-10-16 12:49 <REP> d-------- C:\WINDOWS\ServicePackFiles
                            2008-10-16 12:35 . 2008-10-16 12:35 <REP> d-------- C:\WINDOWS\EHome
                            2008-10-14 19:34 . 2008-10-14 20:07 <REP> d-------- C:\Program Files\Pro Evolution Soccer 2008
                            2008-10-12 18:10 . 2004-08-04 00:38 327,168 --------- C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtaa.sys
                            2008-10-09 14:12 . 2008-10-09 14:12 13,036 -rahs---- C:\WINDOWS\SYSTEM32\antinul.vbe

                            .
                            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                            .
                            2008-10-27 16:10 9,213,984 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
                            2008-10-27 16:06 108,956 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
                            2008-10-27 14:34 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
                            2008-09-28 19:26 --------- d-----w C:\Documents and Settings\Kieffer\Application Data\dvdcss
                            2008-09-15 19:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
                            2008-09-13 16:16 --------- d-----w C:\Program Files\Ubisoft
                            2008-09-11 23:14 --------- d-----w C:\Program Files\Creative
                            2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
                            2006-07-31 09:52 4,096 ----a-w C:\Documents and Settings\Kieffer\log.dat
                            .

                            ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                            .
                            .
                            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                            REGEDIT4

                            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
                            "Ecran de veille"="C:\Program Files\Fichiers communs\AOL\Screensaver\ygpsstra.exe" [2004-03-12 99456]
                            "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-23 68856]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            "Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-08-21 155648]
                            "SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 32881]
                            "PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-05-28 86016]
                            "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 339968]
                            "Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2004-10-07 610304]
                            "ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2004-02-06 70800]
                            "URLLSTCK.exe"="C:\Program Files\Norton Internet Security\UrlLstCk.exe" [2004-01-27 70760]
                            "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-08-13 122939]
                            "UpdateManager"="C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
                            "DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2004-09-15 86016]
                            "RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-02-03 26112]
                            "Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2006-02-18 95960]
                            "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-02-23 278528]
                            "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-12-13 919016]
                            "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 286720]
                            "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
                            "bacstray"="BacsTray.exe" [2003-05-14 C:\WINDOWS\SYSTEM32\BacsTray.exe]

                            [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                            "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]

                            C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                            Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-02-03 24576]

                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
                            2004-01-12 07:55 110592 C:\WINDOWS\SYSTEM32\LgNotify.dll

                            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                            "DisableMonitoring"=dword:00000001

                            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                            "DisableMonitoring"=dword:00000001

                            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
                            "DisableMonitoring"=dword:00000001

                            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                            "EnableFirewall"= 0 (0x0)

                            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                            "%windir%\\system32\\sessmgr.exe"=
                            "C:\\Program Files\\Messenger\\MSMSGS.EXE"=
                            "C:\\Program Files\\iTunes\\iTunes.exe"=
                            "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                            "C:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
                            "C:\\Program Files\\Pro Evolution Soccer 2008\\PES2008.exe"=
                            "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                            "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

                            S1 lusbaudio;Microphone USB Logitech;C:\WINDOWS\system32\drivers\OVSound2.sys [2001-08-17 25216]
                            S3 b61d0504-8f58-4d3a-bd0e-8b4175d5bce3;b61d0504-8f58-4d3a-bd0e-8b4175d5bce3;D:\Player\cds300.dll [ ]
                            S3 ovt530;Webcam Classic;C:\WINDOWS\system32\Drivers\ov530vid.sys [2005-03-15 161792]
                            S3 QCEmerald;QuickCam Web Logitech;C:\WINDOWS\system32\DRIVERS\OVCE.sys [2001-08-17 31872]

                            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3bc06250-3544-11dd-a6a4-00114369262e}]
                            \Shell\AutoRun\command - E:\Install.exe

                            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{93c39f3c-9b7a-11dd-98ce-000cf15bdc9a}]
                            \Shell\AutoRun\command - wscript.exe antinul.vbe
                            \Shell\open\Command - wscript.exe antinul.vbe

                            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9ef49df3-8e60-11dd-98b9-00114369262e}]
                            \Shell\AutoRun\command - wscript.exe antinul.vbe
                            \Shell\open\Command - wscript.exe antinul.vbe
                            .
                            Contenu du dossier 'Tâches planifiées'

                            2008-09-30 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
                            - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]

                            2006-01-17 C:\WINDOWS\Tasks\Norton AntiVirus - Analyser mon ordinateur - Kieffer.job
                            - C:\PROGRA~1\NORTON~1\NORTON~1\NAVW32.EXE [2003-12-04 20:06]

