Trojan vundo impossible a supprimé

Bonjour,
Jai le trojan vundo que je supprime avec malware byte anti malware.
Il semble le detecté et le supprimé et tout
tout va bien pendant quelques heure et puis boum le virus réapparait a lors que je navigue tranquillement sur internet ou je chat sur msn peu importe
voici un Hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:59:14, on 2008-12-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {00e1b210-4f27-4fe7-a982-e389079d588c} - C:\WINDOWS\system32\hoyozebo.dll (file missing)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccb7dd84] rundll32.exe "C:\WINDOWS\system32\nulojaka.dll",b
O4 - HKLM\..\Run: [CPMcf84ee18] Rundll32.exe "c:\windows\system32\bovutaja.dll",a
O4 - HKLM\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'postgres')
O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'postgres')
O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O15 - Trusted Zone: http://*.facebook.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - https://sdlc-esd.oracle.com/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab?GroupName=JSC&FilePath=/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab&BHost=javadl.sun.com&File=jinstall-6u10-windows-i586-jc.cab&AuthParam=1580987764_a5235be86e79daca0cfb05ddc36bfbcd&ext=.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: wasyhy.dll c:\windows\system32\nuwemuno.dll C:\WINDOWS\system32\wesepani.dll c:\windows\system32\bovutaja.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\bovutaja.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\bovutaja.dll
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
O24 - Desktop Component 0: (no name) - http://tbn0.google.com/...

--
End of file - 9879 bytes
Configuration: Windows XP
Internet Explorer 7.0

27 réponses

Résumé de la discussion

Infection par le cheval de Troie Vundo qui réapparaît après suppression avec Malwarebytes' Anti-Malware, et qui survient lors de la navigation ou d’échanges sur MSN, alimente une discussion autour de la persistance du malware. Le log HijackThis et les extraits listés montrent des entrées suspectes, des modules et des services qui persistent sous Windows XP SP2, rendant la suppression efficace difficile. Des réponses évoquent l’usage de MBAM et notent que Vundofix est obsolète, recommandant aussi un antivirus, un pare-feu et une mise à jour régulière des signatures avant une analyse prolongée. En complément, des rapports Avira et des indices sur des composants système indésirables illustrent la complexité du nettoyage et suggèrent une approche multi-outils plutôt que l’attente d’un seul outil.

Bobot (l’IA à votre service)
  1. Quand je clique sur le lien de ton dernier message j'arrive sur une page D'erreur
    Erreur 404 objet non trouver....
    1. Contributeur sécurité
      Télécharge cette version de SDFix (créé par AndyManchesta)
      et renommée pour l'occasion et sauvegarde la sur ton Bureau.
      (merci Jlpjlp )

      Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié dans C:\. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
      • Redémarre ton ordinateur
      • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
      • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
      • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
      • Choisis ton compte.
      Déroule la liste des instructions ci-dessous :
      • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le scrïpt.
      • Appuie sur Y pour commencer le processus de nettoyage.
      • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
      • Appuie sur une touche pour redémarrer le PC.
      • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
      • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
      • Appuie sur une touche pour finir l'exécution du scrïpt et charger les icônes de ton Bureau.
      • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
      • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !
      1. Bon j'ai faite les manipulation que tu as dit a la lettre (mais je n'ai trouvé aucun qui correspondait a ta description)
        sdfix ne marche toujours

        Mais cet apres-midi, avira m'envoyai environ 15 message pour me prévenir de 4 fichier infecté
        zubadira.dll
        peluloge.dll
        pabuzili.dll
        voyuvofe.dll
        tous dans le dossier system32
        je les ai supprimé en mode sans echec en plus de faire un analyse avec mbam
        de plus j'ai fixer les lignes suspect avec hijackthis toujours en mode sans echec
        la ça fait preske 1 heure mon ordi est ouverte et pas de nouvelle du virus mais rien de sur souvent il revien apres un certain temps

