Infection : Win32/Heur + Win32/agent.AO

Résolu
Bonjour,
Mon Pc a était infecté par un virus Win32/Junk:Poly d'aprés mes petites connaisances ce virus a téléchager d'autre virus et trojans ...
Quand j'analyse avec Avast il détécte les infections il les supprimes mais lors du redémarage sa revient encore, AVG lui aussi il arrive pas a supprimer, Hijackthis ne détécte meme pas :S, et maintenant g 16 processus nommée svhost.exe éxécuté par le system alors que je n'avais que 6 processus avec se nom.
Besoin de votre aide et merci d'avance :)
Configuration: Windows XP Pro (Service pack 2)
Avast Edition Familial
AVG Professionnel
Internet Explorer 6.0

17 réponses

  1. Merci pour ton aide Chimay. +1 :)
    0
    1. Contributeur sécurité
      pour moi..et pour beaucoup d'autres..c'est
      pour installer Antivir en français

      le tuto

      mais c'est surtout ta manière de surfer sur le net qui est prépondérante

      plus d'info ici
      Prévention & Sécurité sur le net(Format pdf)
      1
      1. J'ai fini kan meme par reformater mon PC, psk la vrm tt les logiciels sont désinfécter et donc ils marchent plus :S
        Mais jte demande aprés ke j'ai formater kel Antivirus Gratuit prendre ?
        0
        1. Contributeur sécurité
          ah bin tant mieux,mais poste les rapports quand même,cette crasse de virut est vachement tenace...
          0
          1. Merci pour ta méthode mon Pc est Clean maintenant :)
            0
            1. Contributeur sécurité
              bon,

              tes dans le caca...

              ---- C:\WINDOWS\system32\reader_s.exe c'est du virut

              avant de continuer ta désinfection,tu dois impérativement faire un scan en ligne pour voir si ton OS est touché!

              virut est un virus polymorphe;n'ouvre plus aucun fichier .exe il serait inmanquablement contaminé

              **désactive ton antivirus, logiciels de protections et logiciels pouvant bloquer les popups (barres Google, barres Yahoo etc..).**

              Ouvre internet explorer --> Outils --> Options internet --> onglet "sécurité" --> Valide "niveau par défaut".
              Toujours sur Internet explorer --> Outils --> Options internet --> onglet "avancé" --> valide "Paramètres par défaut".

              Scan en ligne avec Kaspersky :
              - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr en utilisant Internet Explorer et pas Firefox, ça ne marchera pas!.
              - Si tu es perdu, tu peux suivre l'aide pour les scans en ligne https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId291566

              AIDE : Configurer le contrôle des ActiveX < http://www.inoculer.com/activex.php3 >
              Tuto ici si problème : http://www.vista-xp.fr/forum/topic109.html , ou là : https://forum.pcastuces.com/sujet.asp?f=25&s=37641 (par Morgane & nico_dodo)

              - Au moment de choisir la cible à analyser, clique sur le bouton Paramètres d'analyse
              - Dans la nouvelle fenêtre, coche "étendu" au milieu puis clique sur OK.
              - Choisis le poste de travail dans la cible à analyser
              - Copie/colle le rapport du scan ici

              NOTE : Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner,
              reconnecte-toi sur le site de Kaspersky pour retenter le scan en ligne.

              ensuite

              Va par le panneau de configuration dans Options d'alimentation et mets "jamais" partout; le pc ne DOIT pas se mettre en veille.

              Télécharge le dernier AVP de la liste ( en bas): ftp://ftp.kaspersky.com/devbuilds/AVPTool/ Enregistre-le sur le bureau.

              Tu ne vas pas devoir le surveiller, tu n'as qu'à choisir "Disinfect" et " apply to all" et l'outil poursuivra son travail tout seul pendant que tu dormiras.

              Ne coche surtout pas la case DELETE!!!

