Trojan vundo impo a supprimer

Mon probleme c'est que norton n'arive pas a supprimer le virus Trojan Vundo , j'ai esayer tout les methode , mais je n'arrive pas a le supprimer . Pouvez vous m'aidez . SVP . Car il me remet le message a chaque fois mais rien n'y fait il n'arrive pas a le supprimer , ca commencer a devenir enervant.En plus du virus j'ai aussi un problme de spyware des pubs s'affiche sans cesse.La aussi j'ai essayer beaucoup de methode mais j'arrive pas.

Merci de m'aider.
Configuration: Windows XP
Internet Explorer 7.0

24 réponses

Résumé de la discussion

Un utilisateur lutte contre le Trojan Vundo et des pubs intrusives sous Windows XP, Norton n'arrivant pas à éliminer l'infection et le spyware persistant. Plusieurs solutions proposées incluent le démarrage en mode sans échec, l'usage d'outils spécialisés comme VirtumundoBeGone et SmitfraudFix, puis l'analyse des rapports avec HijackThis. D'autres méthodes évoquées consistent à renommer des exécutables, recueillir des logs, vérifier les paramètres DNS et détruire des fichiers suspects via Killbox ou VirusTotal. Enfin, le corpus de réponses montre des vérifications manuelles des fichiers marqués et la nécessité de redémarrer dans certains cas pour compléter le nettoyage.

Bobot (l’IA à votre service)
  1. En fait j'ai tout les fichiers marqués dans le log supprimer manuellemt puis vider la corbeille.
    Es-ce que c'est bon ?
    0
    1. télécharge clean : http://www.malekal.com/download/clean.zip

      Installe-le sur le bureau et dezippe-le.
      Un dossier clean va être créer double-clique dessus
      Puis double clique sur clean.cmd et choisit l'option 1.Patiente un peu.
      Poste ce rapport dans ton prochain post
      0
      1. voila

        ven. 11/05/2007 a 13:26:01,70

        *** Recherche des fichiers dans C:
        C:\StubInstaller.exe FOUND

        *** Recherche des fichiers dans C:\WINDOWS\

        *** Recherche des fichiers dans C:\WINDOWS\system32
        C:\WINDOWS\system32\mcrh.tmp FOUND
        C:\WINDOWS\nsreg.dat FOUND
        "C:\Documents and Settings\Owner\Application Data\ezpinst.exe" FOUND

        *** Recherche des fichiers dans C:\Program Files
        "C:\Program Files\Viewpoint\" FOUND
        *** Fin du rapport !
        0
      2. Redémarre en mode sans échec tuto :

        http://forum.telecharger.01net.com/forum/

        Puis ouvre le dossier clean et execute clean.cmd et choisis l'option 2.
        Redémarre normalement et poste le log.
        0
    2. voila le rapport de virustotal

      Antivirus Version Update Result
      AhnLab-V3 2007.5.10.0 05.10.2007 Dropper/Xema.98304.B
      AntiVir 7.4.0.15 05.10.2007 TR/Spy.Winflyer
      Authentium 4.93.8 05.10.2007 no virus found
      Avast 4.7.997.0 05.10.2007 no virus found
      AVG 7.5.0.467 05.09.2007 Dropper.Agent.DKW
      BitDefender 7.2 05.10.2007 Adware.Winflyer.A
      CAT-QuickHeal 9.00 05.10.2007 Adware.WinFlyer.a (Not a Virus)
      ClamAV devel-20070416 05.10.2007 no virus found
      DrWeb 4.33 05.10.2007 no virus found
      eSafe 7.0.15.0 05.08.2007 no virus found
      eTrust-Vet 30.7.3624 05.10.2007 no virus found
      Ewido 4.0 05.10.2007 Dropper.Agent.bhc
      FileAdvisor 1 05.10.2007 no virus found
      Fortinet 2.85.0.0 05.10.2007 no virus found
      F-Prot 4.3.2.48 05.10.2007 no virus found
      F-Secure 6.70.13030.0 05.10.2007 Trojan-Dropper.Win32.Agent.bhc
      Ikarus T3.1.1.7 05.10.2007 Trojan-Dropper.Win32.Agent.bhc
      Kaspersky 4.0.2.24 05.10.2007 Trojan-Dropper.Win32.Agent.bhc
      McAfee 5027 05.09.2007 no virus found
      Microsoft 1.2503 05.10.2007 no virus found
      NOD32v2 2256 05.10.2007 no virus found
      Norman 5.80.02 05.10.2007 W32/Agent.BNXY
      Panda 9.0.0.4 05.10.2007 no virus found
      Prevx1 V2 05.10.2007 no virus found
      Sophos 4.17.0 05.08.2007 no virus found
      Sunbelt 2.2.907.0 05.05.2007 no virus found
      Symantec 10 05.10.2007 no virus found
      TheHacker 6.1.6.112 05.10.2007 no virus found
      VBA32 3.12.0 05.09.2007 no virus found
      VirusBuster 4.3.7:9 05.10.2007 no virus found
      Webwasher-Gateway 6.0.1 05.10.2007 Trojan.Spy.Winflyer
      0
      1. Vas sur le site virustotal : http://www.virustotal.com/en/indexf.html

        Puis dans un petit encadré blanc met ce fichier :

        C:\WINDOWS\system32\WinFlyer32.dll

        Puis clique sur "Send"
        Attend un peu un rapport va être généré.
        Puis poste le rapport.
        0
        1. voila

          Logfile of HijackThis v1.99.1
          Scan saved at 19:50:22, on 9/05/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16441)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
          C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
          C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
          C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
          C:\WINDOWS\system32\LEXBCES.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\LEXPPS.EXE
          C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
          C:\WINDOWS\system32\drivers\CDAC11BA.EXE
          c:\Apps\Powercinema\Kernel\TV\CLCapSvc.exe
          C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
          C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
          C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
          C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          C:\WINDOWS\System32\PAStiSvc.exe
          C:\WINDOWS\system32\svchost.exe
          c:\Apps\Powercinema\Kernel\TV\CLSched.exe
          C:\WINDOWS\system32\VTTimer.exe
          C:\WINDOWS\system32\VTtrayp.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Apps\Powercinema\PCMService.exe
          C:\WINDOWS\system32\LXSUPMON.EXE
          C:\WINDOWS\system32\rundll32.exe
          C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe
          C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X84-X85.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
          C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
          C:\Program Files\Support.com\bin\tgcmd.exe
          C:\WINDOWS\system32\GSICON.EXE
          C:\WINDOWS\system32\dslagent.exe
          C:\WINDOWS\system32\rundll32.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Microsoft ActiveSync\wcescomm.exe
          C:\Program Files\Sitecom\Logiciel Bluetooth\BTTray.exe
          C:\ScanPanel\ScnPanel.exe
          C:\PROGRA~1\MI3AA1~1\rapimgr.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
          C:\scan\scan.exe.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.update.microsoft.com/windowsupdate/v6/default.aspx
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: {BCBF738C-4891-4B9A-959A-C6BF7F608C3A} - {0B1B0D47-95F7-4bad-9309-A945B655AE61} - C:\WINDOWS\system32\regsvr32.exe
          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
          O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
          O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
          O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
          O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
          O3 - Toolbar: NVRIEbar.IEbar - {BCBF738C-4891-4B9A-959A-C6BF7F608C3A} - C:\Program Files\NaturalSoft\FreeVersion65\NVRIEbar.dll
          O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
          O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
          O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
          O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
          O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
          O4 - HKLM\..\Run: [Lexmark X84-X85 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe
          O4 - HKLM\..\Run: [Lexmark X84-X85 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X84-X85.exe
          O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
          O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor
          O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
          O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
          O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
          O4 - HKLM\..\Run: [WinFlyer32.dll] "rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
          O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
          O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
          O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
          O4 - Global Startup: BTTray.lnk = ?
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
          O4 - Global Startup: ScanPanel.lnk = C:\ScanPanel\ScnPanel.exe
          O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
          O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie_ctx.htm
          O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
          O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
          O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
          O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
          O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
          O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
          O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie.htm
          O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie.htm
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O11 - Options group: [INTERNATIONAL] International*
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
          O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) - http://support.packardbell.com/files/activex/InfosFinder2.CAB
          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
          O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
          O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
          O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
          O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
          O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
          O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
          O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\Apps\Powercinema\Kernel\TV\CLCapSvc.exe
          O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\Apps\Powercinema\Kernel\TV\CLSched.exe
          O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
          O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
          O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
          O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
          O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
          O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
          O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
          O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
          O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
          O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
          O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
          0
          1. redemarre le pc et remet un hijackthis
            0
            1. rapport virtumundo