        un nouveau log hijackthis

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 20:23:20, on 2008-12-04
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.5730.0013)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
        C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
        C:\WINDOWS\system32\hkcmd.exe
        C:\WINDOWS\system32\igfxpers.exe
        C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Winamp\winampa.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
        C:\Program Files\DAEMON Tools Lite\daemon.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\LogMeIn\x86\RaMaint.exe
        C:\Program Files\LogMeIn\x86\LogMeIn.exe
        C:\Program Files\LogMeIn\x86\LMIGuardian.exe
        C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
        C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
        C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Windows Live\Contacts\wlcomm.exe
        C:\Program Files\PokerStars\PokerStars.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: (no name) - {00e1b210-4f27-4fe7-a982-e389079d588c} - C:\WINDOWS\system32\peluloge.dll (file missing)
        O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
        O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
        O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
        O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
        O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
        O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
        O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
        O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
        O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
        O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
        O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
        O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\mezeweku.dll",s (User 'postgres')
        O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'postgres')
        O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
        O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
        O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
        O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
        O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
        O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
        O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
        O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
        O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
        O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
        O15 - Trusted Zone: http://*.facebook.com
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
        O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - https://sdlc-esd.oracle.com/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab?GroupName=JSC&FilePath=/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab&BHost=javadl.sun.com&File=jinstall-6u10-windows-i586-jc.cab&AuthParam=1580987764_a5235be86e79daca0cfb05ddc36bfbcd&ext=.cab
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
        O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
        O20 - AppInit_DLLs: wasyhy.dll c:\windows\system32\nuwemuno.dll C:\WINDOWS\system32\pabuzili.dll
        O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
        O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
        O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
        O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
        O24 - Desktop Component 0: (no name) - http://tbn0.google.com/...
        1. Contributeur sécurité
          Regarde en haut a droite, clique sur l'enveloppe.

          Une fois que tu as fais ce que je t'ai mis en MP ( message privé ) fais ce qui suit :

          Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
          Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau.

          Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
          comment demarrer en mode sans echec en images
          Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
          A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
          Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
          Choisis ton compte.

          Déroule la liste des instructions ci-dessous :

          * Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
          * Appuie sur Y pour commencer le processus de nettoyage.
          Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
          * Appuie sur une touche pour redémarrer le PC.
          Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
          Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
          * Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
          Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
          Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum

          Tuto d'instalation et de mise en oeuvre
          1. Contributeur sécurité
            Salut !

            Il faudrait que tu t'inscrives sur le site, ( c'est gratuit ), pour que je puisse te donner une manipulation a faire très précise.
            1. J'ai tenté de faire ce que tu as dit mais ça na pas fonctionner
              je suis en mode sans échec et je start sdfix comme tu as écrit
              jécrit Y
              puis la ça comment en disant start repair search for... en tous cas le message de départ puis ça reste gelé la
              j'ai cancelé et reparti plusieur fois donc 2 fois jlé laissé allé plus de 2 heure et rien aucun signe de travail de la part du programme

              il doit y avoir un autre programme sinon je réessayerai cette nuit

              en passant avira maverti dun virus en disant:
              TR/agent.asdn trojan
              \system32\vudutowo.dll

              si ça peut aidé
              et voici un nouveau hijackthis au cas ou

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 21:34:00, on 2008-12-03
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.5730.0013)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
              C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
              C:\WINDOWS\system32\hkcmd.exe
              C:\WINDOWS\system32\igfxpers.exe
              C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\Winamp\winampa.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\Program Files\DAEMON Tools Lite\daemon.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\Program Files\LogMeIn\x86\RaMaint.exe
              C:\Program Files\LogMeIn\x86\LogMeIn.exe
              C:\Program Files\LogMeIn\x86\LMIGuardian.exe
              C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
              C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
              C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
              C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
              C:\Program Files\Java\jre6\bin\jucheck.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\Windows Live\Contacts\wlcomm.exe
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: (no name) - {00e1b210-4f27-4fe7-a982-e389079d588c} - C:\WINDOWS\system32\hoyozebo.dll (file missing)
              O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
              O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
              O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
              O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
              O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
              O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
              O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
              O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
              O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
              O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
              O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
              O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
              O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
              O4 - HKLM\..\Run: [ccb7dd84] rundll32.exe "C:\WINDOWS\system32\dizihupe.dll",b
              O4 - HKLM\..\Run: [CPMcf84ee18] Rundll32.exe "c:\windows\system32\voyuvofe.dll",a
              O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
              O4 - HKUS\S-1-5-19\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'postgres')
              O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'postgres')
              O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
              O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
              O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
              O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
              O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
              O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
              O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
              O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
              O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
              O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
              O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
              O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
              O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
              O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
              O15 - Trusted Zone: http://*.facebook.com
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
              O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - https://sdlc-esd.oracle.com/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab?GroupName=JSC&FilePath=/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab&BHost=javadl.sun.com&File=jinstall-6u10-windows-i586-jc.cab&AuthParam=1580987764_a5235be86e79daca0cfb05ddc36bfbcd&ext=.cab
              O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
              O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
              O20 - AppInit_DLLs: wasyhy.dll c:\windows\system32\nuwemuno.dll C:\WINDOWS\system32\wesepani.dll c:\windows\system32\voyuvofe.dll
              O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\voyuvofe.dll
              O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\voyuvofe.dll
              O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
              O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
              O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
              O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
              O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
              O24 - Desktop Component 0: (no name) - http://tbn0.google.com/...
              1. Contributeur sécurité
                Tu es encore infecté.

                Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
                Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau.

                Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
                comment demarrer en mode sans echec en images
                Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
                A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
                Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
                Choisis ton compte.

                Déroule la liste des instructions ci-dessous :

                * Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
                * Appuie sur Y pour commencer le processus de nettoyage.
                Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                * Appuie sur une touche pour redémarrer le PC.
                Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                * Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
                Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum

                Tuto d'instalation et de mise en oeuvre
                1. voilà

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 15:52:18, on 2008-12-03
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.5730.0013)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
                  C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Program Files\Winamp\winampa.exe
                  C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\WINDOWS\system32\rundll32.exe
                  C:\Program Files\DAEMON Tools Lite\daemon.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  C:\Program Files\LogMeIn\x86\RaMaint.exe
                  C:\Program Files\LogMeIn\x86\LogMeIn.exe
                  C:\Program Files\LogMeIn\x86\LMIGuardian.exe
                  C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Windows Live\Contacts\wlcomm.exe
                  C:\Program Files\PokerStars\PokerStars.exe
                  C:\Program Files\PokerTracker 3\PokerTracker.exe
                  C:\Program Files\PokerTracker 3\PokerTracker.exe
                  C:\Program Files\PokerTracker 3\PokerTrackerHud.exe
                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: (no name) - {00e1b210-4f27-4fe7-a982-e389079d588c} - C:\WINDOWS\system32\hoyozebo.dll (file missing)
                  O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
                  O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                  O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                  O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
                  O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
                  O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
                  O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
                  O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                  O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
                  O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                  O4 - HKLM\..\Run: [ccb7dd84] rundll32.exe "C:\WINDOWS\system32\dizihupe.dll",b
                  O4 - HKLM\..\Run: [CPMcf84ee18] Rundll32.exe "c:\windows\system32\voyuvofe.dll",a
                  O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
                  O4 - HKUS\S-1-5-19\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'postgres')
                  O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'postgres')
                  O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
                  O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
                  O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
                  O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                  O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                  O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                  O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                  O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                  O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                  O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                  O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                  O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                  O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                  O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                  O15 - Trusted Zone: http://*.facebook.com
                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                  O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - https://sdlc-esd.oracle.com/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab?GroupName=JSC&FilePath=/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab&BHost=javadl.sun.com&File=jinstall-6u10-windows-i586-jc.cab&AuthParam=1580987764_a5235be86e79daca0cfb05ddc36bfbcd&ext=.cab
                  O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
                  O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
                  O20 - AppInit_DLLs: wasyhy.dll c:\windows\system32\nuwemuno.dll C:\WINDOWS\system32\wesepani.dll c:\windows\system32\voyuvofe.dll
                  O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\voyuvofe.dll
                  O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\voyuvofe.dll
                  O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                  O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
                  O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
                  O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                  O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                  O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
                  O24 - Desktop Component 0: (no name) - http://tbn0.google.com/...
                  1. Contributeur sécurité
                    apparament, Avira l'a supprimé

                    Refais moi un log HJT tout frais stp...