                            2008-09-12 C:\WINDOWS\Tasks\Norton AntiVirus - Analyser mon ordinateur.job
                            - C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe [2003-12-04 20:06]

                            2005-02-09 C:\WINDOWS\Tasks\Rappel d'abonnement 1 auprès de l'ISP.job
                            - C:\WINDOWS\system32\OOBE\OOBEBALN.EXE [2008-04-14 03:34]

                            2008-10-26 C:\WINDOWS\Tasks\SJGE 161008.job
                            - C:\Documents and Settings\Kieffer\Bureau\SJGE 161008.doc []

                            2006-05-21 C:\WINDOWS\Tasks\Symantec NetDetect.job
                            - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE [2003-09-09 14:39]
                            .
                            - - - - ORPHELINS SUPPRIMES - - - -

                            HKCU-Run-MoodBook - C:\Program Files\MoodBook\mb.exe

                            .
                            ------- Examen supplémentaire -------
                            .
                            FireFox -: Profile - C:\Documents and Settings\Kieffer\Application Data\Mozilla\Firefox\Profiles\jpj92r9i.default\
                            FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
                            FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
                            .

                            **************************************************************************

                            catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                            Rootkit scan 2008-10-27 17:09:39
                            Windows 5.1.2600 Service Pack 3 NTFS

                            Recherche de processus cachés ...

                            Recherche d'éléments en démarrage automatique cachés ...

                            Recherche de fichiers cachés ...

                            Scan terminé avec succès
                            Fichiers cachés: 0

                            **************************************************************************
                            .
                            --------------------- DLLs chargées dans les processus actifs ---------------------

                            PROCESSUS: C:\WINDOWS\system32\winlogon.exe
                            -> C:\WINDOWS\system32\Ati2evxx.dll
                            .
                            ------------------------ Autres processus actifs ------------------------
                            .
                            C:\WINDOWS\SYSTEM32\ati2evxx.exe
                            C:\WINDOWS\SYSTEM32\S24EvMon.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\CCPROXY.EXE
                            C:\WINDOWS\SYSTEM32\RegSrvc.exe
                            C:\WINDOWS\SYSTEM32\ZCfgSvc.exe
                            C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
                            C:\WINDOWS\SYSTEM32\1XConfig.exe
                            C:\WINDOWS\SYSTEM32\ati2evxx.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\Security Center\symwsc.exe
                            C:\Program Files\Apoint\ApntEx.exe
                            C:\Program Files\iPod\bin\iPodService.exe
                            .
                            **************************************************************************
                            .
                            Heure de fin: 2008-10-27 17:17:01 - La machine a redémarré
                            ComboFix-quarantined-files.txt 2008-10-27 16:16:51

                            Avant-CF: 1,180,467,200 octets libres
                            Après-CF: 1,148,747,776 octets libres

                            197 --- E O F --- 2008-10-26 23:11:30
                            0
                            1. je regarde

                              1- Rends toi sur ce site :

                              https://www.virustotal.com/gui/

                              Copies ce qui suit et colles le dans l'espace pour la recherche :

                              C:\WINDOWS\SYSTEM32\AntiXPVSTFix.exe

                              Cliques sur Send File.

                              Un rapport va s'élaborer ligne à ligne.

                              Attends bien la fin ... Il doit comprendre la taille du fichier envoyé.

                              Sauvegarde le rapport avec le bloc-note.

                              Copies le dans ta prochaine réponse ...

                              ( Si VirusTotal indique que le fichier a déjà été analysé, clique sur le bouton Ré-analyse le fichier maintenant )

                              ---> postes moi donc le rapport ( en précisant bien au début de chacuns à quel fichier ils correspondent ) et attends la suite
                              ou sinon copie les liens et poste les stp...
                              0
                              1. Fichier AntiXPVSTFix.exe reçu le 2008.10.27 17:35:38 (CET)
                                Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE

                                Résultat: 4/36 (11.12%)
                                en train de charger les informations du serveur...
                                Votre fichier est dans la file d'attente, en position: 3.
                                L'heure estimée de démarrage est entre 50 et 71 secondes.
                                Ne fermez pas la fenêtre avant la fin de l'analyse.
                                L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
                                Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
                                Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
                                les résultats seront affichés au fur et à mesure de leur génération.
                                Formaté Impression des résultats
                                Votre fichier a expiré ou n'existe pas.
                                Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

