Trojan vundo impossible a supprimé

Bonjour,
Jai le trojan vundo que je supprime avec malware byte anti malware.
Il semble le detecté et le supprimé et tout
tout va bien pendant quelques heure et puis boum le virus réapparait a lors que je navigue tranquillement sur internet ou je chat sur msn peu importe
voici un Hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:59:14, on 2008-12-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {00e1b210-4f27-4fe7-a982-e389079d588c} - C:\WINDOWS\system32\hoyozebo.dll (file missing)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccb7dd84] rundll32.exe "C:\WINDOWS\system32\nulojaka.dll",b
O4 - HKLM\..\Run: [CPMcf84ee18] Rundll32.exe "c:\windows\system32\bovutaja.dll",a
O4 - HKLM\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'postgres')
O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'postgres')
O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O15 - Trusted Zone: http://*.facebook.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - https://sdlc-esd.oracle.com/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab?GroupName=JSC&FilePath=/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab&BHost=javadl.sun.com&File=jinstall-6u10-windows-i586-jc.cab&AuthParam=1580987764_a5235be86e79daca0cfb05ddc36bfbcd&ext=.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: wasyhy.dll c:\windows\system32\nuwemuno.dll C:\WINDOWS\system32\wesepani.dll c:\windows\system32\bovutaja.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\bovutaja.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\bovutaja.dll
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
O24 - Desktop Component 0: (no name) - http://tbn0.google.com/...

--
End of file - 9879 bytes
Configuration: Windows XP
Internet Explorer 7.0

27 réponses

Résumé de la discussion

Infection par le cheval de Troie Vundo qui réapparaît après suppression avec Malwarebytes' Anti-Malware, et qui survient lors de la navigation ou d’échanges sur MSN, alimente une discussion autour de la persistance du malware. Le log HijackThis et les extraits listés montrent des entrées suspectes, des modules et des services qui persistent sous Windows XP SP2, rendant la suppression efficace difficile. Des réponses évoquent l’usage de MBAM et notent que Vundofix est obsolète, recommandant aussi un antivirus, un pare-feu et une mise à jour régulière des signatures avant une analyse prolongée. En complément, des rapports Avira et des indices sur des composants système indésirables illustrent la complexité du nettoyage et suggèrent une approche multi-outils plutôt que l’attente d’un seul outil.

Bobot (l’IA à votre service)
  1. http://leblogdeclaude.blogspot.com/2007/05/procédure-vundofix.html

    solutions complémentaires en usage dans le monde informatique
    un anti virus
    un pare feu
    un anti spyware

    www.malekal.com

    1. que dois-je faire exactement poyr le supprimé,
      jai essayer de fixé ces lignes avec hijackthis mais elle sont revnue
      proposé moi une démarche et je la suivré a la lettre
      1. http://leblogdeclaude.blogspot.com/2007/05/procédure-vundofi­x.html
        1. tu as le programme et un tuto, alors exécution

          post le rapport et tes conclusions
          1. Contributeur sécurité
            Salut !

            Vundofix, malheureusement ne sert plus a rien.
            Son concepteur a décidé de ne plus le mettre a jour.

            Pour Vundo, il faut utiliser Malwarebytes' Anti-Malware ( MBAM )

            Sauvegarde ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

            Clic droit sur le bureau => nouveau document => document texte et copi/colle ces instructions que tu porras consulter pour faire la manip' correctement !

            * Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton Bureau.
            S'il manque le fichier COMCTL32.OCX, tu pourras le télécharger ici

            C'est un bon scan passif que tu peux garder avec lequel tu pourras effectuer un nettoyage hebdomadaire, sans oublier de faire une mise à jour manuelle avant d'exécuter l’analyse .

            A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celle-ci.

            * Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

            Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware soient cochées.

            MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue. La fenêtre principale de MBAM s'affiche :

            * Dans l'onglet analyse, vérifie que "Exécuter un examen RAPIDE" soit coché et clique sur le bouton Rechercher pour démarrer l'analyse.