                    Ø Relance Hijackthis en double cliquant sur son raccourci sur le Bureau.
                    Choisis l'option "Do a system scan and save a log file"
                    Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
                    Clique sur "Edition" ->> "Sélectionner tout", puis sur "Edition" ->> Copier" pour copier tout le contenu du rapport ici
                    1. Bon j'ai faite l'analyse en mode sans echec avec avira
                      dsl du delais j'ai du recommencé l'analyse trois fois car elle gelais et je suis assez temps ci mais peu importe
                      Apres que j'ai redémarré mon ordinateur apres l'analyse le virus était encore la..
                      A chaque infection signalé j'ai demandé de supprimé
                      Voici le rapport

                      Avira AntiVir Personal
                      Report file date: 3 décembre 2008 12:01

                      Scanning for 1070676 virus strains and unwanted programs.

                      Licensed to: Avira AntiVir PersonalEdition Classic
                      Serial number: 0000149996-ADJIE-0001
                      Platform: Windows XP
                      Windows version: (Service Pack 2) [5.1.2600]
                      Boot mode: Save mode
                      Username: Admin
                      Computer name: XPSP2-7890337B3

                      Version information:
                      BUILD.DAT : 8.2.0.337 16934 Bytes 2008-11-18 13:05:00
                      AVSCAN.EXE : 8.1.4.10 315649 Bytes 2008-11-18 14:21:26
                      AVSCAN.DLL : 8.1.4.0 40705 Bytes 2008-05-26 13:56:40
                      LUKE.DLL : 8.1.4.5 164097 Bytes 2008-06-12 18:44:19
                      LUKERES.DLL : 8.1.4.0 12033 Bytes 2008-05-26 13:58:52
                      ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 2008-10-27 17:30:36
                      ANTIVIR1.VDF : 7.1.0.56 411136 Bytes 2008-11-09 22:57:13
                      ANTIVIR2.VDF : 7.1.0.160 571392 Bytes 2008-11-30 18:01:12
                      ANTIVIR3.VDF : 7.1.0.178 149504 Bytes 2008-12-03 12:35:59
                      Engineversion : 8.2.0.36
                      AEVDF.DLL : 8.1.0.6 102772 Bytes 2008-10-14 16:05:56
                      AESCRIPT.DLL : 8.1.1.15 332156 Bytes 2008-11-11 20:00:07
                      AESCN.DLL : 8.1.1.5 123251 Bytes 2008-11-07 21:06:41
                      AERDL.DLL : 8.1.1.3 438645 Bytes 2008-11-04 19:58:38
                      AEPACK.DLL : 8.1.3.4 393591 Bytes 2008-11-11 15:41:39
                      AEOFFICE.DLL : 8.1.0.30 196986 Bytes 2008-11-07 21:06:41
                      AEHEUR.DLL : 8.1.0.71 1487222 Bytes 2008-11-07 21:06:41
                      AEHELP.DLL : 8.1.2.0 119159 Bytes 2008-12-02 18:01:16
                      AEGEN.DLL : 8.1.1.6 323955 Bytes 2008-12-02 18:01:16
                      AEEMU.DLL : 8.1.0.9 393588 Bytes 2008-10-14 16:05:56
                      AECORE.DLL : 8.1.5.2 172405 Bytes 2008-12-02 18:01:15
                      AEBB.DLL : 8.1.0.3 53618 Bytes 2008-10-14 16:05:56
                      AVWINLL.DLL : 1.0.0.12 15105 Bytes 2008-07-09 14:40:05
                      AVPREF.DLL : 8.0.2.0 38657 Bytes 2008-05-16 15:28:01
                      AVREP.DLL : 8.0.0.2 98344 Bytes 2008-07-31 18:02:15
                      AVREG.DLL : 8.0.0.1 33537 Bytes 2008-05-09 17:26:40
                      AVARKT.DLL : 1.0.0.23 307457 Bytes 2008-02-12 14:29:23
                      AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 2008-06-12 18:27:49
                      SQLITE3.DLL : 3.3.17.1 339968 Bytes 2008-01-22 23:28:02
                      SMTPLIB.DLL : 1.2.0.23 28929 Bytes 2008-06-12 18:49:40
                      NETNT.DLL : 8.0.0.1 7937 Bytes 2008-01-25 18:05:10
                      RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 2008-06-12 19:48:07
                      RCTEXT.DLL : 8.0.52.0 86273 Bytes 2008-06-27 19:34:37