              Le scan est plus ou moins long selon la puissance des pc et du nombre de fichiers à analyser.

              Le rapport étant très lourd, tu ne devras poster que le début qui parle des découvertes et traitements effectués.

              Si tu avais un problème avec ce rapport, sauvegarde-le quel que soit son poids, je te donnerai un lien pour l'héberger.

              SCANNER AVEC AVP TOOL

              Le scan va s'effectuer en Mode Sans Echec: comme tu n'auras pas accès à Internet, je te conseille d'imprimer cette procédure.
              Télécharge et enregistre sur ton Bureau le scanner portable AVP TOOL (sélectionne-la à partir des dates) en cliquant sur le lien:
              http://downloads5.kaspersky-labs.com/devbuilds/AVPTool/

              Redémarre en mode sans échec, pour cela, redémarre l'ordinateur, avant le logo Windows, tapote sur la touche F8, un menu va apparaître,
              choisis Mode sans échec et appuye sur la touche entrée du clavier.

              Choisis ton compte.
              Connecte éventuellement tes clés USB et disques externes.

              Lance l'exécutable intitulé "setup_7.0xxxxx" en double-cliquant dessus
              Réponds "Oui" à la question "Do you want to continue installation?"
              Clique sur "Next" pour les deux fenêtres suivantes: AVP TOOL s'installe sur ton Bureau dans un dossier nommé "Kaspersky Lab Tool"
              Si nécessaire, branche tes périphériques amovibles (clés USB, disque dur externe...)
              L'outil se lance tout seul: coche toutes les cases dans l'onglet "Automatic Scan".
              Clique maintenant sur "Security Level": une fenêtre de configuration s'ouvre: paramètre le scanner comme ceci:

              Dans "security level" laisse le curseur sur "Recommended"

              Dans "Action"
              coche "Prompt for action when the scan is complète"
              coche "Disinfect" et "Delete if disinfection fails"

              Dans "Self-defense options"
              coche "Disable external service control"

              Valide avec "Apply" puis "OK"
              L'outil est maintenant configuré: dans la fenêtre principale, clique sur "Scan".
              Le scan commence, une nouvelle fenêtre s'ouvre indiquant la progression du balayage en pourcentage.
              A la fin du scan, AVP Tool signale les objets infectés par l'intermédiaire d'une pop-up: coche alors "Apply to all" et clique sur "Delete" ou "Disinfect" selon ce que propose la fenêtre:

              Une fois les infections traitées par l'intermédiaire des pop-ups, il se peut que des fichiers malsains n'aient pas été supprimés: ils apparaissent en rouge dans la liste: clique alors sur le bouton "Neutralize all" de la fenêtre de progression du scan: si une pop-up indique qu'il faut redémarrer, accepte en cliquant sur "OK"
              Rends-toi maintenant dans l'onglet "Events" de la fenêtre de progression du scan, et décoche "Show all events"
              Clique enfin sur "Reports" puis "Save to file" et enregistre le rapport sur ton Bureau sous le nom Rapport AVP TOOL
              Ferme les fenêtres d'AVP Tool: un message apparaît proposant de désinstaller le logiciel: choisis "YES"

              Un message d'alerte indique que le PC doit être redémarré pour finir la désinstallation:

              A la question "Would you like to restart now", répond "OUI" et redémarre ton ordinateur en Mode normal.
              Poste le contenu du rapport dans ta prochaine réponse

              Un conseil: désinfecte ce qui peut l'être, sinon "Delete".
              NB: l'outil doit être désinstallé quand il le demandera car il ne peut pas rester sur l'ordi; il causerait des conflits.
              0
              1. Logfile of random's system information tool 1.05 (written by random/random)
                Run by MaG at 2009-03-13 14:40:49
                Microsoft Windows XP Professionnel Service Pack 2
                System drive C: has 44 GB (73%) free of 60 GB
                Total RAM: 1012 MB (40% free)