                                Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
                                Email:

                                Antivirus Version Dernière mise à jour Résultat
                                AhnLab-V3 2008.10.27.3 2008.10.27 -
                                AntiVir 7.9.0.9 2008.10.27 -
                                Authentium 5.1.0.4 2008.10.27 -
                                Avast 4.8.1248.0 2008.10.27 -
                                AVG 8.0.0.161 2008.10.27 -
                                BitDefender 7.2 2008.10.27 -
                                CAT-QuickHeal 9.50 2008.10.27 -
                                ClamAV 0.93.1 2008.10.27 -
                                DrWeb 4.44.0.09170 2008.10.27 -
                                eSafe 7.0.17.0 2008.10.26 Suspicious File
                                eTrust-Vet 31.6.6168 2008.10.25 -
                                Ewido 4.0 2008.10.27 -
                                F-Prot 4.4.4.56 2008.10.27 -
                                F-Secure 8.0.14332.0 2008.10.27 -
                                Fortinet 3.113.0.0 2008.10.27 -
                                GData 19 2008.10.27 -
                                Ikarus T3.1.1.44.0 2008.10.27 -
                                K7AntiVirus 7.10.509 2008.10.27 -
                                Kaspersky 7.0.0.125 2008.10.27 -
                                McAfee 5415 2008.10.25 -
                                Microsoft 1.4005 2008.10.27 -
                                NOD32 3560 2008.10.27 -
                                Norman 5.80.02 2008.10.24 -
                                Panda 9.0.0.4 2008.10.27 Suspicious file
                                PCTools 4.4.2.0 2008.10.27 -
                                Prevx1 V2 2008.10.27 -
                                Rising 21.01.02.00 2008.10.27 -
                                SecureWeb-Gateway 6.7.6 2008.10.27 -
                                Sophos 4.35.0 2008.10.27 Sus/Behav-1004
                                Sunbelt 3.1.1753.1 2008.10.25 -
                                Symantec 10 2008.10.27 -
                                TheHacker 6.3.1.1.131 2008.10.27 -
                                TrendMicro 8.700.0.1004 2008.10.27 -
                                VBA32 3.12.8.8 2008.10.27 BackDoor.IRC.Dosig.15
                                ViRobot 2008.10.27.1438 2008.10.27 -
                                VirusBuster 4.5.11.0 2008.10.27 -
                                Information additionnelle
                                File size: 88576 bytes
                                MD5...: bf1bbf73f1006530cc388a84122f1902
                                SHA1..: 539d988b428d8d2da074ae40ff8801a40d0338a3
                                SHA256: a918aa3b0fcd4e6a165e011df60a11e24021c839216354d23055f35999a6a73e
                                SHA512: 35060e1f209d8af25597cd80b602e708c7727a493e5cb88a209d0dc8281039e9
                                aa2b49c99f15d139b47dd2f12858fcec7c57c46e72a8050bd072bbeb51fd282a
                                PEiD..: -
                                TrID..: File type identification
                                UPX compressed Win32 Executable (39.5%)
                                Win32 EXE Yoda's Crypter (34.3%)
                                Win32 Executable Generic (11.0%)
                                Win32 Dynamic Link Library (generic) (9.8%)
                                Generic Win/DOS Executable (2.5%)
                                PEInfo: PE Structure information

                                ( base data )
                                entrypointaddress.: 0x4f4040
                                timedatestamp.....: 0x48c59b6f (Mon Sep 08 21:38:55 2008)
                                machinetype.......: 0x14c (I386)

                                ( 3 sections )
                                name viradd virsiz rawdsiz ntrpy md5
                                UPX0 0x1000 0xde000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
                                UPX1 0xdf000 0x16000 0x15200 7.91 160e013ed511ccddbfe53d401042b227
                                .rsrc 0xf5000 0x1000 0x600 2.85 97f40ad590e77edc941a106123761cf5

                                ( 4 imports )
                                > KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
                                > ADVAPI32.DLL: RegCloseKey
                                > msvcrt.dll: _iob
                                > SHELL32.DLL: ShellExecuteA

                                ( 0 exports )

                                packers (Kaspersky): PE_Patch.UPX, UPX
                                packers (F-Prot): UPX
                                0
                                1. ok

                                  reposte un log hijackthis
                                  0
                                  1. bonjour

                                    apres verification cette ligne est saine

                                    F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\userinit.exe,C:\WINDOWS\SYSTEM3­2\wscript.exe C:\WINDOWS\SYSTEM32\antinul.vbe

                                    * Tout d abord a propos de Boonty games

                                    Utilises tu des jeux de boonty games depuis longtemps ?