                      Configuration settings for the scan:
                      Jobname..........................: Complete system scan
                      Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                      Logging..........................: low
                      Primary action...................: interactive
                      Secondary action.................: ignore
                      Scan master boot sector..........: on
                      Scan boot sector.................: on
                      Boot sectors.....................: C:,
                      Process scan.....................: on
                      Scan registry....................: on
                      Search for rootkits..............: off
                      Scan all files...................: Intelligent file selection
                      Scan archives....................: on
                      Recursion depth..................: 20
                      Smart extensions.................: on
                      Macro heuristic..................: on
                      File heuristic...................: medium

                      Start of the scan: 3 décembre 2008 12:01

                      The scan of running processes will be started
                      Scan process 'avscan.exe' - '1' Module(s) have been scanned
                      Scan process 'notepad.exe' - '1' Module(s) have been scanned
                      Scan process 'avscan.exe' - '1' Module(s) have been scanned
                      Scan process 'igfxsrvc.exe' - '1' Module(s) have been scanned
                      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                      Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                      Scan process 'explorer.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'lsass.exe' - '1' Module(s) have been scanned
                      Scan process 'services.exe' - '1' Module(s) have been scanned
                      Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                      Scan process 'csrss.exe' - '1' Module(s) have been scanned
                      Scan process 'smss.exe' - '1' Module(s) have been scanned
                      15 processes with 15 modules were scanned

                      Starting master boot sector scan:
                      Master boot sector HD0
                      [INFO] No virus was found!

                      Start scanning boot sectors:
                      Boot sector 'C:\'
                      [INFO] No virus was found!

                      Starting to scan the registry.
                      The registry was scanned ( '58' files ).

                      Starting the file scan:

                      Begin scan in 'C:\'
                      C:\pagefile.sys
                      [WARNING] The file could not be opened!
                      C:\WINDOWS\system32\wojujive.dll
                      [DETECTION] Is the TR/Spy.Agent.evp Trojan
                      [NOTE] The file was deleted!
                      C:\WINDOWS\system32\drivers\sptd.sys
                      [WARNING] The file could not be opened!

                      End of the scan: 3 décembre 2008 15:20
                      Used time: 3:19:21 Hour(s)

                      The scan has been done completely.

                      4639 Scanning directories
                      303339 Files were scanned
                      1 viruses and/or unwanted programs were found
                      0 Files were classified as suspicious:
                      1 files were deleted
                      0 files were repaired
                      0 files were moved to quarantine
                      0 files were renamed
                      2 Files cannot be scanned
                      303336 Files not concerned
                      3488 Archives were scanned
                      2 Warnings
                      1 Notes
                      1. Contributeur sécurité
                        Tu n'as aucun antivirus sur le pc !

                        télécharge AVIRA Antivir ( gratuit et performant ) sur le lien suivant.
                        https://www.clubic.com/telecharger-fiche10821-avira-antivir-personal-free-antivirus.html

                        Installe ANTIVIR...
                        TUTO D' installation par Malekal
                        Tuto D'instalation et de mise en Oeuvre
                        Encore un au cas ou...
                        Reconnecte toi, fais les mises à jours Antivir... tu seras mieux protégé !

                        Après l'installation, mets le à jour - si ton firewall fait une alerte.. accepte la connexion.
                        Assure toi qu'Antivir est bien à jour, ( clic droit sur le parapluie => Start Update ) et laisse faire la MàJ.

                        Redémarre en mode sans échec !
                        Pour cela, redémarre l'ordinateur, avant le logo Windows, tapote sur la touche F8, un menu va apparaître, choisis Mode sans échec et appuye sur la touche entrée du clavier.

                        - Ouvre Antivir par le menu Démarrer / Programmes
                        - Cliquez sur l'onglet Scanner.
                        - Sélectionne Manual Selection
                        - Sélectionne le disque C
                        - Lance le scan - Mets en quarantaine tous les éléments détectés.
                        - Une fois le scan terminé Enregistre le rapport.