            MBAM analyse ton ordinateur. L'analyse peut prendre un certain temps. Il suffit de vérifier de temps en temps son avancement.

            A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.

            * Si des malwares ont été détectés, leur liste s'affiche.

            Coche tous les éléments détectés par Malwarebytes' Anti-Malware puis clique sur Supprimer la sélection afin d'éradiquer les malwares détectés.
            /!\ (a faire impérativement sous peine de recommencer le scan) /!\ , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

            MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Ferme le Bloc-notes. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

            Ferme MBAM en cliquant sur Quitter.

            Poste le rapport dans ta réponse

            Tutoriel
            Un autre si tu as besoin d'aide.
            1. Voila j'ai faite exactement ce que tu as dit

              Malwarebytes' Anti-Malware 1.30
              Version de la base de données: 1443
              Windows 5.1.2600 Service Pack 2

              2008-12-01 20:21:49
              mbam-log-2008-12-01 (20-21-49).txt

              Type de recherche: Examen complet (A:\|C:\|D:\|E:\|F:\|)
              Eléments examinés: 114296
              Temps écoulé: 19 minute(s), 1 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 3
              Clé(s) du Registre infectée(s): 5
              Valeur(s) du Registre infectée(s): 4
              Elément(s) de données du Registre infecté(s): 2
              Dossier(s) infecté(s): 0
              Fichier(s) infecté(s): 7

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              C:\WINDOWS\system32\vudifina.dll (Trojan.Vundo.H) -> Delete on reboot.
              C:\WINDOWS\system32\tahadevo.dll (Trojan.Vundo) -> Delete on reboot.
              C:\WINDOWS\system32\silahije.dll (Trojan.BHO) -> Delete on reboot.

              Clé(s) du Registre infectée(s):
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00e1b210-4f27-4fe7-a982-e389079d588c} (Trojan.BHO.H) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{00e1b210-4f27-4fe7-a982-e389079d588c} (Trojan.BHO.H) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.

              Valeur(s) du Registre infectée(s):
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.BHO) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpmcf84ee18 (Trojan.Agent) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lafoyagune (Trojan.Agent) -> Quarantined and deleted successfully.

              Elément(s) de données du Registre infecté(s):
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: c:\windows\system32\silahije.dll -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: system32\silahije.dll -> Quarantined and deleted successfully.

              Dossier(s) infecté(s):
              (Aucun élément nuisible détecté)

              Fichier(s) infecté(s):
              C:\WINDOWS\system32\tahadevo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\ovedahat.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\vudifina.dll (Trojan.Vundo.H) -> Delete on reboot.
              C:\WINDOWS\system32\anifiduv.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\hoyozebo.dll (Trojan.BHO.H) -> Delete on reboot.
              c:\WINDOWS\system32\silahije.dll (Trojan.BHO) -> Delete on reboot.
              C:\WINDOWS\system32\kipojamo.dll (Trojan.Agent) -> Delete on reboot.
              1. le Virus en encore revnue peu de temps après que j'ai redémarré l'ordinateur
                Ce n'était pas la premeire fois que jutilisait malware byte, et chaque fois que j'ai tenté de le supprimé de cette facon le virus est revenu quelques heure après

                il doit avoir un quelques chose qui ramene le virus a chaque fois je ne sait pas quoi
                1. J'ai refait un analyse apres malgré l'absence de symptome et le virus semblais encore la..
                  peu de temps apres la premiere analyse

                  Malwarebytes' Anti-Malware 1.30
                  Version de la base de données: 1445
                  Windows 5.1.2600 Service Pack 2

                  2008-12-02 08:05:07
                  mbam-log-2008-12-02 (08-05-07).txt

                  Type de recherche: Examen rapide
                  Eléments examinés: 76374
                  Temps écoulé: 7 minute(s), 32 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 3
                  Clé(s) du Registre infectée(s): 3
                  Valeur(s) du Registre infectée(s): 5
                  Elément(s) de données du Registre infecté(s): 2
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 5

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  C:\WINDOWS\system32\nulojaka.dll (Trojan.Vundo.H) -> Delete on reboot.
                  C:\WINDOWS\system32\ladahawe.dll (Trojan.Vundo) -> Delete on reboot.
                  C:\WINDOWS\system32\hapameva.dll (Trojan.BHO) -> Delete on reboot.