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 14:41:15, on 13/03/2009
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                C:\PROGRA~1\AVG\AVG8\avgemc.exe
                C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                C:\Program Files\AVG\AVG8\avgcsrvx.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\wscntfy.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\AVG\AVG8\avgscanx.exe
                C:\Program Files\AVG\AVG8\avgcsrvx.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Mozilla Firefox\firefox.exe
                C:\Program Files\uTorrent\uTorrent.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Documents and Settings\MaG\Bureau\Anti-Virus\RSIT.exe
                C:\Program Files\Trend Micro\HijackThis\MaG.exe
                C:\Program Files\Internet Download Manager\IDMan.exe

                R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\windres.exe,userinit.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\undname.exe,C:\WINDOWS\system32\ndetect.exe,C:\WINDOWS\system32\codeblocks.exe,C:\WINDOWS\system32\c++.exe,
                O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
                O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\eMule.exe -AutoStart
                O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
                O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
                O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                0
                1. Contributeur sécurité
                  mmmm!

                  poste moi un nouveau rapport rsit stp

                  uniquement log.txt
                  0
                  1. SmitFraudFix v2.403

                    Rapport fait à 14:02:25,12, 13/03/2009
                    Executé à partir de C:\Documents and Settings\MaG\Bureau\Anti-Virus\SmitfraudFix
                    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                    Le type du système de fichiers est NTFS
                    Fix executé en mode sans echec

                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                    127.0.0.1 jL.chura.pl
                    127.0.0.1 localhost

                    »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                    VACFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                    S!Ri's WS2Fix: LSP not Found.

                    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                    GenericRenosFix by S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                    IEDFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

                    Agent.OMZ.Fix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                    404Fix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» RK

                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                    HKLM\SYSTEM\CS2\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                    HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

                    »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    "System"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                    Nettoyage terminé.

                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Fin

                    Hijackthis.log

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 14:13:33, on 13/03/2009
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                    C:\PROGRA~1\AVG\AVG8\avgemc.exe
                    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                    C:\Program Files\AVG\AVG8\avgcsrvx.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\wscntfy.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Program Files\AVG\AVG8\avgscanx.exe
                    C:\Program Files\AVG\AVG8\avgcsrvx.exe
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\windres.exe,userinit.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\undname.exe,C:\WINDOWS\system32\ndetect.exe,C:\WINDOWS\system32\codeblocks.exe,C:\WINDOWS\system32\c++.exe,
                    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
                    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
                    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                    0
                    1. Contributeur sécurité
                      Redémarre l'ordinateur en mode sans échec .
                      Comment aller en Mode sans échec
                      1) Redémarre ton ordi
                      2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                      3) Tu verras un écran avec options de démarrage apparaître
                      4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                      5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
                      ( ps : n'oublies pas , en mode sans échec , pas de connexion ! Donc copie ou imprime bien les infos ci-dessous ...)

                      *Double click sur SmitfraudFix.exe

                      * Sélectionnes 2 et presses "Entrée" dans le menu pour supprimer les fichiers responsables de l'infection.

                      * A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et presse Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection.

                      ( Le correctif déterminera si le fichier wininet.dll est infecté.)

                      * A la question: "Corriger le fichier infecté ?" répondre O (oui) et presser Entrée
                      pour remplacer le fichier corrompu.