              [05/09/2007, 19:22:53] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Owner\Bureau\VirtumundoBeGone.exe" )
              [05/09/2007, 19:23:04] - Detected System Information:
              [05/09/2007, 19:23:04] - Windows Version: 5.1.2600, Service Pack 2
              [05/09/2007, 19:23:04] - Current Username: Owner (Admin)
              [05/09/2007, 19:23:04] - Windows is in NORMAL mode.
              [05/09/2007, 19:23:04] - Searching for Browser Helper Objects:
              [05/09/2007, 19:23:04] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
              [05/09/2007, 19:23:04] - BHO 2: {0B1B0D47-95F7-4bad-9309-A945B655AE61} (NVRShowBar)
              [05/09/2007, 19:23:04] - BHO 3: {338DA9F8-3260-41FC-A66B-19B525185D1A} ()
              [05/09/2007, 19:23:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
              [05/09/2007, 19:23:04] - Checking for HKLM\...\Winlogon\Notify\qommjgh
              [05/09/2007, 19:23:04] - Found: HKLM\...\Winlogon\Notify\qommjgh - This is probably Virtumundo.
              [05/09/2007, 19:23:04] - Assigning {338DA9F8-3260-41FC-A66B-19B525185D1A} MSEvents Object
              [05/09/2007, 19:23:04] - BHO list has been changed! Starting over...
              [05/09/2007, 19:23:04] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
              [05/09/2007, 19:23:04] - BHO 2: {0B1B0D47-95F7-4bad-9309-A945B655AE61} (NVRShowBar)
              [05/09/2007, 19:23:04] - BHO 3: {338DA9F8-3260-41FC-A66B-19B525185D1A} (MSEvents Object)
              [05/09/2007, 19:23:04] - ALERT: Found MSEvents Object!
              [05/09/2007, 19:23:04] - BHO 4: {53707962-6F74-2D53-2644-206D7942484F} ()
              [05/09/2007, 19:23:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
              [05/09/2007, 19:23:04] - Checking for HKLM\...\Winlogon\Notify\SDHelper
              [05/09/2007, 19:23:04] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
              [05/09/2007, 19:23:04] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
              [05/09/2007, 19:23:04] - BHO 6: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
              [05/09/2007, 19:23:04] - BHO 7: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
              [05/09/2007, 19:23:04] - BHO 8: {AA112AFE-37CD-42C0-8DB5-FBE7247C8EE8} ()
              [05/09/2007, 19:23:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
              [05/09/2007, 19:23:04] - Checking for HKLM\...\Winlogon\Notify\vtstu
              [05/09/2007, 19:23:04] - Found: HKLM\...\Winlogon\Notify\vtstu - This is probably Virtumundo.
              [05/09/2007, 19:23:04] - Assigning {AA112AFE-37CD-42C0-8DB5-FBE7247C8EE8} MSEvents Object
              [05/09/2007, 19:23:04] - BHO list has been changed! Starting over...
              [05/09/2007, 19:23:04] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
              [05/09/2007, 19:23:04] - BHO 2: {0B1B0D47-95F7-4bad-9309-A945B655AE61} (NVRShowBar)
              [05/09/2007, 19:23:04] - BHO 3: {338DA9F8-3260-41FC-A66B-19B525185D1A} (MSEvents Object)
              [05/09/2007, 19:23:04] - ALERT: Found MSEvents Object!
              [05/09/2007, 19:23:04] - BHO 4: {53707962-6F74-2D53-2644-206D7942484F} ()
              [05/09/2007, 19:23:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
              [05/09/2007, 19:23:04] - Checking for HKLM\...\Winlogon\Notify\SDHelper
              [05/09/2007, 19:23:04] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
              [05/09/2007, 19:23:04] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
              [05/09/2007, 19:23:04] - BHO 6: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
              [05/09/2007, 19:23:04] - BHO 7: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
              [05/09/2007, 19:23:04] - BHO 8: {AA112AFE-37CD-42C0-8DB5-FBE7247C8EE8} (MSEvents Object)
              [05/09/2007, 19:23:04] - ALERT: Found MSEvents Object!
              [05/09/2007, 19:23:04] - Finished Searching Browser Helper Objects
              [05/09/2007, 19:23:04] - *** Detected MSEvents Object
              [05/09/2007, 19:23:04] - Trying to remove MSEvents Object...
              [05/09/2007, 19:23:05] - Terminating Process: IEXPLORE.EXE
              [05/09/2007, 19:23:06] - Terminating Process: RUNDLL32.EXE
              [05/09/2007, 19:23:06] - Disabling Automatic Shell Restart
              [05/09/2007, 19:23:06] - Terminating Process: EXPLORER.EXE
              [05/09/2007, 19:23:07] - Suspending the NT Session Manager System Service
              [05/09/2007, 19:23:07] - Terminating Windows NT Logon/Logoff Manager
              [05/09/2007, 19:23:08] - Re-enabling Automatic Shell Restart
              [05/09/2007, 19:23:08] - File to disable: C:\WINDOWS\system32\qommjgh.dll
              [05/09/2007, 19:23:08] - Renaming C:\WINDOWS\system32\qommjgh.dll -> C:\WINDOWS\system32\qommjgh.dll.vir
              [05/09/2007, 19:23:08] - File successfully renamed!
              [05/09/2007, 19:23:08] - Removing HKLM\...\Browser Helper Objects\{338DA9F8-3260-41FC-A66B-19B525185D1A}
              [05/09/2007, 19:23:08] - Removing HKCR\CLSID\{338DA9F8-3260-41FC-A66B-19B525185D1A}
              [05/09/2007, 19:23:08] - Adding Kill Bit for ActiveX for GUID: {338DA9F8-3260-41FC-A66B-19B525185D1A}
              [05/09/2007, 19:23:08] - Deleting ATLEvents/MSEvents Registry entries
              [05/09/2007, 19:23:08] - Removing HKLM\...\Winlogon\Notify\qommjgh
              [05/09/2007, 19:23:08] - Searching for Browser Helper Objects:
              [05/09/2007, 19:23:08] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
              [05/09/2007, 19:23:08] - BHO 2: {0B1B0D47-95F7-4bad-9309-A945B655AE61} (NVRShowBar)
              [05/09/2007, 19:23:08] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
              [05/09/2007, 19:23:08] - WARNING: BHO has no default name. Checking for Winlogon reference.
              [05/09/2007, 19:23:08] - Checking for HKLM\...\Winlogon\Notify\SDHelper
              [05/09/2007, 19:23:08] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
              [05/09/2007, 19:23:08] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
              [05/09/2007, 19:23:08] - BHO 5: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
              [05/09/2007, 19:23:08] - BHO 6: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
              [05/09/2007, 19:23:08] - BHO 7: {AA112AFE-37CD-42C0-8DB5-FBE7247C8EE8} (MSEvents Object)
              [05/09/2007, 19:23:08] - ALERT: Found MSEvents Object!
              [05/09/2007, 19:23:09] - Finished Searching Browser Helper Objects
              [05/09/2007, 19:23:09] - *** Detected MSEvents Object
              [05/09/2007, 19:23:09] - Trying to remove MSEvents Object...
              [05/09/2007, 19:23:10] - Terminating Process: IEXPLORE.EXE
              [05/09/2007, 19:23:10] - Terminating Process: RUNDLL32.EXE
              [05/09/2007, 19:23:10] - Disabling Automatic Shell Restart
              [05/09/2007, 19:23:10] - Terminating Process: EXPLORER.EXE
              [05/09/2007, 19:23:10] - Suspending the NT Session Manager System Service
              [05/09/2007, 19:23:10] - Terminating Windows NT Logon/Logoff Manager
              [05/09/2007, 19:23:10] - Re-enabling Automatic Shell Restart
              [05/09/2007, 19:23:10] - File to disable: C:\WINDOWS\system32\vtstu.dll
              [05/09/2007, 19:23:10] - Renaming C:\WINDOWS\system32\vtstu.dll -> C:\WINDOWS\system32\vtstu.dll.vir
              [05/09/2007, 19:23:10] - File successfully renamed!
              [05/09/2007, 19:23:10] - Removing HKLM\...\Browser Helper Objects\{AA112AFE-37CD-42C0-8DB5-FBE7247C8EE8}
              [05/09/2007, 19:23:10] - Removing HKCR\CLSID\{AA112AFE-37CD-42C0-8DB5-FBE7247C8EE8}
              [05/09/2007, 19:23:10] - Adding Kill Bit for ActiveX for GUID: {AA112AFE-37CD-42C0-8DB5-FBE7247C8EE8}
              [05/09/2007, 19:23:10] - Deleting ATLEvents/MSEvents Registry entries
              [05/09/2007, 19:23:10] - Removing HKLM\...\Winlogon\Notify\vtstu
              [05/09/2007, 19:23:10] - Searching for Browser Helper Objects:
              [05/09/2007, 19:23:10] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
              [05/09/2007, 19:23:10] - BHO 2: {0B1B0D47-95F7-4bad-9309-A945B655AE61} (NVRShowBar)
              [05/09/2007, 19:23:10] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
              [05/09/2007, 19:23:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
              [05/09/2007, 19:23:10] - Checking for HKLM\...\Winlogon\Notify\SDHelper
              [05/09/2007, 19:23:10] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
              [05/09/2007, 19:23:10] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
              [05/09/2007, 19:23:10] - BHO 5: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
              [05/09/2007, 19:23:10] - BHO 6: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
              [05/09/2007, 19:23:10] - Finished Searching Browser Helper Objects
              [05/09/2007, 19:23:10] - Finishing up...
              [05/09/2007, 19:23:10] - A restart is needed.
              [05/09/2007, 19:23:13] - Attempting to Restart via STOP error (Blue Screen!)

