Infection : Win32/Heur + Win32/agent.AO

Résolu
Bonjour,
Mon Pc a était infecté par un virus Win32/Junk:Poly d'aprés mes petites connaisances ce virus a téléchager d'autre virus et trojans ...
Quand j'analyse avec Avast il détécte les infections il les supprimes mais lors du redémarage sa revient encore, AVG lui aussi il arrive pas a supprimer, Hijackthis ne détécte meme pas :S, et maintenant g 16 processus nommée svhost.exe éxécuté par le system alors que je n'avais que 6 processus avec se nom.
Besoin de votre aide et merci d'avance :)
Configuration: Windows XP Pro (Service pack 2)
Avast Edition Familial
AVG Professionnel
Internet Explorer 6.0

17 réponses

  1. Contributeur sécurité
    Hijackthis ne détécte meme pas :S

    colle nous le rapport stp
    0
    1. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:51:00, on 13/03/2009
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\PROGRA~1\AVG\AVG8\avgemc.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\AVG\AVG8\avgcsrvx.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\svchost.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\TeamSpeak3\TeamSpeak.exe
      C:\WINDOWS\system32\Restore\rstrui.exe
      C:\Program Files\AVG\AVG8\avgscanx.exe
      C:\Program Files\AVG\AVG8\avgcsrvx.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\AVG\AVG8\avgui.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\windres.exe,userinit.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\undname.exe,C:\WINDOWS\system32\ndetect.exe,
      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
      O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      0
      1. Contributeur sécurité
        cela me semble un peu court comme log...!!??

        Télécharge random's system information tool (RSIT) par random/random et sauvegarde-le sur le Bureau.
        http://images.malwareremoval.com/random/RSIT.exe
        Double-clique sur RSIT.exe afin de lancer RSIT.
        Clique Continue à l'écran Disclaimer.
        Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
        Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (<<qui sera affiché)
        ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).
        NB : Les rapports sont sauvegardés dans le dossier C:\rsit
        0
        1. info.txt logfile of random's system information tool 1.05 2009-03-13 11:54:57
          ======Uninstall list======