                      * Un redémarrage sera peut être nécessaire pour terminer la procédure de nettoyage ( sinon fais le manuellement )

                      Le rapport se trouve à la racine de C\:
                      (dans le fichier "rapport.txt")

                      Poste ce dernier rapport accompagné, dans la même réponse, d'un nouveau rapport hijackthis ( fais en mode normal )
                      0
                      1. <gras>rapport.txt (Smitfraudfix)</gras>

                        SmitFraudFix v2.403

                        Rapport fait à 13:44:04,67, 13/03/2009
                        Executé à partir de C:\Documents and Settings\MaG\Bureau\SmitfraudFix\SmitfraudFix
                        OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                        Le type du système de fichiers est NTFS
                        Fix executé en mode normal

                        »»»»»»»»»»»»»»»»»»»»»»»» Process

                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                        C:\PROGRA~1\AVG\AVG8\avgemc.exe
                        C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                        C:\Program Files\AVG\AVG8\avgcsrvx.exe
                        C:\WINDOWS\system32\wscntfy.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\AVG\AVG8\avgscanx.exe
                        C:\Program Files\AVG\AVG8\avgcsrvx.exe
                        C:\WINDOWS\system32\notepad.exe
                        C:\Program Files\Internet Explorer\IEXPLORE.EXE
                        C:\WINDOWS\system32\cmd.exe

                        »»»»»»»»»»»»»»»»»»»»»»»» hosts

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\MaG

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MaG\LOCALS~1\Temp

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\MaG\Application Data

                        »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MaG\Favoris

                        »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                        »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                        »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                        "Source"="About:Home"
                        "SubscribedURL"="About:Home"
                        "FriendlyName"="Ma page d'accueil"

                        »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        o4Patch
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        Agent.OMZ.Fix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                        "AppInit_DLLs"=""
                        "LoadAppInit_DLLs"=dword:00000001

                        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                        "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,C:\\WINDOWS\\system32\\windres.exe,userinit.exe,C:\\WINDOWS\\system32\\deviceemulator.exe,C:\\WINDOWS\\system32\\undname.exe,C:\\WINDOWS\\system32\\ndetect.exe,C:\\WINDOWS\\system32\\codeblocks.exe,"
                        "System"=""

                        »»»»»»»»»»»»»»»»»»»»»»»» RK

                        »»»»»»»»»»»»»»»»»»»»»»»» DNS

                        Description: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC - Miniport d'ordonnancement de paquets
                        DNS Server Search Order: 192.168.2.1

                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                        HKLM\SYSTEM\CS2\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                        HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                        »»»»»»»»»»»»»»»»»»»»»»»» Fin
                        0
                        1. Report.txt[b]SDFix: Version 1.240 [/b]
                          Run by MaG on 13/03/2009 at 12:16

                          Microsoft Windows XP [version 5.1.2600]
                          Running From: C:\SDFix

                          [b]Checking Services [/b]:

                          [b]Name [/b]:
                          restore

                          [b]Path [/b]:
                          \??\C:\WINDOWS\system32\drivers\restore.sys

                          restore - Deleted

                          Restoring Default Security Values
                          Restoring Default Hosts File

                          Rebooting

                          [b]Checking Files [/b]:

                          Trojan Files Found:

                          C:\WINDOWS\system32\3.tmp - Deleted
                          C:\WINDOWS\system32\4.tmp - Deleted
                          C:\WINDOWS\system32\5.tmp - Deleted
                          C:\WINDOWS\system32\6.tmp - Deleted
                          C:\WINDOWS\system32\7.tmp - Deleted
                          C:\WINDOWS\system32\8.tmp - Deleted
                          C:\WINDOWS\system32\9.tmp - Deleted
                          C:\WINDOWS\system32\A.tmp - Deleted
                          C:\WINDOWS\system32\B.tmp - Deleted
                          C:\WINDOWS\system32\C.tmp - Deleted
                          C:\WINDOWS\system32\D.tmp - Deleted
                          C:\WINDOWS\system32\E.tmp - Deleted
                          C:\WINDOWS\system32\F.tmp - Deleted
                          C:\WINDOWS\system32\10.tmp - Deleted
                          C:\WINDOWS\system32\11.tmp - Deleted
                          C:\WINDOWS\system32\12.tmp - Deleted
                          C:\WINDOWS\services.exe - Deleted

                          Removing Temp Files

                          [b]ADS Check [/b]:

                          [b]Final Check [/b]:

                          catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2009-03-13 13:37:42
                          Windows 5.1.2600 Service Pack 2 NTFS

                          detected NTDLL code modification:
                          ZwOpenFile

                          scanning hidden processes ...