              Rapport hijackthis

              Logfile of HijackThis v1.99.1
              Scan saved at 19:29:17, on 9/05/2007
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16441)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
              C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
              C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
              C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
              C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
              C:\WINDOWS\system32\LEXBCES.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\system32\LEXPPS.EXE
              C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
              C:\WINDOWS\system32\drivers\CDAC11BA.EXE
              c:\Apps\Powercinema\Kernel\TV\CLCapSvc.exe
              C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
              C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
              C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
              C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              C:\WINDOWS\System32\PAStiSvc.exe
              C:\WINDOWS\system32\svchost.exe
              c:\Apps\Powercinema\Kernel\TV\CLSched.exe
              C:\WINDOWS\system32\VTTimer.exe
              C:\WINDOWS\system32\VTtrayp.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\Apps\Powercinema\PCMService.exe
              C:\WINDOWS\system32\LXSUPMON.EXE
              C:\WINDOWS\system32\rundll32.exe
              C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe
              C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X84-X85.exe
              C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
              C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
              C:\Program Files\Support.com\bin\tgcmd.exe
              C:\WINDOWS\system32\GSICON.EXE
              C:\WINDOWS\system32\dslagent.exe
              C:\WINDOWS\system32\rundll32.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Microsoft ActiveSync\wcescomm.exe
              C:\Program Files\Sitecom\Logiciel Bluetooth\BTTray.exe
              C:\PROGRA~1\MI3AA1~1\rapimgr.exe
              C:\ScanPanel\ScnPanel.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\scan\scan.exe.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
              R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.update.microsoft.com/windowsupdate/v6/default.aspx
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: {BCBF738C-4891-4B9A-959A-C6BF7F608C3A} - {0B1B0D47-95F7-4bad-9309-A945B655AE61} - C:\WINDOWS\system32\regsvr32.exe
              O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
              O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
              O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
              O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
              O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
              O3 - Toolbar: NVRIEbar.IEbar - {BCBF738C-4891-4B9A-959A-C6BF7F608C3A} - C:\Program Files\NaturalSoft\FreeVersion65\NVRIEbar.dll
              O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
              O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
              O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
              O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
              O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
              O4 - HKLM\..\Run: [Lexmark X84-X85 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe
              O4 - HKLM\..\Run: [Lexmark X84-X85 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X84-X85.exe
              O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
              O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
              O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor
              O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
              O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
              O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
              O4 - HKLM\..\Run: [WinFlyer32.dll] "rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
              O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
              O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
              O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
              O4 - Global Startup: BTTray.lnk = ?
              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
              O4 - Global Startup: ScanPanel.lnk = C:\ScanPanel\ScnPanel.exe
              O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
              O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie_ctx.htm
              O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
              O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
              O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
              O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie.htm
              O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie.htm
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O11 - Options group: [INTERNATIONAL] International*
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
              O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) - http://support.packardbell.com/files/activex/InfosFinder2.CAB
              O17 - HKLM\System\CCS\Services\Tcpip\..\{57E3DA57-7460-46D5-B202-BE7BEE8E4700}: NameServer = 85.255.116.118 85.255.112.205
              O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
              O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
              O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
              O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
              O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
              O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
              O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
              O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
              O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
              O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
              O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\Apps\Powercinema\Kernel\TV\CLCapSvc.exe
              O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\Apps\Powercinema\Kernel\TV\CLSched.exe
              O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
              O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
              O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
              O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
              O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
              O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
              O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
              O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
              O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
              O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
              O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
              O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
              0
              1. un autre outil pour éradiquer vundo :
                Télécharge VirtumundoBegone sur le bureau:
                http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe

                Double clique ensuite sur VirtumundoBeGone.exe et suis les instructions.
                Une fois terminé, redémarre et poste le rapport VBG.TXT créé sur le bureau dans ta prochaine réponse avec un nouveau rapport HijackThis.
                Ne t'inquiète pas si tu vois un message Ecran bleu "Erreur fatale", c'est normal et attendu

                Tu remets un log Hijackthis, on fera un peu de ménage après, histoire d'y voir plus clair.
                @+

                0
                1. pouvez vous me dire la suite SVP
                  0
                  1. Rapport de virustotal :

                    Complete scanning result of "WinFlyer32.dll", received in VirusTotal at 05.09.2007, 12:59:21 (CET).