          -->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
          -->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
          -->C:\WINDOWS\UNRecode.exe /UNINSTALL
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{107254A0-0ADF-11D4-9397-00D0B7020B38}\setup.exe"
          -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
          7-Zip 4.65-->"C:\Program Files\7-Zip\Uninstall.exe"
          Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
          Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
          Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
          Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
          Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
          Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
          Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
          Adobe Color Common Settings-->MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
          Adobe Color EU Recommended Settings-->MsiExec.exe /I{73B5D990-04EA-4751-B10F-5534770B91F2}
          Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
          Adobe Color NA Extra Settings-->MsiExec.exe /I{FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}
          Adobe Default Language CS3-->MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
          Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
          Adobe ExtendScript Toolkit 2-->C:\Program Files\Fichiers communs\Adobe\Installers\3e054d2218e7aa282c2369d939e58ff\Setup.exe
          Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}
          Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
          Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
          Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{58BAA8D0-404E-4585-9FD3-ED1BB72AC2EE}
          Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{685A56F8-75B6-44AD-B3DA-FB0A3266B47C}
          Adobe Fonts All-->MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
          Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
          Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
          Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
          Adobe Photoshop CS3-->C:\Program Files\Fichiers communs\Adobe\Installers\32e9033392a51340b32fdc6ad893ab7\Setup.exe
          Adobe Photoshop CS3-->MsiExec.exe /I{BF794769-8875-4E01-B7BE-E00104604F4A}
          Adobe Reader 8.1.3-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81300000003}
          Adobe Setup-->MsiExec.exe /I{926DEB4E-2B0A-4C5C-AE4A-BF6C06949702}
          Adobe Setup-->MsiExec.exe /I{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}
          Adobe Shockwave Player 11-->C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
          Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
          Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
          Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
          Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
          Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
          Adobe XMP Panels CS3-->MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
          AMX Mod X Installer 1.8.1-->C:\Program Files\AMX Mod X\uninst.exe
          Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
          Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
          avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
          AVG 8.0-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
          CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
          CleanUp!-->C:\Program Files\CleanUp!\uninstall.exe
          Code de la Route-->MsiExec.exe /X{A37A26D5-8444-4862-933B-478371D0299D}
          Counter-Strike-->"C:\Program Files\Steam\steam.exe" steam://uninstall/10
          Decal Converter-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5BB207D6-0E1E-11D5-9B6A-00C04F7EC248}\Setup.exe"
          DoNaut 2.0.1-->C:\Program Files\Xponaut\DoNaut\uninst.exe
          eMule-->"C:\Program Files\eMule\Uninstall.exe"
          FileZilla Client 3.2.2-->C:\Program Files\FileZilla FTP Client\uninstall.exe
          Half-Life Dedicated Server Update Tool-->E:\HLDS\UNWISE.EXE E:\HLDS\INSTALL.LOG
          High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
          HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
          HLSW v1.3.1-->"C:\Program Files\HLSW\unins000.exe"
          Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
          Intel(R) Integrator Toolkit FE-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A67B3991-7226-404B-B5F6-71962D3F2376}\Setup.exe"
          Internet Download Manager-->C:\Program Files\Internet Download Manager\Uninstall.exe
          Java(TM) 6 Update 12-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF}
          la version d'évaluation de Namo WebEdiotor 6-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EF3FA287-2622-4340-AAF6-0AD29F21A691}\setup.exe" -l0x40c
          Ma-Config.com-->MsiExec.exe /X{8AFB8FC4-3EBA-4C67-943F-CF43DB2180F1}
          Macromedia Extension Manager-->MsiExec.exe /I{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}
          Macromedia Flash 8-->MsiExec.exe /I{2BD5C305-1B27-4D41-B690-7A61172D2FEB}
          Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
          Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - FRA-->MsiExec.exe /I{3F7924B9-D148-3141-87B1-68F36043A940}
          Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
          Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - FRA-->MsiExec.exe /I{511DF669-2930-30C0-8EB6-552887E29EC8}
          Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
          Microsoft .NET Framework 3.5 Language Pack - fra-->MsiExec.exe /I{5B76AEA2-D4E5-3B55-B965-ACC36AE0EAFC}
          Microsoft .NET Framework 3.5-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\setup.exe
          Microsoft .NET Framework 3.5-->MsiExec.exe /I{2FC099BD-AC9B-33EB-809C-D332E1B27C40}
          Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
          mIRC-->C:\Program Files\mIRC\uninstall.exe _?=C:\Program Files\mIRC
          Module linguistique Microsoft .NET Framework 3.5 - fra-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack - fra\setup.exe
          Mozilla Firefox (3.0.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
          Nero 8 Ultra Edition HD-->MsiExec.exe /X{D6C9AF27-9414-46C8-B9D8-D878BA041036}
          neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
          No-IP.com DUC (remove only)-->"C:\Program Files\No-IP\DUC20.exe" -uninstall
          Pack Vista Inspirat 2 1.0-->C:\WINDOWS\BricoPacks\Vista Inspirat 2\Remove.exe
          PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
          PhotoFiltre Studio-->"C:\Program Files\PhotoFiltre Studio\Uninst.exe"
          QuickTime-->MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
          REALTEK GbE & FE Ethernet PCI-E NIC Driver-->"C:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe" -runfromtemp -l0x040c -removeonly
          Realtek High Definition Audio Driver-->RtlUpd.exe -r -m -nrg2709
          Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
          SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
          TeamSpeak Client-->"C:\Program Files\TeamSpeak3\unins000.exe"
          TrackMania Nations Forever-->"C:\Program Files\Steam\steam.exe" steam://uninstall/11020
          VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
          VDownloader 0.77-->"C:\Program Files\VDOWNLOADER\unins000.exe"
          VLC media player 0.9.2-->C:\Program Files\VideoLAN\VLC\uninstall.exe
          Wallpachange-->C:\Program Files\Wallpachange\Uninstal.exe
          WampServer 2.0-->"c:\wamp\unins000.exe"
          Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
          Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
          Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
          Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
          Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
          Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
          WinHTTrack Website Copier 3.43-2-->"C:\Program Files\WinHTTrack\unins000.exe"
          XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
          Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE

          =====HijackThis Backups=====

          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?SearchSource=10&ctid=CT2102473
          O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
          O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
          R3 - URLSearchHook: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHPN.dll
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.fr/?gws_rd=ssl
          O3 - Toolbar: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHPN.dll
          O2 - BHO: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHPN.dll
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 91.121.112.151:3128
          O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
          O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
          O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 193.55.112.41:3128
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.files-ftp.com/~unicorni/phpBB2/index.php
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
          O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
          O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
          O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
          O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O4 - HKCU\..\Run: [DoNaut] "C:\Program Files\Xponaut\DoNaut\DoNaut.exe" --minimized
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 193.55.112.41:3128
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
          O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.32\bin\mysqld.exe
          O23 - Service: CSIScanner - Prevx - C:\Program Files\Prevx\prevx.exe
          O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\MaG\reader_s.exe (User 'SYSTEM')
          O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
          O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
          O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
          O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
          O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

          ======Hosts File======

          127.0.0.1 jL.chura.pl

          ======Security center information======

          AV: AVG Anti-Virus
          AV: avast! antivirus 4.8.1335 [VPS 090312-0] (disabled)

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
          "windir"=%SystemRoot%
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "PROCESSOR_ARCHITECTURE"=x86
          "PROCESSOR_LEVEL"=6
          "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 2, GenuineIntel
          "PROCESSOR_REVISION"=0f02
          "NUMBER_OF_PROCESSORS"=2
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP
          "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
          "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

          -----------------EOF-----------------

          Log.txt =
          Logfile of random's system information tool 1.05 (written by random/random)
          Run by MaG at 2009-03-13 11:54:52
          Microsoft Windows XP Professionnel Service Pack 2
          System drive C: has 39 GB (65%) free of 60 GB
          Total RAM: 1012 MB (51% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 11:54:54, on 13/03/2009
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\PROGRA~1\AVG\AVG8\avgemc.exe
          C:\PROGRA~1\AVG\AVG8\avgrsx.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\AVG\AVG8\avgcsrvx.exe
          C:\WINDOWS\system32\wbem\wmiapsrv.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\svchost.exe
          C:\PROGRA~1\AVG\AVG8\avgtray.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\WINDOWS\system32\Restore\rstrui.exe
          C:\Program Files\AVG\AVG8\avgscanx.exe
          C:\Program Files\AVG\AVG8\avgcsrvx.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Documents and Settings\MaG\Bureau\RSIT.exe
          C:\Program Files\Trend Micro\HijackThis\MaG.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\windres.exe,userinit.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\undname.exe,C:\WINDOWS\system32\ndetect.exe,
          O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
          O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
          O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
          O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
          O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
          O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          0
          1. Contributeur sécurité
            bon,y a du taf en vue

            et ton rapport n'est pas complet

            Télécharge SDfix (créé par AndyManchesta) et sauvegarde le sur ton Bureau. Tu peux suivre le tutorial SDFix de Malekal pour t'aider :

            Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
            Redémarre ton ordinateur
            Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
            A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
            Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
            Choisis ton compte.

            Déroule la liste des instructions ci-dessous :
            Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
            Appuie sur Y pour commencer le nettoyage.

            Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
            Appuie sur une touche pour redémarrer le PC.
            Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
            Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.

            Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
            Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
            Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !

            Si SDFix ne se lance pas
            Clique sur Démarrer > Exécuter
            Copie/colle ceci :
            %systemroot%\system32\cmd.exe /K %systemdrive%\SDFix\apps\FixPath.exe

            Clique sur Ok.
            Redémarre et essaie de relance SDFix.

            ensuite

            Télécharge SmitFraudfix de S!Ri, balltrap34 et moe31
            http://siri.urz.free.fr/Fix/SmitfraudFix.zip -
            en cas de problème avec le premier lien,
            mirroir: http://72.232.135.12/siri/SmitfraudFix.php

            voila à quoi cela ressemble : http://siri.urz.free.fr/Fix/SmitfraudFix.php
            une aide en vidéo (merci à balltrap34)
            http://pagesperso-orange.fr/rginformatique/section%20virus/smitfraudfix.htm

            Désactive les logiciels de protections(antivirus et antispyware)
            -- Fais un clic droit puis Extraire tout sur le fichier SmitfraudFix.zip, cela va tout décompresser dans un nouveau dossier SmitFraudfix
            -- Ouvre le dossier SmitfraudFix double-clique sur SmitfraudFix.cmd (le .cmd peut ne pas être présent)
            -- Choisis l'option 1 et appuie sur Entrée
            -- Réponds o (Oui) aux deux questions suivantes si elles sont posées
            -- Un rapport sera généré; sauvegarde le dans un dossier.
            -- Copie/colle le contenu du rapport ici
            0
            1. Report.txt[b]SDFix: Version 1.240 [/b]
              Run by MaG on 13/03/2009 at 12:16