                  Clé(s) du Registre infectée(s):
                  HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.

                  Valeur(s) du Registre infectée(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ccb7dd84 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.BHO) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpmcf84ee18 (Trojan.Agent) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lafoyagune (Trojan.Agent) -> Quarantined and deleted successfully.

                  Elément(s) de données du Registre infecté(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: c:\windows\system32\hapameva.dll -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: system32\hapameva.dll -> Quarantined and deleted successfully.

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  C:\WINDOWS\system32\ladahawe.dll (Trojan.Vundo.H) -> Delete on reboot.
                  C:\WINDOWS\system32\ewahadal.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\nulojaka.dll (Trojan.Vundo.H) -> Delete on reboot.
                  C:\WINDOWS\system32\akajolun.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  c:\WINDOWS\system32\hapameva.dll (Trojan.BHO) -> Delete on reboot.
                  1. Voici un hijackthis apres les 2 analyse
                    Jespere que vs aurez une solution pour qu'il ne revienne plus

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 08:09:07, on 2008-12-02
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.5730.0013)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
                    C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
                    C:\WINDOWS\system32\igfxtray.exe
                    C:\WINDOWS\system32\hkcmd.exe
                    C:\WINDOWS\system32\igfxpers.exe
                    C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
                    C:\Program Files\Java\jre6\bin\jusched.exe
                    C:\Program Files\Winamp\winampa.exe
                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                    C:\Program Files\DAEMON Tools Lite\daemon.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe
                    C:\Program Files\Java\jre6\bin\jqs.exe
                    C:\Program Files\LogMeIn\x86\RaMaint.exe
                    C:\Program Files\LogMeIn\x86\LogMeIn.exe
                    C:\Program Files\LogMeIn\x86\LMIGuardian.exe
                    C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                    C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                    C:\WINDOWS\system32\NOTEPAD.EXE
                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O2 - BHO: (no name) - {00e1b210-4f27-4fe7-a982-e389079d588c} - C:\WINDOWS\system32\hoyozebo.dll (file missing)
                    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
                    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
                    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                    O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
                    O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
                    O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKLM\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s
                    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    O4 - HKUS\S-1-5-19\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'postgres')
                    O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'postgres')
                    O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
                    O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
                    O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
                    O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                    O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                    O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                    O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                    O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                    O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                    O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                    O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                    O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                    O15 - Trusted Zone: http://*.facebook.com
                    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - https://sdlc-esd.oracle.com/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab?GroupName=JSC&FilePath=/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab&BHost=javadl.sun.com&File=jinstall-6u10-windows-i586-jc.cab&AuthParam=1580987764_a5235be86e79daca0cfb05ddc36bfbcd&ext=.cab
                    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
                    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
                    O20 - AppInit_DLLs: wasyhy.dll c:\windows\system32\nuwemuno.dll C:\WINDOWS\system32\wesepani.dll
                    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                    O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
                    O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
                    O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
                    O24 - Desktop Component 0: (no name) - http://tbn0.google.com/...
                    1. Contributeur sécurité
                      Avec une version XP modifiée, faut pas être étonné.

                      Je te prépare la suite, je reviens.
                      1. Contributeur sécurité
                        Tu n'as aucun antivirus sur le pc !