                          scanning hidden services & system hive ...

                          scanning hidden registry entries ...

                          scanning hidden files ...

                          scan completed successfully
                          hidden processes: 0
                          hidden services: 0
                          hidden files: 0

                          [b]Remaining Services [/b]:

                          Authorized Application Key Export:

                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                          "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
                          "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                          "\\??\\C:\\WINDOWS\\system32\\winlogon.exe"="\\??\\C:\\WINDOWS\\system32\\winlogon.exe:*:enabled:@shell32.dll,-1"

                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                          "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

                          [b]Remaining Files [/b]:

                          File Backups: - C:\SDFix\backups\backups.zip

                          [b]Files with Hidden Attributes [/b]:

                          Thu 26 Feb 2009 1,386 ...H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\Colored Flash\colored_flashbangs.sma.bak"
                          Thu 26 Feb 2009 4,302 ...H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\Country Plugin\GHW_connect.sma.bak"
                          Wed 25 Feb 2009 4,033 ...H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\Fire in The Holl Color\descriptive_fire_in_the_hole.sma.bak"
                          Wed 11 Mar 2009 1,768 ...H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\Radio\shamusi_music_plugin.sma.bak"
                          Wed 11 Mar 2009 2,743 ...H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\SpecT List\speclist.sma.bak"
                          Wed 4 Mar 2009 3,767 A..H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\Unstuckin\stuck.sma.bak"
                          Wed 25 Feb 2009 11,984 A..H. --- "C:\Documents and Settings\MaG\Bureau\Plugins\Hats Plugin\Hats08.sma.bak"

                          [b]Finished![/b]
                          0
                          1. Contributeur sécurité
                            bon,y a du taf en vue

                            et ton rapport n'est pas complet

                            Télécharge SDfix (créé par AndyManchesta) et sauvegarde le sur ton Bureau. Tu peux suivre le tutorial SDFix de Malekal pour t'aider :

                            Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
                            Redémarre ton ordinateur
                            Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
                            A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
                            Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
                            Choisis ton compte.

                            Déroule la liste des instructions ci-dessous :
                            Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
                            Appuie sur Y pour commencer le nettoyage.

                            Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                            Appuie sur une touche pour redémarrer le PC.
                            Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                            Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.

                            Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
                            Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                            Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !

                            Si SDFix ne se lance pas
                            Clique sur Démarrer > Exécuter
                            Copie/colle ceci :
                            %systemroot%\system32\cmd.exe /K %systemdrive%\SDFix\apps\FixPath.exe

                            Clique sur Ok.
                            Redémarre et essaie de relance SDFix.

                            ensuite

                            Télécharge SmitFraudfix de S!Ri, balltrap34 et moe31
                            http://siri.urz.free.fr/Fix/SmitfraudFix.zip -
                            en cas de problème avec le premier lien,
                            mirroir: http://72.232.135.12/siri/SmitfraudFix.php

                            voila à quoi cela ressemble : http://siri.urz.free.fr/Fix/SmitfraudFix.php
                            une aide en vidéo (merci à balltrap34)
                            http://pagesperso-orange.fr/rginformatique/section%20virus/smitfraudfix.htm

                            Désactive les logiciels de protections(antivirus et antispyware)
                            -- Fais un clic droit puis Extraire tout sur le fichier SmitfraudFix.zip, cela va tout décompresser dans un nouveau dossier SmitFraudfix
                            -- Ouvre le dossier SmitfraudFix double-clique sur SmitfraudFix.cmd (le .cmd peut ne pas être présent)
                            -- Choisis l'option 1 et appuie sur Entrée
                            -- Réponds o (Oui) aux deux questions suivantes si elles sont posées
                            -- Un rapport sera généré; sauvegarde le dans un dossier.
                            -- Copie/colle le contenu du rapport ici
                            0
                            1. info.txt logfile of random's system information tool 1.05 2009-03-13 11:54:57
                              ======Uninstall list======