              Microsoft Windows XP [version 5.1.2600]
              Running From: C:\SDFix

              [b]Checking Services [/b]:

              [b]Name [/b]:
              restore

              [b]Path [/b]:
              \??\C:\WINDOWS\system32\drivers\restore.sys

              restore - Deleted

              Restoring Default Security Values
              Restoring Default Hosts File

              Rebooting

              [b]Checking Files [/b]:

              Trojan Files Found:

              C:\WINDOWS\system32\3.tmp - Deleted
              C:\WINDOWS\system32\4.tmp - Deleted
              C:\WINDOWS\system32\5.tmp - Deleted
              C:\WINDOWS\system32\6.tmp - Deleted
              C:\WINDOWS\system32\7.tmp - Deleted
              C:\WINDOWS\system32\8.tmp - Deleted
              C:\WINDOWS\system32\9.tmp - Deleted
              C:\WINDOWS\system32\A.tmp - Deleted
              C:\WINDOWS\system32\B.tmp - Deleted
              C:\WINDOWS\system32\C.tmp - Deleted
              C:\WINDOWS\system32\D.tmp - Deleted
              C:\WINDOWS\system32\E.tmp - Deleted
              C:\WINDOWS\system32\F.tmp - Deleted
              C:\WINDOWS\system32\10.tmp - Deleted
              C:\WINDOWS\system32\11.tmp - Deleted
              C:\WINDOWS\system32\12.tmp - Deleted
              C:\WINDOWS\services.exe - Deleted

              Removing Temp Files

              [b]ADS Check [/b]:

              [b]Final Check [/b]:

              catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2009-03-13 13:37:42
              Windows 5.1.2600 Service Pack 2 NTFS

              detected NTDLL code modification:
              ZwOpenFile

              scanning hidden processes ...

              scanning hidden services & system hive ...

              scanning hidden registry entries ...

              scanning hidden files ...

              scan completed successfully
              hidden processes: 0
              hidden services: 0
              hidden files: 0

              [b]Remaining Services [/b]:

              Authorized Application Key Export:

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
              "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
              "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
              "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
              "\\??\\C:\\WINDOWS\\system32\\winlogon.exe"="\\??\\C:\\WINDOWS\\system32\\winlogon.exe:*:enabled:@shell32.dll,-1"

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
              "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
              "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

              [b]Remaining Files [/b]:

              File Backups: - C:\SDFix\backups\backups.zip

              [b]Files with Hidden Attributes [/b]:

              Thu 26 Feb 2009 1,386 ...H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\Colored Flash\colored_flashbangs.sma.bak"
              Thu 26 Feb 2009 4,302 ...H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\Country Plugin\GHW_connect.sma.bak"
              Wed 25 Feb 2009 4,033 ...H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\Fire in The Holl Color\descriptive_fire_in_the_hole.sma.bak"
              Wed 11 Mar 2009 1,768 ...H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\Radio\shamusi_music_plugin.sma.bak"
              Wed 11 Mar 2009 2,743 ...H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\SpecT List\speclist.sma.bak"
              Wed 4 Mar 2009 3,767 A..H. --- "C:\Documents and Settings\MaG\Bureau\NoLiF3 Project\Unstuckin\stuck.sma.bak"
              Wed 25 Feb 2009 11,984 A..H. --- "C:\Documents and Settings\MaG\Bureau\Plugins\Hats Plugin\Hats08.sma.bak"

              [b]Finished![/b]
              0
              1. <gras>rapport.txt (Smitfraudfix)</gras>

                SmitFraudFix v2.403

                Rapport fait à 13:44:04,67, 13/03/2009
                Executé à partir de C:\Documents and Settings\MaG\Bureau\SmitfraudFix\SmitfraudFix
                OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                Le type du système de fichiers est NTFS
                Fix executé en mode normal