                                    Voici une petite information sur Boonty games

                                    Leur politique :

                                    "Il se peut que nous partageons aussi des informations payantes avec des tiers
                                    qui fournissent ds services payants et partage des données regroupées montrant le type
                                    et le nombre de jeux videos que vous téléchargez, votre age, votre sexe, vos occupations,
                                    niveau d'éducation, localité géographique, données sur l'équipement de votre ordinateur,
                                    internet et intérêts pour les jeux videos, activités et entrainement des jeux édités.
                                    De plus, nous partageons les adresses email avec des tiers fournisseurs de compte mails
                                    qui nous assistent en envoyant nos mails a de nombreux clients en même temps..."

                                    si tu es d'accord avec eux, pas de problèmes sinon, il faut désintaller le service en allant dans

                                    (démarrer / exécuter / tape services.msc ) recherche le service, clique droit / propriétés et dans type de demarrage tu mets sur désactivé et tu valide puis ok .

                                    Lance une recherche Boonty et supprime tout.
                                    0
                                    1. Ca a l'air d'être ce fichier antinul.vbe qui fout la merde...
                                      Etant aussi sous Ubuntu, j'ai pu le voir passer de pc en clé en pc etc.... et Hijackthis ne marche pas à tous les coups , et ça mystère et boule de gomme.

                                      Donc j'ai essayé de le gicler en passant par là...

                                      Voici une méthode qui vaut ce qu'elle vaut mais pour l'instant je n'ai plus de message. Après, si vous pensez que c'est une connerie dites le moi.
                                      J'ai utilisé Knoppix pour le virer afin de fournir une possibilité accessible à tous. C'est du pas à pas donc ca devrait le faire ^^

                                      Suppression du fichier antinul.vbe => généralement C:\WINDOWS\system32\antinul.vbe

                                      Prérequis
                                      - Avoir installé Hijackthis ou connaître les lignes de la base de registre à modifier (perso, je préfère Hijackthis, car ce « virus » bloque l’accès à la base et on est obligé d’utiliser un autre logiciel pour l’atteindre.)
                                      - Télécharger un live CD Knoppix : Utiliser Knoppix comme CD de secours

                                      Mettre la galette de Knoppix
                                      Redémarrer le PC en le bootant sur le CD

                                      Ecran de titre : taper => knoppix lang=fr

                                      Laisser charger…

                                      Arrivée sur le bureau, repérer le DD où se trouve le fichier system32
                                      Normalement hda1 ou hdc1 etc…
                                      Clic gauche, Changer le mode ecriture/lecture, OK (si le DD est indiqué non monté – unmounted – patienter le temps que le syst. finisse de charger).

                                      Aller dans le hdc1 afin de contrôler le chemin du fichier à supprimer (Patienter le temps que tous les fichiers apparaissent). Notez la.
                                      Normalement, le chemin est du type : /media/hdc1/Windows/system32/antinul.vbe

                                      Fermer la fenêtre.

                                      Alt+F2, taper : xterm

                                      Ouverture console, taper : rm –rf /chemin du fichier
                                      Attention, contrôler toujours votre commande !!!!
                                      Valider

                                      AVANT DE QUITTER KNOPPIX PENSEZ A NETTOYER VOS CLES USB AVEC :
                                      Clic droit sur la clé : démonter
                                      Puis dans la console (Alt+F2, xterm): mkfs.vfat –F 32 /dev/nom de la clé

                                      Pour quitter Knoppix, redémarrer le PC. Attendez qu’il vous soit demandé de retirer le CD, et regarder Windows se lancer.

                                      Un message d’erreur Wscript.exe vous accueillera….
                                      Lancer Hijackthis :

                                      Cocher :
                                      R0 – HKCU\Sofware\Microsoft\Internet Explore\Main,Sart Page = Travaillez plus.com
                                      R1 – HKCU\Sofware\Microsoft\Internet Explore\Main,Window Title = Au travail ! arrêtez de surfer !
                                      F2 – Reg :system.ini : user …………C:\WINDOWS\system32\antinul.vbe

                                      Fix Checked

                                      Redémarrer

                                      Un coup d’Hijackthis pour vérifier que les modifs ont été apportées et normalement c’est OK
                                      Plus de message « Au Travail » ^^
                                      Si j’ai oublié qqchose, n’hésitez pas !!!!
                                      0
                                      • 1
                                      • 2