                              -->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
                              -->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
                              -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
                              -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
                              -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
                              -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
                              -->C:\WINDOWS\UNRecode.exe /UNINSTALL
                              -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{107254A0-0ADF-11D4-9397-00D0B7020B38}\setup.exe"
                              -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                              7-Zip 4.65-->"C:\Program Files\7-Zip\Uninstall.exe"
                              Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
                              Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
                              Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
                              Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
                              Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
                              Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
                              Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
                              Adobe Color Common Settings-->MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
                              Adobe Color EU Recommended Settings-->MsiExec.exe /I{73B5D990-04EA-4751-B10F-5534770B91F2}
                              Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
                              Adobe Color NA Extra Settings-->MsiExec.exe /I{FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}
                              Adobe Default Language CS3-->MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
                              Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
                              Adobe ExtendScript Toolkit 2-->C:\Program Files\Fichiers communs\Adobe\Installers\3e054d2218e7aa282c2369d939e58ff\Setup.exe
                              Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}
                              Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                              Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                              Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{58BAA8D0-404E-4585-9FD3-ED1BB72AC2EE}
                              Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{685A56F8-75B6-44AD-B3DA-FB0A3266B47C}
                              Adobe Fonts All-->MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
                              Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
                              Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
                              Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
                              Adobe Photoshop CS3-->C:\Program Files\Fichiers communs\Adobe\Installers\32e9033392a51340b32fdc6ad893ab7\Setup.exe
                              Adobe Photoshop CS3-->MsiExec.exe /I{BF794769-8875-4E01-B7BE-E00104604F4A}
                              Adobe Reader 8.1.3-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81300000003}
                              Adobe Setup-->MsiExec.exe /I{926DEB4E-2B0A-4C5C-AE4A-BF6C06949702}
                              Adobe Setup-->MsiExec.exe /I{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}
                              Adobe Shockwave Player 11-->C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
                              Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
                              Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
                              Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
                              Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
                              Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
                              Adobe XMP Panels CS3-->MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
                              AMX Mod X Installer 1.8.1-->C:\Program Files\AMX Mod X\uninst.exe
                              Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                              Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
                              avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
                              AVG 8.0-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
                              CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                              CleanUp!-->C:\Program Files\CleanUp!\uninstall.exe
                              Code de la Route-->MsiExec.exe /X{A37A26D5-8444-4862-933B-478371D0299D}
                              Counter-Strike-->"C:\Program Files\Steam\steam.exe" steam://uninstall/10
                              Decal Converter-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5BB207D6-0E1E-11D5-9B6A-00C04F7EC248}\Setup.exe"
                              DoNaut 2.0.1-->C:\Program Files\Xponaut\DoNaut\uninst.exe
                              eMule-->"C:\Program Files\eMule\Uninstall.exe"
                              FileZilla Client 3.2.2-->C:\Program Files\FileZilla FTP Client\uninstall.exe