                        télécharge AVIRA Antivir ( gratuit et performant ) sur le lien suivant.
                        https://www.clubic.com/telecharger-fiche10821-avira-antivir-personal-free-antivirus.html

                        Installe ANTIVIR...
                        TUTO D' installation par Malekal
                        Tuto D'instalation et de mise en Oeuvre
                        Encore un au cas ou...
                        Reconnecte toi, fais les mises à jours Antivir... tu seras mieux protégé !

                        Après l'installation, mets le à jour - si ton firewall fait une alerte.. accepte la connexion.
                        Assure toi qu'Antivir est bien à jour, ( clic droit sur le parapluie => Start Update ) et laisse faire la MàJ.

                        Redémarre en mode sans échec !
                        Pour cela, redémarre l'ordinateur, avant le logo Windows, tapote sur la touche F8, un menu va apparaître, choisis Mode sans échec et appuye sur la touche entrée du clavier.

                        - Ouvre Antivir par le menu Démarrer / Programmes
                        - Cliquez sur l'onglet Scanner.
                        - Sélectionne Manual Selection
                        - Sélectionne le disque C
                        - Lance le scan - Mets en quarantaine tous les éléments détectés.
                        - Une fois le scan terminé Enregistre le rapport.

                        Redémarre en mode normal.

                        Poste le rapport ici.
                        1. Bon j'ai faite l'analyse en mode sans echec avec avira
                          dsl du delais j'ai du recommencé l'analyse trois fois car elle gelais et je suis assez temps ci mais peu importe
                          Apres que j'ai redémarré mon ordinateur apres l'analyse le virus était encore la..
                          A chaque infection signalé j'ai demandé de supprimé
                          Voici le rapport

                          Avira AntiVir Personal
                          Report file date: 3 décembre 2008 12:01

                          Scanning for 1070676 virus strains and unwanted programs.

                          Licensed to: Avira AntiVir PersonalEdition Classic
                          Serial number: 0000149996-ADJIE-0001
                          Platform: Windows XP
                          Windows version: (Service Pack 2) [5.1.2600]
                          Boot mode: Save mode
                          Username: Admin
                          Computer name: XPSP2-7890337B3

                          Version information:
                          BUILD.DAT : 8.2.0.337 16934 Bytes 2008-11-18 13:05:00
                          AVSCAN.EXE : 8.1.4.10 315649 Bytes 2008-11-18 14:21:26
                          AVSCAN.DLL : 8.1.4.0 40705 Bytes 2008-05-26 13:56:40
                          LUKE.DLL : 8.1.4.5 164097 Bytes 2008-06-12 18:44:19
                          LUKERES.DLL : 8.1.4.0 12033 Bytes 2008-05-26 13:58:52
                          ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 2008-10-27 17:30:36
                          ANTIVIR1.VDF : 7.1.0.56 411136 Bytes 2008-11-09 22:57:13
                          ANTIVIR2.VDF : 7.1.0.160 571392 Bytes 2008-11-30 18:01:12
                          ANTIVIR3.VDF : 7.1.0.178 149504 Bytes 2008-12-03 12:35:59
                          Engineversion : 8.2.0.36
                          AEVDF.DLL : 8.1.0.6 102772 Bytes 2008-10-14 16:05:56
                          AESCRIPT.DLL : 8.1.1.15 332156 Bytes 2008-11-11 20:00:07
                          AESCN.DLL : 8.1.1.5 123251 Bytes 2008-11-07 21:06:41
                          AERDL.DLL : 8.1.1.3 438645 Bytes 2008-11-04 19:58:38
                          AEPACK.DLL : 8.1.3.4 393591 Bytes 2008-11-11 15:41:39
                          AEOFFICE.DLL : 8.1.0.30 196986 Bytes 2008-11-07 21:06:41
                          AEHEUR.DLL : 8.1.0.71 1487222 Bytes 2008-11-07 21:06:41
                          AEHELP.DLL : 8.1.2.0 119159 Bytes 2008-12-02 18:01:16
                          AEGEN.DLL : 8.1.1.6 323955 Bytes 2008-12-02 18:01:16
                          AEEMU.DLL : 8.1.0.9 393588 Bytes 2008-10-14 16:05:56
                          AECORE.DLL : 8.1.5.2 172405 Bytes 2008-12-02 18:01:15
                          AEBB.DLL : 8.1.0.3 53618 Bytes 2008-10-14 16:05:56
                          AVWINLL.DLL : 1.0.0.12 15105 Bytes 2008-07-09 14:40:05
                          AVPREF.DLL : 8.0.2.0 38657 Bytes 2008-05-16 15:28:01
                          AVREP.DLL : 8.0.0.2 98344 Bytes 2008-07-31 18:02:15
                          AVREG.DLL : 8.0.0.1 33537 Bytes 2008-05-09 17:26:40
                          AVARKT.DLL : 1.0.0.23 307457 Bytes 2008-02-12 14:29:23
                          AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 2008-06-12 18:27:49
                          SQLITE3.DLL : 3.3.17.1 339968 Bytes 2008-01-22 23:28:02
                          SMTPLIB.DLL : 1.2.0.23 28929 Bytes 2008-06-12 18:49:40
                          NETNT.DLL : 8.0.0.1 7937 Bytes 2008-01-25 18:05:10
                          RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 2008-06-12 19:48:07
                          RCTEXT.DLL : 8.0.52.0 86273 Bytes 2008-06-27 19:34:37