                »»»»»»»»»»»»»»»»»»»»»»»» Process

                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                C:\PROGRA~1\AVG\AVG8\avgemc.exe
                C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                C:\Program Files\AVG\AVG8\avgcsrvx.exe
                C:\WINDOWS\system32\wscntfy.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\AVG\AVG8\avgscanx.exe
                C:\Program Files\AVG\AVG8\avgcsrvx.exe
                C:\WINDOWS\system32\notepad.exe
                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                C:\WINDOWS\system32\cmd.exe

                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                »»»»»»»»»»»»»»»»»»»»»»»» C:\

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\MaG

                »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MaG\LOCALS~1\Temp

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\MaG\Application Data

                »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MaG\Favoris

                »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                "Source"="About:Home"
                "SubscribedURL"="About:Home"
                "FriendlyName"="Ma page d'accueil"

                »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                o4Patch
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                Agent.OMZ.Fix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                SrchSTS.exe by S!Ri
                Search SharedTaskScheduler's .dll

                »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                "AppInit_DLLs"=""
                "LoadAppInit_DLLs"=dword:00000001

                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,C:\\WINDOWS\\system32\\windres.exe,userinit.exe,C:\\WINDOWS\\system32\\deviceemulator.exe,C:\\WINDOWS\\system32\\undname.exe,C:\\WINDOWS\\system32\\ndetect.exe,C:\\WINDOWS\\system32\\codeblocks.exe,"
                "System"=""

                »»»»»»»»»»»»»»»»»»»»»»»» RK

                »»»»»»»»»»»»»»»»»»»»»»»» DNS

                Description: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC - Miniport d'ordonnancement de paquets
                DNS Server Search Order: 192.168.2.1

                HKLM\SYSTEM\CCS\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                HKLM\SYSTEM\CS1\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                HKLM\SYSTEM\CS2\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

                »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                »»»»»»»»»»»»»»»»»»»»»»»» Fin
                0
                1. Contributeur sécurité
                  Redémarre l'ordinateur en mode sans échec .
                  Comment aller en Mode sans échec
                  1) Redémarre ton ordi
                  2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                  3) Tu verras un écran avec options de démarrage apparaître
                  4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                  5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
                  ( ps : n'oublies pas , en mode sans échec , pas de connexion ! Donc copie ou imprime bien les infos ci-dessous ...)

                  *Double click sur SmitfraudFix.exe

                  * Sélectionnes 2 et presses "Entrée" dans le menu pour supprimer les fichiers responsables de l'infection.

                  * A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et presse Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection.

                  ( Le correctif déterminera si le fichier wininet.dll est infecté.)

                  * A la question: "Corriger le fichier infecté ?" répondre O (oui) et presser Entrée
                  pour remplacer le fichier corrompu.

                  * Un redémarrage sera peut être nécessaire pour terminer la procédure de nettoyage ( sinon fais le manuellement )

                  Le rapport se trouve à la racine de C\:
                  (dans le fichier "rapport.txt")

                  Poste ce dernier rapport accompagné, dans la même réponse, d'un nouveau rapport hijackthis ( fais en mode normal )
                  0
                  1. SmitFraudFix v2.403

                    Rapport fait à 14:02:25,12, 13/03/2009
                    Executé à partir de C:\Documents and Settings\MaG\Bureau\Anti-Virus\SmitfraudFix
                    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                    Le type du système de fichiers est NTFS
                    Fix executé en mode sans echec

                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                    127.0.0.1 jL.chura.pl
                    127.0.0.1 localhost

                    »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                    VACFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                    S!Ri's WS2Fix: LSP not Found.

                    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                    GenericRenosFix by S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                    IEDFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

                    Agent.OMZ.Fix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                    404Fix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» RK

                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                    HKLM\SYSTEM\CS2\Services\Tcpip\..\{2592F4CC-F802-443F-BA31-427DE97F2EF9}: DhcpNameServer=192.168.2.1
                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                    HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

                    »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    "System"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                    Nettoyage terminé.