                    Antivirus Version Update Result
                    AhnLab-V3 2007.5.9.0 05.09.2007 Dropper/Xema.98304.B
                    AntiVir 7.4.0.15 05.09.2007 TR/Spy.Winflyer
                    Authentium 4.93.8 05.08.2007 no virus found
                    Avast 4.7.997.0 05.09.2007 no virus found
                    AVG 7.5.0.467 05.08.2007 Dropper.Agent.DKW
                    BitDefender 7.2 05.09.2007 Adware.Winflyer.A
                    CAT-QuickHeal 9.00 05.08.2007 Adware.WinFlyer.a (Not a Virus)
                    ClamAV devel-20070416 05.09.2007 no virus found
                    DrWeb 4.33 05.09.2007 no virus found
                    eSafe 7.0.15.0 05.08.2007 no virus found
                    eTrust-Vet 30.7.3621 05.09.2007 no virus found
                    Ewido 4.0 05.09.2007 Dropper.Agent.bhc
                    FileAdvisor 1 05.09.2007 no virus found
                    Fortinet 2.85.0.0 05.09.2007 no virus found
                    F-Prot 4.3.2.48 05.08.2007 no virus found
                    F-Secure 6.70.13030.0 05.09.2007 Trojan-Dropper.Win32.Agent.bhc
                    Ikarus T3.1.1.7 05.09.2007 no virus found
                    Kaspersky 4.0.2.24 05.09.2007 Trojan-Dropper.Win32.Agent.bhc
                    McAfee 5026 05.08.2007 no virus found
                    Microsoft 1.2503 05.09.2007 no virus found
                    NOD32v2 2251 05.09.2007 no virus found
                    Norman 5.80.02 05.08.2007 no virus found
                    Panda 9.0.0.4 05.09.2007 no virus found
                    Prevx1 V2 05.09.2007 no virus found
                    Sophos 4.17.0 05.08.2007 no virus found
                    Sunbelt 2.2.907.0 05.05.2007 no virus found
                    Symantec 10 05.09.2007 no virus found
                    TheHacker 6.1.6.110 05.08.2007 no virus found
                    VBA32 3.12.0 05.08.2007 no virus found
                    VirusBuster 4.3.7:9 05.08.2007 no virus found
                    Webwasher-Gateway 6.0.1 05.09.2007 Trojan.Spy.Winflyer

                    Rapport de Killbox

                    Pocket Killbox version 2.0.0.978
                    Running on Windows XP as Owner(Administrator)
                    was started @ lundi, mai 07, 2007, 6:13 PM

                    Killbox Closed(Exit) @ 6:15:19 PM
                    __________________________________________________

                    Pocket Killbox version 2.0.0.978
                    Running on Windows XP as Owner(Administrator)
                    was started @ lundi, mai 07, 2007, 6:15 PM

                    # 1 [Files to Delete]
                    Path = qommjgh.dll
                    *This file does not seem to exist

                    # 2 [Files to Delete]
                    Path = c:\windows\System32\qommjgh.dll
                    *This file does not seem to exist

                    # 3 [Files to Delete]
                    Path = c:\windows\System32\qommjgh.dll
                    *This file does not seem to exist

                    # 4 [Delete on Reboot]
                    Path = c:\windows\System32\qommjgh.dll
                    *This file does not seem to exist

                    Killbox Closed(Exit) @ 6:16:32 PM
                    __________________________________________________

                    Pocket Killbox version 2.0.0.978
                    Running on Windows XP as Owner(Administrator)
                    was started @ mercredi, mai 09, 2007, 1:19 PM

                    # 1 [Delete on Reboot]
                    Path = C:\WINDOWS\system32\vtstu.dll

                    # 2 [Delete on Reboot]
                    Path = C:\WINDOWS\system32\qommjgh.dll

                    PendingFileRenameOperations Registry Data has been Removed by External Process! @ 1:22:21 PM
                    Killbox Closed(Exit) @ 1:23:03 PM
                    __________________________________________________

                    Pocket Killbox version 2.0.0.978
                    Running on Windows XP as Owner(Administrator)
                    was started @ mercredi, mai 09, 2007, 1:34 PM

                    Raport de hijackthis

                    Logfile of HijackThis v1.99.1
                    Scan saved at 13:36:25, on 9/05/2007
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16441)

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                    C:\WINDOWS\system32\LEXBCES.EXE
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\system32\LEXPPS.EXE
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
                    C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                    c:\Apps\Powercinema\Kernel\TV\CLCapSvc.exe
                    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
                    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                    C:\WINDOWS\System32\PAStiSvc.exe
                    C:\WINDOWS\system32\svchost.exe
                    c:\Apps\Powercinema\Kernel\TV\CLSched.exe
                    C:\WINDOWS\system32\VTTimer.exe
                    C:\WINDOWS\system32\VTtrayp.exe
                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                    C:\Apps\Powercinema\PCMService.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\WINDOWS\system32\LXSUPMON.EXE
                    C:\WINDOWS\system32\rundll32.exe
                    C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe
                    C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X84-X85.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
                    C:\Program Files\Support.com\bin\tgcmd.exe
                    C:\WINDOWS\system32\GSICON.EXE
                    C:\WINDOWS\system32\dslagent.exe
                    C:\WINDOWS\system32\rundll32.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
                    C:\Program Files\Sitecom\Logiciel Bluetooth\BTTray.exe
                    C:\PROGRA~1\MI3AA1~1\rapimgr.exe
                    C:\ScanPanel\ScnPanel.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
                    C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
                    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
                    C:\scan\scan.exe.exe
                    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
                    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
                    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
                    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.update.microsoft.com/windowsupdate/v6/default.aspx
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    O2 - BHO: {BCBF738C-4891-4B9A-959A-C6BF7F608C3A} - {0B1B0D47-95F7-4bad-9309-A945B655AE61} - C:\WINDOWS\system32\regsvr32.exe
                    O2 - BHO: (no name) - {338DA9F8-3260-41FC-A66B-19B525185D1A} - C:\WINDOWS\system32\qommjgh.dll
                    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                    O2 - BHO: (no name) - {55C74084-9761-4C04-A998-BDAF95D0FE1F} - C:\WINDOWS\system32\vtstu.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                    O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                    O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                    O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                    O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                    O3 - Toolbar: NVRIEbar.IEbar - {BCBF738C-4891-4B9A-959A-C6BF7F608C3A} - C:\Program Files\NaturalSoft\FreeVersion65\NVRIEbar.dll
                    O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
                    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                    O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
                    O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
                    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                    O4 - HKLM\..\Run: [Lexmark X84-X85 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe
                    O4 - HKLM\..\Run: [Lexmark X84-X85 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X84-X85.exe
                    O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
                    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
                    O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor
                    O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
                    O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
                    O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
                    O4 - HKLM\..\Run: [WinFlyer32.dll] "rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
                    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                    O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
                    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
                    O4 - Global Startup: BTTray.lnk = ?
                    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                    O4 - Global Startup: ScanPanel.lnk = C:\ScanPanel\ScnPanel.exe
                    O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
                    O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie_ctx.htm
                    O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                    O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
                    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
                    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie.htm
                    O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie.htm
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O11 - Options group: [INTERNATIONAL] International*
                    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                    O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) - http://support.packardbell.com/files/activex/InfosFinder2.CAB
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{57E3DA57-7460-46D5-B202-BE7BEE8E4700}: NameServer = 85.255.116.118 85.255.112.205
                    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                    O20 - Winlogon Notify: qommjgh - C:\WINDOWS\SYSTEM32\qommjgh.dll
                    O20 - Winlogon Notify: vtstu - C:\WINDOWS\system32\vtstu.dll
                    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
                    O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
                    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                    O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
                    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                    O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\Apps\Powercinema\Kernel\TV\CLCapSvc.exe
                    O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\Apps\Powercinema\Kernel\TV\CLSched.exe
                    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
                    O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                    O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                    O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
                    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
                    O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                    O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
                    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                    0
                    1. Vas sur le site virustotal : http://www.virustotal.com/en/indexf.html