                          Configuration settings for the scan:
                          Jobname..........................: Complete system scan
                          Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                          Logging..........................: low
                          Primary action...................: interactive
                          Secondary action.................: ignore
                          Scan master boot sector..........: on
                          Scan boot sector.................: on
                          Boot sectors.....................: C:,
                          Process scan.....................: on
                          Scan registry....................: on
                          Search for rootkits..............: off
                          Scan all files...................: Intelligent file selection
                          Scan archives....................: on
                          Recursion depth..................: 20
                          Smart extensions.................: on
                          Macro heuristic..................: on
                          File heuristic...................: medium

                          Start of the scan: 3 décembre 2008 12:01

                          The scan of running processes will be started
                          Scan process 'avscan.exe' - '1' Module(s) have been scanned
                          Scan process 'notepad.exe' - '1' Module(s) have been scanned
                          Scan process 'avscan.exe' - '1' Module(s) have been scanned
                          Scan process 'igfxsrvc.exe' - '1' Module(s) have been scanned
                          Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                          Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                          Scan process 'explorer.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'lsass.exe' - '1' Module(s) have been scanned
                          Scan process 'services.exe' - '1' Module(s) have been scanned
                          Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                          Scan process 'csrss.exe' - '1' Module(s) have been scanned
                          Scan process 'smss.exe' - '1' Module(s) have been scanned
                          15 processes with 15 modules were scanned

                          Starting master boot sector scan:
                          Master boot sector HD0
                          [INFO] No virus was found!

                          Start scanning boot sectors:
                          Boot sector 'C:\'
                          [INFO] No virus was found!

                          Starting to scan the registry.
                          The registry was scanned ( '58' files ).

                          Starting the file scan:

                          Begin scan in 'C:\'
                          C:\pagefile.sys
                          [WARNING] The file could not be opened!
                          C:\WINDOWS\system32\wojujive.dll
                          [DETECTION] Is the TR/Spy.Agent.evp Trojan
                          [NOTE] The file was deleted!
                          C:\WINDOWS\system32\drivers\sptd.sys
                          [WARNING] The file could not be opened!

                          End of the scan: 3 décembre 2008 15:20
                          Used time: 3:19:21 Hour(s)

                          The scan has been done completely.