                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Fin

                    Hijackthis.log

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 14:13:33, on 13/03/2009
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                    C:\PROGRA~1\AVG\AVG8\avgemc.exe
                    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                    C:\Program Files\AVG\AVG8\avgcsrvx.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\wscntfy.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Program Files\AVG\AVG8\avgscanx.exe
                    C:\Program Files\AVG\AVG8\avgcsrvx.exe
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\windres.exe,userinit.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\undname.exe,C:\WINDOWS\system32\ndetect.exe,C:\WINDOWS\system32\codeblocks.exe,C:\WINDOWS\system32\c++.exe,
                    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
                    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
                    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                    0
                    1. Contributeur sécurité
                      mmmm!

                      poste moi un nouveau rapport rsit stp

                      uniquement log.txt
                      0
                      1. Logfile of random's system information tool 1.05 (written by random/random)
                        Run by MaG at 2009-03-13 14:40:49
                        Microsoft Windows XP Professionnel Service Pack 2
                        System drive C: has 44 GB (73%) free of 60 GB
                        Total RAM: 1012 MB (40% free)

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 14:41:15, on 13/03/2009
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                        C:\PROGRA~1\AVG\AVG8\avgemc.exe
                        C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                        C:\Program Files\AVG\AVG8\avgcsrvx.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\wscntfy.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\AVG\AVG8\avgscanx.exe
                        C:\Program Files\AVG\AVG8\avgcsrvx.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\Program Files\uTorrent\uTorrent.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Documents and Settings\MaG\Bureau\Anti-Virus\RSIT.exe
                        C:\Program Files\Trend Micro\HijackThis\MaG.exe
                        C:\Program Files\Internet Download Manager\IDMan.exe

                        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\windres.exe,userinit.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\undname.exe,C:\WINDOWS\system32\ndetect.exe,C:\WINDOWS\system32\codeblocks.exe,C:\WINDOWS\system32\c++.exe,
                        O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                        O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
                        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\eMule.exe -AutoStart
                        O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
                        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                        O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
                        O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                        O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                        0
                        1. Contributeur sécurité
                          bon,

                          tes dans le caca...

                          ---- C:\WINDOWS\system32\reader_s.exe c'est du virut

                          avant de continuer ta désinfection,tu dois impérativement faire un scan en ligne pour voir si ton OS est touché!

                          virut est un virus polymorphe;n'ouvre plus aucun fichier .exe il serait inmanquablement contaminé

                          **désactive ton antivirus, logiciels de protections et logiciels pouvant bloquer les popups (barres Google, barres Yahoo etc..).**

                          Ouvre internet explorer --> Outils --> Options internet --> onglet "sécurité" --> Valide "niveau par défaut".
                          Toujours sur Internet explorer --> Outils --> Options internet --> onglet "avancé" --> valide "Paramètres par défaut".

                          Scan en ligne avec Kaspersky :
                          - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr en utilisant Internet Explorer et pas Firefox, ça ne marchera pas!.
                          - Si tu es perdu, tu peux suivre l'aide pour les scans en ligne https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId291566

                          AIDE : Configurer le contrôle des ActiveX < http://www.inoculer.com/activex.php3 >
                          Tuto ici si problème : http://www.vista-xp.fr/forum/topic109.html , ou là : https://forum.pcastuces.com/sujet.asp?f=25&s=37641 (par Morgane & nico_dodo)

                          - Au moment de choisir la cible à analyser, clique sur le bouton Paramètres d'analyse
                          - Dans la nouvelle fenêtre, coche "étendu" au milieu puis clique sur OK.
                          - Choisis le poste de travail dans la cible à analyser
                          - Copie/colle le rapport du scan ici

                          NOTE : Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner,
                          reconnecte-toi sur le site de Kaspersky pour retenter le scan en ligne.

                          ensuite

                          Va par le panneau de configuration dans Options d'alimentation et mets "jamais" partout; le pc ne DOIT pas se mettre en veille.

                          Télécharge le dernier AVP de la liste ( en bas): ftp://ftp.kaspersky.com/devbuilds/AVPTool/ Enregistre-le sur le bureau.

                          Tu ne vas pas devoir le surveiller, tu n'as qu'à choisir "Disinfect" et " apply to all" et l'outil poursuivra son travail tout seul pendant que tu dormiras.

                          Ne coche surtout pas la case DELETE!!!

                          Le scan est plus ou moins long selon la puissance des pc et du nombre de fichiers à analyser.

                          Le rapport étant très lourd, tu ne devras poster que le début qui parle des découvertes et traitements effectués.

                          Si tu avais un problème avec ce rapport, sauvegarde-le quel que soit son poids, je te donnerai un lien pour l'héberger.