                      Puis dans un petit encadré blanc met ce fichier :

                      C:\WINDOWS\system32\WinFlyer32.dll

                      Puis clique sur "Send"
                      Attend un peu un rapport va être généré.
                      Puis poste le rapport.

                      relance hijackthis puis clic sur "do a system scan only"

                      apres le scan coche ces lignes et seulement celles ci !!

                      O2 - BHO: (no name) - {140F31E4-704B-4A87-B1D7-0A253EC204E0} - C:\WINDOWS\system32\pmkhe.dll (file missing)

                      O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)

                      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE

                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

                      O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://tdserver.bitstream.com/tdserver.cab

                      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://fashion-victime-2006.spaces.live.com//PhotoUpload/MsnPUpld.cab

                      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/default.aspx

                      O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://wisup.net/_plateforme/Upload/Aurigma/AurigmaActiveX/ImageUploader4.cab

                      O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.extrafilm.be/net/Import/ImageUploader3.cab

                      O17 - HKLM\System\CCS\Services\Tcpip\..\{57E3DA57-7460-46D5-B202-BE7BEE8E4700}: NameServer = 85.255.116.118 85.255.112.205

                      O18 - Filter: text/html - (no CLSID) - (no file)

                      referme ton navigateur (internet explorer ) puis clic sur " fix check"

                      Telecharges Killbox : https://www.generation-nt.com/killbox-telechargement-25430.html

                      Doubles clique sur killbox.exe (Pocket Killbox)

                      sélectionne entièrement la liste ci-dessous :

                      C:\WINDOWS\system32\vtstu.dll
                      C:\WINDOWS\system32\qommjgh.dll
                      C:\WINDOWS\SYSTEM32\qommjgh.dll
                      C:\WINDOWS\system32\vtstu.dll

                      ---> et tu fais clic droit / copier

                      Ouvres killbox
                      - Sélectionne "delete on reboot"
                      - Clique sur le menu "File" -> "Past from clip board"
                      - Clique sur All Files
                      - Clique sur la croix rouge et et blanche
                      - Répond yes et laisse redémarrer ton pc.

                      NOTE: Si tu reçois le message "PendingFileRenameOperations Registry Data has been removed by external process!" et que l'ordinateur ne redémarre pas, redémarre le manuellement ---> Menu Démarrer / arreter / redémarrer l'ordinateur

                      Après redémarrage, relance Killbox puis clic sur l'onglet "fichier" -> Log -> Actions History Log
                      Poste le rapport ici

                      remet un nouveau rapport hijackthis
                      0
                      1. Raport de vundo
                        voila le raport

                        VundoFix V6.3.21

                        Checking Java version...

                        Java version is 1.5.0.6
                        Old versions of java are exploitable and should be removed.

                        Java version is 1.5.0.9
                        Old versions of java are exploitable and should be removed.

                        Java version is 1.5.0.10

                        Java version is 1.5.0.11

                        Scan started at 19:30:38 8/05/2007

                        Listing files found while scanning....

                        C:\WINDOWS\system32\ehkmp.bak1
                        C:\WINDOWS\system32\ehkmp.bak2
                        C:\WINDOWS\system32\ehkmp.ini
                        C:\WINDOWS\system32\ehkmp.ini2
                        C:\WINDOWS\system32\ehkmp.tmp
                        C:\WINDOWS\system32\owwyfpxi.dll
                        C:\WINDOWS\system32\pmkhe.dll

                        Beginning removal...

                        Attempting to delete C:\WINDOWS\system32\ehkmp.bak1
                        C:\WINDOWS\system32\ehkmp.bak1 Has been deleted!

                        Attempting to delete C:\WINDOWS\system32\ehkmp.bak2
                        C:\WINDOWS\system32\ehkmp.bak2 Has been deleted!

                        Attempting to delete C:\WINDOWS\system32\ehkmp.ini
                        C:\WINDOWS\system32\ehkmp.ini Has been deleted!

                        Attempting to delete C:\WINDOWS\system32\ehkmp.ini2
                        C:\WINDOWS\system32\ehkmp.ini2 Has been deleted!

                        Attempting to delete C:\WINDOWS\system32\ehkmp.tmp
                        C:\WINDOWS\system32\ehkmp.tmp Has been deleted!

                        Attempting to delete C:\WINDOWS\system32\pmkhe.dll
                        C:\WINDOWS\system32\pmkhe.dll Has been deleted!

                        Performing Repairs to the registry.
                        Done!

                        raport hijacktis

                        Logfile of HijackThis v1.99.1
                        Scan saved at 20:00:56, on 8/05/2007
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16414)