                        Redémarre en mode normal.

                        Poste le rapport ici.
                        1. Contributeur sécurité
                          Avec une version XP modifiée, faut pas être étonné.

                          Je te prépare la suite, je reviens.
                          1. Voici un hijackthis apres les 2 analyse
                            Jespere que vs aurez une solution pour qu'il ne revienne plus

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 08:09:07, on 2008-12-02
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v7.00 (7.00.5730.0013)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
                            C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
                            C:\WINDOWS\system32\igfxtray.exe
                            C:\WINDOWS\system32\hkcmd.exe
                            C:\WINDOWS\system32\igfxpers.exe
                            C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
                            C:\Program Files\Java\jre6\bin\jusched.exe
                            C:\Program Files\Winamp\winampa.exe
                            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                            C:\Program Files\DAEMON Tools Lite\daemon.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe
                            C:\Program Files\Java\jre6\bin\jqs.exe
                            C:\Program Files\LogMeIn\x86\RaMaint.exe
                            C:\Program Files\LogMeIn\x86\LogMeIn.exe
                            C:\Program Files\LogMeIn\x86\LMIGuardian.exe
                            C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                            C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                            C:\WINDOWS\system32\NOTEPAD.EXE
                            C:\Program Files\Internet Explorer\IEXPLORE.EXE
                            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            O2 - BHO: (no name) - {00e1b210-4f27-4fe7-a982-e389079d588c} - C:\WINDOWS\system32\hoyozebo.dll (file missing)
                            O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
                            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                            O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                            O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
                            O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
                            O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                            O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                            O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
                            O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
                            O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                            O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                            O4 - HKLM\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s
                            O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            O4 - HKUS\S-1-5-19\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\Run: [lafoyagune] Rundll32.exe "C:\WINDOWS\system32\kipojamo.dll",s (User 'postgres')
                            O4 - HKUS\S-1-5-21-1957994488-1844237615-725345543-1006\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'postgres')
                            O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
                            O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
                            O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
                            O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                            O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                            O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                            O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                            O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                            O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                            O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                            O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                            O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                            O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                            O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
                            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                            O15 - Trusted Zone: http://*.facebook.com
                            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                            O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - https://sdlc-esd.oracle.com/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab?GroupName=JSC&FilePath=/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab&BHost=javadl.sun.com&File=jinstall-6u10-windows-i586-jc.cab&AuthParam=1580987764_a5235be86e79daca0cfb05ddc36bfbcd&ext=.cab
                            O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
                            O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
                            O20 - AppInit_DLLs: wasyhy.dll c:\windows\system32\nuwemuno.dll C:\WINDOWS\system32\wesepani.dll
                            O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                            O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
                            O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
                            O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
                            O24 - Desktop Component 0: (no name) - http://tbn0.google.com/...
                            1. J'ai refait un analyse apres malgré l'absence de symptome et le virus semblais encore la..
                              peu de temps apres la premiere analyse

                              Malwarebytes' Anti-Malware 1.30
                              Version de la base de données: 1445
                              Windows 5.1.2600 Service Pack 2

                              2008-12-02 08:05:07
                              mbam-log-2008-12-02 (08-05-07).txt

                              Type de recherche: Examen rapide
                              Eléments examinés: 76374
                              Temps écoulé: 7 minute(s), 32 second(s)

                              Processus mémoire infecté(s): 0
                              Module(s) mémoire infecté(s): 3
                              Clé(s) du Registre infectée(s): 3
                              Valeur(s) du Registre infectée(s): 5
                              Elément(s) de données du Registre infecté(s): 2
                              Dossier(s) infecté(s): 0
                              Fichier(s) infecté(s): 5

                              Processus mémoire infecté(s):
                              (Aucun élément nuisible détecté)

                              Module(s) mémoire infecté(s):
                              C:\WINDOWS\system32\nulojaka.dll (Trojan.Vundo.H) -> Delete on reboot.
                              C:\WINDOWS\system32\ladahawe.dll (Trojan.Vundo) -> Delete on reboot.
                              C:\WINDOWS\system32\hapameva.dll (Trojan.BHO) -> Delete on reboot.