                          SCANNER AVEC AVP TOOL

                          Le scan va s'effectuer en Mode Sans Echec: comme tu n'auras pas accès à Internet, je te conseille d'imprimer cette procédure.
                          Télécharge et enregistre sur ton Bureau le scanner portable AVP TOOL (sélectionne-la à partir des dates) en cliquant sur le lien:
                          http://downloads5.kaspersky-labs.com/devbuilds/AVPTool/

                          Redémarre en mode sans échec, pour cela, redémarre l'ordinateur, avant le logo Windows, tapote sur la touche F8, un menu va apparaître,
                          choisis Mode sans échec et appuye sur la touche entrée du clavier.

                          Choisis ton compte.
                          Connecte éventuellement tes clés USB et disques externes.

                          Lance l'exécutable intitulé "setup_7.0xxxxx" en double-cliquant dessus
                          Réponds "Oui" à la question "Do you want to continue installation?"
                          Clique sur "Next" pour les deux fenêtres suivantes: AVP TOOL s'installe sur ton Bureau dans un dossier nommé "Kaspersky Lab Tool"
                          Si nécessaire, branche tes périphériques amovibles (clés USB, disque dur externe...)
                          L'outil se lance tout seul: coche toutes les cases dans l'onglet "Automatic Scan".
                          Clique maintenant sur "Security Level": une fenêtre de configuration s'ouvre: paramètre le scanner comme ceci:

                          Dans "security level" laisse le curseur sur "Recommended"

                          Dans "Action"
                          coche "Prompt for action when the scan is complète"
                          coche "Disinfect" et "Delete if disinfection fails"

                          Dans "Self-defense options"
                          coche "Disable external service control"

                          Valide avec "Apply" puis "OK"
                          L'outil est maintenant configuré: dans la fenêtre principale, clique sur "Scan".
                          Le scan commence, une nouvelle fenêtre s'ouvre indiquant la progression du balayage en pourcentage.
                          A la fin du scan, AVP Tool signale les objets infectés par l'intermédiaire d'une pop-up: coche alors "Apply to all" et clique sur "Delete" ou "Disinfect" selon ce que propose la fenêtre:

                          Une fois les infections traitées par l'intermédiaire des pop-ups, il se peut que des fichiers malsains n'aient pas été supprimés: ils apparaissent en rouge dans la liste: clique alors sur le bouton "Neutralize all" de la fenêtre de progression du scan: si une pop-up indique qu'il faut redémarrer, accepte en cliquant sur "OK"
                          Rends-toi maintenant dans l'onglet "Events" de la fenêtre de progression du scan, et décoche "Show all events"
                          Clique enfin sur "Reports" puis "Save to file" et enregistre le rapport sur ton Bureau sous le nom Rapport AVP TOOL
                          Ferme les fenêtres d'AVP Tool: un message apparaît proposant de désinstaller le logiciel: choisis "YES"

                          Un message d'alerte indique que le PC doit être redémarré pour finir la désinstallation:

                          A la question "Would you like to restart now", répond "OUI" et redémarre ton ordinateur en Mode normal.
                          Poste le contenu du rapport dans ta prochaine réponse

                          Un conseil: désinfecte ce qui peut l'être, sinon "Delete".
                          NB: l'outil doit être désinstallé quand il le demandera car il ne peut pas rester sur l'ordi; il causerait des conflits.
                          0
                          1. Merci pour ta méthode mon Pc est Clean maintenant :)
                            0
                            1. Contributeur sécurité
                              ah bin tant mieux,mais poste les rapports quand même,cette crasse de virut est vachement tenace...
                              0
                              1. J'ai fini kan meme par reformater mon PC, psk la vrm tt les logiciels sont désinfécter et donc ils marchent plus :S
                                Mais jte demande aprés ke j'ai formater kel Antivirus Gratuit prendre ?
                                0
                                1. Contributeur sécurité
                                  pour moi..et pour beaucoup d'autres..c'est
                                  pour installer Antivir en français

                                  le tuto

                                  mais c'est surtout ta manière de surfer sur le net qui est prépondérante

                                  plus d'info ici
                                  Prévention & Sécurité sur le net(Format pdf)
                                  1
                                  1. Merci pour ton aide Chimay. +1 :)
                                    0