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                        C:\WINDOWS\system32\LEXBCES.EXE
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\WINDOWS\system32\LEXPPS.EXE
                        C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
                        C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                        c:\Apps\Powercinema\Kernel\TV\CLCapSvc.exe
                        C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                        C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
                        C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                        C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                        C:\WINDOWS\SOUNDMAN.EXE
                        C:\WINDOWS\system32\VTTimer.exe
                        C:\WINDOWS\system32\VTtrayp.exe
                        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                        C:\Program Files\QuickTime\qttask.exe
                        C:\Apps\Powercinema\PCMService.exe
                        C:\WINDOWS\system32\LXSUPMON.EXE
                        C:\WINDOWS\system32\rundll32.exe
                        C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe
                        C:\WINDOWS\System32\PAStiSvc.exe
                        C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X84-X85.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                        C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
                        C:\Program Files\Support.com\bin\tgcmd.exe
                        C:\WINDOWS\system32\GSICON.EXE
                        c:\Apps\Powercinema\Kernel\TV\CLSched.exe
                        C:\WINDOWS\system32\dslagent.exe
                        C:\WINDOWS\system32\rundll32.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Microsoft ActiveSync\wcescomm.exe
                        C:\Program Files\Sitecom\Logiciel Bluetooth\BTTray.exe
                        C:\ScanPanel\ScnPanel.exe
                        C:\PROGRA~1\MI3AA1~1\rapimgr.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\WINDOWS\system32\rundll32.exe
                        C:\Program Files\Messenger\msmsgs.exe
                        C:\scan\scan.exe.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.update.microsoft.com/windowsupdate/v6/default.aspx
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: {BCBF738C-4891-4B9A-959A-C6BF7F608C3A} - {0B1B0D47-95F7-4bad-9309-A945B655AE61} - C:\WINDOWS\system32\regsvr32.exe
                        O2 - BHO: (no name) - {140F31E4-704B-4A87-B1D7-0A253EC204E0} - C:\WINDOWS\system32\pmkhe.dll (file missing)
                        O2 - BHO: (no name) - {305F3E01-F4C3-43E6-9EF0-3903C319371F} - C:\WINDOWS\system32\vtstu.dll
                        O2 - BHO: (no name) - {338DA9F8-3260-41FC-A66B-19B525185D1A} - C:\WINDOWS\system32\qommjgh.dll
                        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                        O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                        O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                        O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                        O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                        O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
                        O3 - Toolbar: NVRIEbar.IEbar - {BCBF738C-4891-4B9A-959A-C6BF7F608C3A} - C:\Program Files\NaturalSoft\FreeVersion65\NVRIEbar.dll
                        O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
                        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                        O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                        O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
                        O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
                        O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                        O4 - HKLM\..\Run: [Lexmark X84-X85 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe
                        O4 - HKLM\..\Run: [Lexmark X84-X85 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X84-X85.exe
                        O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
                        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
                        O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor
                        O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
                        O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
                        O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
                        O4 - HKLM\..\Run: [WinFlyer32.dll] "rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
                        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                        O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
                        O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                        O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
                        O4 - Global Startup: BTTray.lnk = ?
                        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                        O4 - Global Startup: ScanPanel.lnk = C:\ScanPanel\ScnPanel.exe
                        O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
                        O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie_ctx.htm
                        O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                        O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                        O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                        O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
                        O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
                        O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie.htm
                        O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie.htm
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O11 - Options group: [INTERNATIONAL] International*
                        O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://tdserver.bitstream.com/tdserver.cab
                        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://fashion-victime-2006.spaces.live.com//PhotoUpload/MsnPUpld.cab
                        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                        O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://wisup.net/_plateforme/Upload/Aurigma/AurigmaActiveX/ImageUploader4.cab
                        O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.extrafilm.be/net/Import/ImageUploader3.cab
                        O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) - http://support.packardbell.com/files/activex/InfosFinder2.CAB
                        O17 - HKLM\System\CCS\Services\Tcpip\..\{57E3DA57-7460-46D5-B202-BE7BEE8E4700}: NameServer = 85.255.116.118 85.255.112.205
                        O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                        O18 - Filter: text/html - (no CLSID) - (no file)
                        O20 - Winlogon Notify: qommjgh - C:\WINDOWS\SYSTEM32\qommjgh.dll
                        O20 - Winlogon Notify: vtstu - C:\WINDOWS\system32\vtstu.dll
                        O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                        O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                        O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
                        O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
                        O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                        O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
                        O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                        O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\Apps\Powercinema\Kernel\TV\CLCapSvc.exe
                        O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\Apps\Powercinema\Kernel\TV\CLSched.exe
                        O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
                        O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                        O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                        O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                        O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
                        O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                        O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
                        O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                        O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                        O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
                        O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                        0
                        1. en renomant hijackthis en scan.exe les lignes de vundoo sont apparus !!!!

                          Télécharge VundoFix.exe (par Atribune) sur ton Bureau.
                          http://www.atribune.org/ccount/click.php?id=4
                          * Double-clique VundoFix.exe afin de le lancer
                          * Clique sur le bouton Scan for Vundo
                          * Lorsque le scan est complété, clique sur le bouton Remove Vundo
                          * Une invite te demandera si tu veux supprimer les fichiers, clique YES
                          * Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers
                          * Tu verras une invite qui t'annonce que ton PC va redémarrer; clique OK
                          * Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis! dans ta prochaine réponse

                          Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci dessus, à partir de "clique sur le bouton Scan for Vundo".

                          et reposte un log hijackthis ,
                          @+

                          0
                          1. Logfile of HijackThis v1.99.1
                            Scan saved at 19:54:45, on 8/05/2007
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v7.00 (7.00.6000.16414)

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                            C:\WINDOWS\system32\LEXBCES.EXE
                            C:\WINDOWS\Explorer.EXE
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\WINDOWS\system32\LEXPPS.EXE
                            C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
                            C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                            c:\Apps\Powercinema\Kernel\TV\CLCapSvc.exe
                            C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                            C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
                            C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                            C:\WINDOWS\SOUNDMAN.EXE
                            C:\WINDOWS\system32\VTTimer.exe
                            C:\WINDOWS\system32\VTtrayp.exe
                            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                            C:\Program Files\QuickTime\qttask.exe
                            C:\Apps\Powercinema\PCMService.exe
                            C:\WINDOWS\system32\LXSUPMON.EXE
                            C:\WINDOWS\system32\rundll32.exe
                            C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe
                            C:\WINDOWS\System32\PAStiSvc.exe
                            C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X84-X85.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                            C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
                            C:\Program Files\Support.com\bin\tgcmd.exe
                            C:\WINDOWS\system32\GSICON.EXE
                            c:\Apps\Powercinema\Kernel\TV\CLSched.exe
                            C:\WINDOWS\system32\dslagent.exe
                            C:\WINDOWS\system32\rundll32.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Microsoft ActiveSync\wcescomm.exe
                            C:\Program Files\Sitecom\Logiciel Bluetooth\BTTray.exe
                            C:\ScanPanel\ScnPanel.exe
                            C:\PROGRA~1\MI3AA1~1\rapimgr.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\WINDOWS\system32\rundll32.exe
                            C:\Program Files\Messenger\msmsgs.exe
                            C:\scan\scan.exe.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.update.microsoft.com/windowsupdate/v6/default.aspx
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                            O2 - BHO: {BCBF738C-4891-4B9A-959A-C6BF7F608C3A} - {0B1B0D47-95F7-4bad-9309-A945B655AE61} - C:\WINDOWS\system32\regsvr32.exe
                            O2 - BHO: (no name) - {140F31E4-704B-4A87-B1D7-0A253EC204E0} - C:\WINDOWS\system32\pmkhe.dll (file missing)
                            O2 - BHO: (no name) - {305F3E01-F4C3-43E6-9EF0-3903C319371F} - C:\WINDOWS\system32\vtstu.dll
                            O2 - BHO: (no name) - {338DA9F8-3260-41FC-A66B-19B525185D1A} - C:\WINDOWS\system32\qommjgh.dll
                            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                            O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                            O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                            O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                            O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                            O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
                            O3 - Toolbar: NVRIEbar.IEbar - {BCBF738C-4891-4B9A-959A-C6BF7F608C3A} - C:\Program Files\NaturalSoft\FreeVersion65\NVRIEbar.dll
                            O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
                            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                            O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                            O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
                            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                            O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
                            O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
                            O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                            O4 - HKLM\..\Run: [Lexmark X84-X85 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe
                            O4 - HKLM\..\Run: [Lexmark X84-X85 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X84-X85.exe
                            O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
                            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
                            O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor
                            O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
                            O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
                            O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
                            O4 - HKLM\..\Run: [WinFlyer32.dll] "rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
                            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                            O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
                            O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                            O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
                            O4 - Global Startup: BTTray.lnk = ?
                            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                            O4 - Global Startup: ScanPanel.lnk = C:\ScanPanel\ScnPanel.exe
                            O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
                            O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie_ctx.htm
                            O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                            O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                            O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                            O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                            O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
                            O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
                            O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie.htm
                            O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie.htm
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O11 - Options group: [INTERNATIONAL] International*
                            O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://tdserver.bitstream.com/tdserver.cab
                            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://fashion-victime-2006.spaces.live.com//PhotoUpload/MsnPUpld.cab
                            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                            O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://wisup.net/_plateforme/Upload/Aurigma/AurigmaActiveX/ImageUploader4.cab
                            O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.extrafilm.be/net/Import/ImageUploader3.cab
                            O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) - http://support.packardbell.com/files/activex/InfosFinder2.CAB
                            O17 - HKLM\System\CCS\Services\Tcpip\..\{57E3DA57-7460-46D5-B202-BE7BEE8E4700}: NameServer = 85.255.116.118 85.255.112.205
                            O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                            O18 - Filter: text/html - (no CLSID) - (no file)
                            O20 - Winlogon Notify: qommjgh - C:\WINDOWS\SYSTEM32\qommjgh.dll
                            O20 - Winlogon Notify: vtstu - C:\WINDOWS\system32\vtstu.dll
                            O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                            O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                            O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
                            O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
                            O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                            O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
                            O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                            O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\Apps\Powercinema\Kernel\TV\CLCapSvc.exe
                            O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\Apps\Powercinema\Kernel\TV\CLSched.exe
                            O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
                            O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                            O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                            O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                            O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
                            O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                            O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
                            O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                            O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                            O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                            O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
                            O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                            0
                            1. renome hijackthis " scan.exe" par exemple