                              Clé(s) du Registre infectée(s):
                              HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.

                              Valeur(s) du Registre infectée(s):
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ccb7dd84 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.BHO) -> Quarantined and deleted successfully.
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpmcf84ee18 (Trojan.Agent) -> Quarantined and deleted successfully.
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lafoyagune (Trojan.Agent) -> Quarantined and deleted successfully.

                              Elément(s) de données du Registre infecté(s):
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: c:\windows\system32\hapameva.dll -> Quarantined and deleted successfully.
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: system32\hapameva.dll -> Quarantined and deleted successfully.

                              Dossier(s) infecté(s):
                              (Aucun élément nuisible détecté)

                              Fichier(s) infecté(s):
                              C:\WINDOWS\system32\ladahawe.dll (Trojan.Vundo.H) -> Delete on reboot.
                              C:\WINDOWS\system32\ewahadal.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                              C:\WINDOWS\system32\nulojaka.dll (Trojan.Vundo.H) -> Delete on reboot.
                              C:\WINDOWS\system32\akajolun.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                              c:\WINDOWS\system32\hapameva.dll (Trojan.BHO) -> Delete on reboot.
                              1. le Virus en encore revnue peu de temps après que j'ai redémarré l'ordinateur
                                Ce n'était pas la premeire fois que jutilisait malware byte, et chaque fois que j'ai tenté de le supprimé de cette facon le virus est revenu quelques heure après

                                il doit avoir un quelques chose qui ramene le virus a chaque fois je ne sait pas quoi
                                1. Voila j'ai faite exactement ce que tu as dit

                                  Malwarebytes' Anti-Malware 1.30
                                  Version de la base de données: 1443
                                  Windows 5.1.2600 Service Pack 2

                                  2008-12-01 20:21:49
                                  mbam-log-2008-12-01 (20-21-49).txt

                                  Type de recherche: Examen complet (A:\|C:\|D:\|E:\|F:\|)
                                  Eléments examinés: 114296
                                  Temps écoulé: 19 minute(s), 1 second(s)

                                  Processus mémoire infecté(s): 0
                                  Module(s) mémoire infecté(s): 3
                                  Clé(s) du Registre infectée(s): 5
                                  Valeur(s) du Registre infectée(s): 4
                                  Elément(s) de données du Registre infecté(s): 2
                                  Dossier(s) infecté(s): 0
                                  Fichier(s) infecté(s): 7

                                  Processus mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Module(s) mémoire infecté(s):
                                  C:\WINDOWS\system32\vudifina.dll (Trojan.Vundo.H) -> Delete on reboot.
                                  C:\WINDOWS\system32\tahadevo.dll (Trojan.Vundo) -> Delete on reboot.
                                  C:\WINDOWS\system32\silahije.dll (Trojan.BHO) -> Delete on reboot.

                                  Clé(s) du Registre infectée(s):
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00e1b210-4f27-4fe7-a982-e389079d588c} (Trojan.BHO.H) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\CLSID\{00e1b210-4f27-4fe7-a982-e389079d588c} (Trojan.BHO.H) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.

                                  Valeur(s) du Registre infectée(s):
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpmcf84ee18 (Trojan.Agent) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lafoyagune (Trojan.Agent) -> Quarantined and deleted successfully.

                                  Elément(s) de données du Registre infecté(s):
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: c:\windows\system32\silahije.dll -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: system32\silahije.dll -> Quarantined and deleted successfully.

                                  Dossier(s) infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Fichier(s) infecté(s):
                                  C:\WINDOWS\system32\tahadevo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                  C:\WINDOWS\system32\ovedahat.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                  C:\WINDOWS\system32\vudifina.dll (Trojan.Vundo.H) -> Delete on reboot.
                                  C:\WINDOWS\system32\anifiduv.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                                  C:\WINDOWS\system32\hoyozebo.dll (Trojan.BHO.H) -> Delete on reboot.
                                  c:\WINDOWS\system32\silahije.dll (Trojan.BHO) -> Delete on reboot.
                                  C:\WINDOWS\system32\kipojamo.dll (Trojan.Agent) -> Delete on reboot.
                                  • 1
                                  • 2