                          4639 Scanning directories
                          303339 Files were scanned
                          1 viruses and/or unwanted programs were found
                          0 Files were classified as suspicious:
                          1 files were deleted
                          0 files were repaired
                          0 files were moved to quarantine
                          0 files were renamed
                          2 Files cannot be scanned
                          303336 Files not concerned
                          3488 Archives were scanned
                          2 Warnings
                          1 Notes
                          1. Contributeur sécurité
                            apparament, Avira l'a supprimé

                            Refais moi un log HJT tout frais stp...

                            Ø Relance Hijackthis en double cliquant sur son raccourci sur le Bureau.
                            Choisis l'option "Do a system scan and save a log file"
                            Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
                            Clique sur "Edition" ->> "Sélectionner tout", puis sur "Edition" ->> Copier" pour copier tout le contenu du rapport ici
                            1. voilà

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 15:52:18, on 2008-12-03
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v7.00 (7.00.5730.0013)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
                              C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
                              C:\Program Files\Java\jre6\bin\jusched.exe
                              C:\Program Files\Winamp\winampa.exe
                              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                              C:\WINDOWS\system32\rundll32.exe
                              C:\Program Files\DAEMON Tools Lite\daemon.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                              C:\Program Files\LogMeIn\x86\RaMaint.exe
                              C:\Program Files\LogMeIn\x86\LogMeIn.exe
                              C:\Program Files\LogMeIn\x86\LMIGuardian.exe
                              C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Program Files\Windows Live\Contacts\wlcomm.exe
                              C:\Program Files\PokerStars\PokerStars.exe
                              C:\Program Files\PokerTracker 3\PokerTracker.exe
                              C:\Program Files\PokerTracker 3\PokerTracker.exe
                              C:\Program Files\PokerTracker 3\PokerTrackerHud.exe
                              C:\Program Files\Internet Explorer\IEXPLORE.EXE
                              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: (no name) - {00e1b210-4f27-4fe7-a982-e389079d588c} - C:\WINDOWS\system32\hoyozebo.dll (file missing)
                              O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
                              O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                              O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
                              O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
                              O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                              O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                              O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                              O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
                              O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
                              O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                              O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                              O4 - HKLM\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s
                              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                              O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
                              O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                              O4 - HKLM\..\Run: [ccb7dd84] rundll32.exe "C:\WINDOWS\system32\dizihupe.dll",b
                              O4 - HKLM\..\Run: [CPMcf84ee18] Rundll32.exe "c:\windows\system32\voyuvofe.dll",a
                              O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
                              O4 - HKUS\S-1-5-19\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'postgres')
                              O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'postgres')
                              O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
                              O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
                              O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
                              O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                              O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                              O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                              O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                              O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                              O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                              O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                              O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                              O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                              O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                              O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                              O15 - Trusted Zone: http://*.facebook.com
                              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                              O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - https://sdlc-esd.oracle.com/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab?GroupName=JSC&FilePath=/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab&BHost=javadl.sun.com&File=jinstall-6u10-windows-i586-jc.cab&AuthParam=1580987764_a5235be86e79daca0cfb05ddc36bfbcd&ext=.cab
                              O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
                              O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
                              O20 - AppInit_DLLs: wasyhy.dll c:\windows\system32\nuwemuno.dll C:\WINDOWS\system32\wesepani.dll c:\windows\system32\voyuvofe.dll
                              O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\voyuvofe.dll
                              O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\voyuvofe.dll
                              O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                              O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                              O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                              O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
                              O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
                              O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                              O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
                              O24 - Desktop Component 0: (no name) - http://tbn0.google.com/...
                              1. Contributeur sécurité
                                Tu es encore infecté.

                                Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
                                Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau.

                                Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
                                comment demarrer en mode sans echec en images
                                Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
                                A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
                                Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
                                Choisis ton compte.