                              et remet un nouveau log hijackthis stp
                              0
                              1. Voila le rapport de fixwareout :

                                voila le raport

                                Fixwareout Last edited 4/5/2007
                                Post this report in the forums please
                                ...
                                »»»»»Prerun check

                                »»»»» System restarted

                                »»»»» Postrun check
                                HKLM\SOFTWARE\~\Winlogon\ "System"=""
                                ....
                                ....
                                »»»»» Misc files.
                                ....
                                »»»»» Checking for older varients.
                                ....

                                Search five digit cs, dm, kd, jb, other, files.
                                The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.

                                Click browse, find the file then click submit.
                                http://www.virustotal.com/flash/index_en.html
                                Or https://virusscan.jotti.org/

                                »»»»» Other

                                »»»»» Current runs
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "SoundMan"="SOUNDMAN.EXE"
                                "VTTimer"="VTTimer.exe"
                                "VTTrayp"="VTtrayp.exe"
                                "TkBellExe"="\"C:\\Program Files\\Fichiers communs\\Real\\Update_OB\\realsched.exe\" -osboot"
                                "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
                                "PCMService"="\"c:\\Apps\\Powercinema\\PCMService.exe\""
                                "LXSUPMON"="C:\\WINDOWS\\system32\\LXSUPMON.EXE RUN"
                                "BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
                                "Lexmark X84-X85 Button Monitor"="C:\\PROGRA~1\\LEXMAR~1\\ACMonitor_X84-X85.exe"
                                "Lexmark X84-X85 Button Manager"="C:\\PROGRA~1\\LEXMAR~1\\AcBtnMgr_X84-X85.exe"
                                "PrinTray"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\printray.exe"
                                "ccApp"="\"C:\\Program Files\\Fichiers communs\\Symantec Shared\\ccApp.exe\""
                                "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\jusched.exe\""
                                "tgcmd"="\"C:\\Program Files\\Support.com\\bin\\tgcmd.exe\" /server /startmonitor "
                                "GSICONEXE"="GSICON.EXE"
                                "DSLAGENTEXE"="dslagent.exe USB"
                                "PinnacleDriverCheck"="C:\\WINDOWS\\system32\\\\PSDrvCheck.exe"
                                "WinFlyer32.dll"="\"rundll32.exe\" C:\\WINDOWS\\system32\\WinFlyer32.dll,Run"

                                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
                                "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Fichiers communs\\Ahead\\Lib\\NMBgMonitor.exe\""
                                "BitTorrent"="\"C:\\Program Files\\BitTorrent\\bittorrent.exe\" --force_start_minimized"
                                "Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
                                "H/PC Connection Agent"="\"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe\""
                                ....
                                Hosts file was reset, If you use a custom hosts file please replace it
                                »»»»» End report »»»»»

                                Voila le rapport avec hijackthis

                                Logfile of HijackThis v1.99.1
                                Scan saved at 19:16:31, on 8/05/2007
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16414)