                              Half-Life Dedicated Server Update Tool-->E:\HLDS\UNWISE.EXE E:\HLDS\INSTALL.LOG
                              High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
                              HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
                              HLSW v1.3.1-->"C:\Program Files\HLSW\unins000.exe"
                              Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
                              Intel(R) Integrator Toolkit FE-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A67B3991-7226-404B-B5F6-71962D3F2376}\Setup.exe"
                              Internet Download Manager-->C:\Program Files\Internet Download Manager\Uninstall.exe
                              Java(TM) 6 Update 12-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF}
                              la version d'évaluation de Namo WebEdiotor 6-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EF3FA287-2622-4340-AAF6-0AD29F21A691}\setup.exe" -l0x40c
                              Ma-Config.com-->MsiExec.exe /X{8AFB8FC4-3EBA-4C67-943F-CF43DB2180F1}
                              Macromedia Extension Manager-->MsiExec.exe /I{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}
                              Macromedia Flash 8-->MsiExec.exe /I{2BD5C305-1B27-4D41-B690-7A61172D2FEB}
                              Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
                              Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - FRA-->MsiExec.exe /I{3F7924B9-D148-3141-87B1-68F36043A940}
                              Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
                              Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - FRA-->MsiExec.exe /I{511DF669-2930-30C0-8EB6-552887E29EC8}
                              Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
                              Microsoft .NET Framework 3.5 Language Pack - fra-->MsiExec.exe /I{5B76AEA2-D4E5-3B55-B965-ACC36AE0EAFC}
                              Microsoft .NET Framework 3.5-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\setup.exe
                              Microsoft .NET Framework 3.5-->MsiExec.exe /I{2FC099BD-AC9B-33EB-809C-D332E1B27C40}
                              Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
                              Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                              Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
                              mIRC-->C:\Program Files\mIRC\uninstall.exe _?=C:\Program Files\mIRC
                              Module linguistique Microsoft .NET Framework 3.5 - fra-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack - fra\setup.exe
                              Mozilla Firefox (3.0.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                              MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
                              Nero 8 Ultra Edition HD-->MsiExec.exe /X{D6C9AF27-9414-46C8-B9D8-D878BA041036}
                              neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
                              No-IP.com DUC (remove only)-->"C:\Program Files\No-IP\DUC20.exe" -uninstall
                              Pack Vista Inspirat 2 1.0-->C:\WINDOWS\BricoPacks\Vista Inspirat 2\Remove.exe
                              PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
                              PhotoFiltre Studio-->"C:\Program Files\PhotoFiltre Studio\Uninst.exe"
                              QuickTime-->MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
                              REALTEK GbE & FE Ethernet PCI-E NIC Driver-->"C:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe" -runfromtemp -l0x040c -removeonly
                              Realtek High Definition Audio Driver-->RtlUpd.exe -r -m -nrg2709
                              Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
                              SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
                              TeamSpeak Client-->"C:\Program Files\TeamSpeak3\unins000.exe"
                              TrackMania Nations Forever-->"C:\Program Files\Steam\steam.exe" steam://uninstall/11020
                              VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
                              VDownloader 0.77-->"C:\Program Files\VDOWNLOADER\unins000.exe"
                              VLC media player 0.9.2-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                              Wallpachange-->C:\Program Files\Wallpachange\Uninstal.exe
                              WampServer 2.0-->"c:\wamp\unins000.exe"
                              Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
                              Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
                              Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
                              Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
                              Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                              Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                              WinHTTrack Website Copier 3.43-2-->"C:\Program Files\WinHTTrack\unins000.exe"
                              XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
                              Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE

                              =====HijackThis Backups=====

                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                              O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?SearchSource=10&ctid=CT2102473
                              O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
                              O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
                              R3 - URLSearchHook: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHPN.dll
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.fr/?gws_rd=ssl
                              O3 - Toolbar: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHPN.dll
                              O2 - BHO: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHPN.dll
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 91.121.112.151:3128
                              O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                              O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
                              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                              O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 193.55.112.41:3128
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.files-ftp.com/~unicorni/phpBB2/index.php
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
                              O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                              O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
                              O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                              O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
                              O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
                              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O4 - HKCU\..\Run: [DoNaut] "C:\Program Files\Xponaut\DoNaut\DoNaut.exe" --minimized
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 193.55.112.41:3128
                              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                              O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                              O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.32\bin\mysqld.exe
                              O23 - Service: CSIScanner - Prevx - C:\Program Files\Prevx\prevx.exe
                              O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\MaG\reader_s.exe (User 'SYSTEM')
                              O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
                              O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
                              O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
                              O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                              O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
                              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

                              ======Hosts File======

                              127.0.0.1 jL.chura.pl

                              ======Security center information======

                              AV: AVG Anti-Virus
                              AV: avast! antivirus 4.8.1335 [VPS 090312-0] (disabled)

                              ======Environment variables======

                              "ComSpec"=%SystemRoot%\system32\cmd.exe
                              "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
                              "windir"=%SystemRoot%
                              "FP_NO_HOST_CHECK"=NO
                              "OS"=Windows_NT
                              "PROCESSOR_ARCHITECTURE"=x86
                              "PROCESSOR_LEVEL"=6
                              "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 2, GenuineIntel
                              "PROCESSOR_REVISION"=0f02
                              "NUMBER_OF_PROCESSORS"=2
                              "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                              "TEMP"=%SystemRoot%\TEMP
                              "TMP"=%SystemRoot%\TEMP
                              "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
                              "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

                              -----------------EOF-----------------

                              Log.txt =
                              Logfile of random's system information tool 1.05 (written by random/random)
                              Run by MaG at 2009-03-13 11:54:52
                              Microsoft Windows XP Professionnel Service Pack 2
                              System drive C: has 39 GB (65%) free of 60 GB
                              Total RAM: 1012 MB (51% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 11:54:54, on 13/03/2009
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                              C:\Program Files\Java\jre6\bin\jqs.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\PROGRA~1\AVG\AVG8\avgemc.exe
                              C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\AVG\AVG8\avgcsrvx.exe
                              C:\WINDOWS\system32\wbem\wmiapsrv.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\svchost.exe
                              C:\PROGRA~1\AVG\AVG8\avgtray.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\WINDOWS\system32\Restore\rstrui.exe
                              C:\Program Files\AVG\AVG8\avgscanx.exe
                              C:\Program Files\AVG\AVG8\avgcsrvx.exe
                              C:\Program Files\Internet Explorer\IEXPLORE.EXE
                              C:\Documents and Settings\MaG\Bureau\RSIT.exe
                              C:\Program Files\Trend Micro\HijackThis\MaG.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\windres.exe,userinit.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\undname.exe,C:\WINDOWS\system32\ndetect.exe,
                              O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                              O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
                              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
                              O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                              O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
                              O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                              O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                              0
                              1. Contributeur sécurité
                                cela me semble un peu court comme log...!!??

                                Télécharge random's system information tool (RSIT) par random/random et sauvegarde-le sur le Bureau.
                                http://images.malwareremoval.com/random/RSIT.exe
                                Double-clique sur RSIT.exe afin de lancer RSIT.
                                Clique Continue à l'écran Disclaimer.
                                Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
                                Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (<<qui sera affiché)
                                ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).
                                NB : Les rapports sont sauvegardés dans le dossier C:\rsit
                                0
                                1. Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 11:51:00, on 13/03/2009
                                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                  C:\Program Files\Java\jre6\bin\jqs.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\PROGRA~1\AVG\AVG8\avgemc.exe
                                  C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\AVG\AVG8\avgcsrvx.exe
                                  C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                  C:\Program Files\TeamSpeak3\TeamSpeak.exe
                                  C:\WINDOWS\system32\Restore\rstrui.exe
                                  C:\Program Files\AVG\AVG8\avgscanx.exe
                                  C:\Program Files\AVG\AVG8\avgcsrvx.exe
                                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                  C:\Program Files\AVG\AVG8\avgui.exe
                                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                  F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\windres.exe,userinit.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\undname.exe,C:\WINDOWS\system32\ndetect.exe,
                                  O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                  O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                                  O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
                                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                  O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
                                  O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                                  O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
                                  O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                                  O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                  0
                                  1. Contributeur sécurité
                                    Hijackthis ne détécte meme pas :S

                                    colle nous le rapport stp
                                    0