                                Déroule la liste des instructions ci-dessous :

                                * Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
                                * Appuie sur Y pour commencer le processus de nettoyage.
                                Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                                * Appuie sur une touche pour redémarrer le PC.
                                Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                                Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                                * Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
                                Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                                Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum

                                Tuto d'instalation et de mise en oeuvre
                                1. J'ai tenté de faire ce que tu as dit mais ça na pas fonctionner
                                  je suis en mode sans échec et je start sdfix comme tu as écrit
                                  jécrit Y
                                  puis la ça comment en disant start repair search for... en tous cas le message de départ puis ça reste gelé la
                                  j'ai cancelé et reparti plusieur fois donc 2 fois jlé laissé allé plus de 2 heure et rien aucun signe de travail de la part du programme

                                  il doit y avoir un autre programme sinon je réessayerai cette nuit

                                  en passant avira maverti dun virus en disant:
                                  TR/agent.asdn trojan
                                  \system32\vudutowo.dll

                                  si ça peut aidé
                                  et voici un nouveau hijackthis au cas ou

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 21:34:00, on 2008-12-03
                                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v7.00 (7.00.5730.0013)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
                                  C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
                                  C:\WINDOWS\system32\hkcmd.exe
                                  C:\WINDOWS\system32\igfxpers.exe
                                  C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
                                  C:\Program Files\Java\jre6\bin\jusched.exe
                                  C:\Program Files\Winamp\winampa.exe
                                  C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                  C:\Program Files\DAEMON Tools Lite\daemon.exe
                                  C:\WINDOWS\system32\ctfmon.exe
                                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                  C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
                                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                  C:\Program Files\Java\jre6\bin\jqs.exe
                                  C:\Program Files\LogMeIn\x86\RaMaint.exe
                                  C:\Program Files\LogMeIn\x86\LogMeIn.exe
                                  C:\Program Files\LogMeIn\x86\LMIGuardian.exe
                                  C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                                  C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                                  C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                                  C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
                                  C:\Program Files\Java\jre6\bin\jucheck.exe
                                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                  C:\Program Files\Windows Live\Contacts\wlcomm.exe
                                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                  C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  O2 - BHO: (no name) - {00e1b210-4f27-4fe7-a982-e389079d588c} - C:\WINDOWS\system32\hoyozebo.dll (file missing)
                                  O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
                                  O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                  O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                                  O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                                  O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
                                  O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
                                  O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                                  O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                                  O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                                  O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
                                  O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
                                  O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                  O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                  O4 - HKLM\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s
                                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
                                  O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                                  O4 - HKLM\..\Run: [ccb7dd84] rundll32.exe "C:\WINDOWS\system32\dizihupe.dll",b
                                  O4 - HKLM\..\Run: [CPMcf84ee18] Rundll32.exe "c:\windows\system32\voyuvofe.dll",a
                                  O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                  O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
                                  O4 - HKUS\S-1-5-19\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'SERVICE RÉSEAU')
                                  O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
                                  O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'postgres')
                                  O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'postgres')
                                  O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
                                  O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
                                  O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
                                  O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
                                  O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                                  O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                                  O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                                  O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                                  O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                                  O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                                  O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                                  O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                  O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                                  O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                                  O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
                                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                                  O15 - Trusted Zone: http://*.facebook.com
                                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                                  O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - https://sdlc-esd.oracle.com/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab?GroupName=JSC&FilePath=/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab&BHost=javadl.sun.com&File=jinstall-6u10-windows-i586-jc.cab&AuthParam=1580987764_a5235be86e79daca0cfb05ddc36bfbcd&ext=.cab
                                  O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
                                  O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
                                  O20 - AppInit_DLLs: wasyhy.dll c:\windows\system32\nuwemuno.dll C:\WINDOWS\system32\wesepani.dll c:\windows\system32\voyuvofe.dll
                                  O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\voyuvofe.dll
                                  O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\voyuvofe.dll
                                  O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                  O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                  O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                  O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
                                  O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
                                  O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                                  O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                                  O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
                                  O24 - Desktop Component 0: (no name) - http://tbn0.google.com/...
                                  • 1
                                  • 2