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                                C:\WINDOWS\system32\LEXBCES.EXE
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\WINDOWS\system32\LEXPPS.EXE
                                C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
                                C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                                c:\Apps\Powercinema\Kernel\TV\CLCapSvc.exe
                                C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                                C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
                                C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                                C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                C:\WINDOWS\System32\PAStiSvc.exe
                                C:\WINDOWS\system32\svchost.exe
                                c:\Apps\Powercinema\Kernel\TV\CLSched.exe
                                C:\WINDOWS\SOUNDMAN.EXE
                                C:\WINDOWS\system32\VTTimer.exe
                                C:\WINDOWS\system32\VTtrayp.exe
                                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                C:\Program Files\QuickTime\qttask.exe
                                C:\Apps\Powercinema\PCMService.exe
                                C:\WINDOWS\system32\LXSUPMON.EXE
                                C:\WINDOWS\system32\rundll32.exe
                                C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe
                                C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X84-X85.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                                C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
                                C:\Program Files\Support.com\bin\tgcmd.exe
                                C:\WINDOWS\system32\GSICON.EXE
                                C:\WINDOWS\system32\dslagent.exe
                                C:\WINDOWS\system32\rundll32.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\Program Files\Microsoft ActiveSync\wcescomm.exe
                                C:\Program Files\Sitecom\Logiciel Bluetooth\BTTray.exe
                                C:\ScanPanel\ScnPanel.exe
                                C:\PROGRA~1\MI3AA1~1\rapimgr.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\WINDOWS\system32\NOTEPAD.EXE
                                C:\Program Files\Messenger\msmsgs.exe
                                C:\hijackthis\HijackThis.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                                R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.update.microsoft.com/windowsupdate/v6/default.aspx
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                                O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                                O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                                O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
                                O3 - Toolbar: NVRIEbar.IEbar - {BCBF738C-4891-4B9A-959A-C6BF7F608C3A} - C:\Program Files\NaturalSoft\FreeVersion65\NVRIEbar.dll
                                O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
                                O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                                O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
                                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
                                O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
                                O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                                O4 - HKLM\..\Run: [Lexmark X84-X85 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe
                                O4 - HKLM\..\Run: [Lexmark X84-X85 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X84-X85.exe
                                O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
                                O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
                                O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor
                                O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
                                O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
                                O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
                                O4 - HKLM\..\Run: [WinFlyer32.dll] "rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
                                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                                O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
                                O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                                O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
                                O4 - Global Startup: BTTray.lnk = ?
                                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                                O4 - Global Startup: ScanPanel.lnk = C:\ScanPanel\ScnPanel.exe
                                O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
                                O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie_ctx.htm
                                O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                                O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                                O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                                O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
                                O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
                                O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie.htm
                                O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie.htm
                                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O11 - Options group: [INTERNATIONAL] International*
                                O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://tdserver.bitstream.com/tdserver.cab
                                O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://fashion-victime-2006.spaces.live.com//PhotoUpload/MsnPUpld.cab
                                O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                                O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://wisup.net/_plateforme/Upload/Aurigma/AurigmaActiveX/ImageUploader4.cab
                                O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.extrafilm.be/net/Import/ImageUploader3.cab
                                O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) - http://support.packardbell.com/files/activex/InfosFinder2.CAB
                                O17 - HKLM\System\CCS\Services\Tcpip\..\{06B77ABD-1A0E-46C0-A2B0-76F43C7713B0}: NameServer = 85.255.116.118,85.255.112.205
                                O17 - HKLM\System\CCS\Services\Tcpip\..\{136EDD1A-5B42-4476-8225-21DB2A2D3C29}: NameServer = 85.255.116.118,85.255.112.205
                                O17 - HKLM\System\CCS\Services\Tcpip\..\{4BA4A728-A13A-40FA-9EBF-70164611F6D5}: NameServer = 85.255.116.118,85.255.112.205
                                O17 - HKLM\System\CCS\Services\Tcpip\..\{541853E9-1E9A-4DCE-8841-ADF53127C1E2}: NameServer = 85.255.116.118,85.255.112.205
                                O17 - HKLM\System\CCS\Services\Tcpip\..\{57E3DA57-7460-46D5-B202-BE7BEE8E4700}: NameServer = 85.255.116.118 85.255.112.205
                                O17 - HKLM\System\CCS\Services\Tcpip\..\{EA6813D3-4B67-4109-BCF5-6AAA557609E2}: NameServer = 85.255.116.118,85.255.112.205
                                O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.118 85.255.112.205
                                O17 - HKLM\System\CS1\Services\Tcpip\..\{06B77ABD-1A0E-46C0-A2B0-76F43C7713B0}: NameServer = 85.255.116.118,85.255.112.205
                                O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.118 85.255.112.205
                                O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                                O18 - Filter: text/html - (no CLSID) - (no file)
                                O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                                O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
                                O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
                                O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                                O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                                O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
                                O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                                O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                                O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\Apps\Powercinema\Kernel\TV\CLCapSvc.exe
                                O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\Apps\Powercinema\Kernel\TV\CLSched.exe
                                O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
                                O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                                O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                                O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                                O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
                                O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
                                O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                                O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                                O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                                O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
                                O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                                0
                                1. Télécharge FixWareout d'un de ces deux sites sur le bureau:
                                  http://downloads.subratam.org/Fixwareout.exe
                                  http://swandog46.geekstogo.com/Fixwareout.exe

                                  * Lance le fix: clique sur Next, puis Install, puis assure toi que "Run fixit" est activé puis clique sur Finish.
                                  Le fix va commencer, suis les messages à l'écran. Il te sera demandé de redémarrer ton ordinateur, fais le. Ton système mettra un peu plus de temps au démarrage, c'est normal.

                                  *Poste (Copie/colle) le contenu du rapport qui va s'afficher à l'écran (report.txt)

                                  renome hijackthis " scan.exe" par exemple

                                  et remet un nouveau log hijackthis stp
                                  0
                                  1. Voila le rapport

                                    SmitFraudFix v2.177

                                    Rapport fait à 18:58:54,78, mar. 08/05/2007
                                    Executé à partir de C:\Documents and Settings\Owner\Bureau\SmitfraudFix
                                    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                                    Le type du système de fichiers est NTFS
                                    Fix executé en mode sans echec

                                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                    SrchSTS.exe by S!Ri
                                    Search SharedTaskScheduler's .dll

                                    »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                    127.0.0.1 localhost

                                    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                                    GenericRenosFix by S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{06B77ABD-1A0E-46C0-A2B0-76F43C7713B0}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{06B77ABD-1A0E-46C0-A2B0-76F43C7713B0}: NameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{136EDD1A-5B42-4476-8225-21DB2A2D3C29}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{136EDD1A-5B42-4476-8225-21DB2A2D3C29}: NameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{4BA4A728-A13A-40FA-9EBF-70164611F6D5}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{4BA4A728-A13A-40FA-9EBF-70164611F6D5}: NameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{541853E9-1E9A-4DCE-8841-ADF53127C1E2}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{541853E9-1E9A-4DCE-8841-ADF53127C1E2}: NameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{D1B6362D-74E2-419F-B02D-88B895ECE247}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{EA6813D3-4B67-4109-BCF5-6AAA557609E2}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{EA6813D3-4B67-4109-BCF5-6AAA557609E2}: NameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{06B77ABD-1A0E-46C0-A2B0-76F43C7713B0}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{06B77ABD-1A0E-46C0-A2B0-76F43C7713B0}: NameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{136EDD1A-5B42-4476-8225-21DB2A2D3C29}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{136EDD1A-5B42-4476-8225-21DB2A2D3C29}: NameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{4BA4A728-A13A-40FA-9EBF-70164611F6D5}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{4BA4A728-A13A-40FA-9EBF-70164611F6D5}: NameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{541853E9-1E9A-4DCE-8841-ADF53127C1E2}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{541853E9-1E9A-4DCE-8841-ADF53127C1E2}: NameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{D1B6362D-74E2-419F-B02D-88B895ECE247}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{EA6813D3-4B67-4109-BCF5-6AAA557609E2}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{EA6813D3-4B67-4109-BCF5-6AAA557609E2}: NameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{06B77ABD-1A0E-46C0-A2B0-76F43C7713B0}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{06B77ABD-1A0E-46C0-A2B0-76F43C7713B0}: NameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{136EDD1A-5B42-4476-8225-21DB2A2D3C29}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{136EDD1A-5B42-4476-8225-21DB2A2D3C29}: NameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{4BA4A728-A13A-40FA-9EBF-70164611F6D5}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{4BA4A728-A13A-40FA-9EBF-70164611F6D5}: NameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{541853E9-1E9A-4DCE-8841-ADF53127C1E2}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{541853E9-1E9A-4DCE-8841-ADF53127C1E2}: NameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{D1B6362D-74E2-419F-B02D-88B895ECE247}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{EA6813D3-4B67-4109-BCF5-6AAA557609E2}: DhcpNameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{EA6813D3-4B67-4109-BCF5-6AAA557609E2}: NameServer=85.255.116.118,85.255.112.205
                                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=85.255.116.118 85.255.112.205
                                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=85.255.116.118 85.255.112.205
                                    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: NameServer=85.255.116.118 85.255.112.205

                                    »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                    "System"=""

                                    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                                    Nettoyage terminé.

                                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                    SrchSTS.exe by S!Ri
                                    Search SharedTaskScheduler's .dll

                                    »»»»»»»»»»»»»»»»»»»»»»»» Fin
                                    0
                                    1. Démarre en mode sans échec :
                                      Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                                      Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                                      Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                                      (Si F8 ne marche pas utilise la touche F5).
                                      ----------------------------------------------------------------------------
                                      Relance le programme Smitfraud,
                                      Cette fois choisit l’option 2, répond oui a tous ;
                                      Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

                                      A+
                                      0
                                      • 1
                                      • 2