Probleme myzor

Bonjour, je rencontre un probleme avec myzor. j'ai lu les messages le concernant et suivi les instructions ( hijakthis et smitfraudfix) mais mon pc est toujours infecté. je vous laisse regarder le rapport hijak et poste au plus vite celui de smit. Je signale egalement que hijak me met 2 messages d'erreur en demarrant le scan et smit semble ne pas pouvoir ouvrir et traiter certains fichier alors que j'ai bien decoché les option de visibilité des dossier cachés); Merci d'avance pour vos conseils avisés.

Logfile of HijackThis v1.99.1
Scan saved at 20:54:42, on 27/11/2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:
C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files (x86)\Logitech\QuickCam\Quickcam.exe
C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files (x86)\Internet Explorer\ieuser.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\conime.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil9f.exe
C:\Users\maquisard\AppData\Local\Temp\Temp2_HiJackThis.zip\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = https://laptopadviser.com/malware-removal/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://laptopadviser.com/malware-removal/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://laptopadviser.com/malware-removal/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://laptopadviser.com/malware-removal/
R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {64466B8E-20A7-4A4A-AFF4-AAD9CA68B52C} - C:\Program Files (x86)\WebMediaViewer\hpmun.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
O3 - Toolbar: Browser Toolbar - {2EEF94DF-75F6-42E9-B7FB-AF5A170A6E2E} - C:\Program Files (x86)\WebMediaViewer\browseul.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files (x86)\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files (x86)\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: (no name) - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.expresstoolie.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IExplorer Security - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.expresstoolie.com/redirect.php (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4D2DEA76-48B7-4B44-872F-8DFE332E63AD}: NameServer = 81.253.149.9 80.10.246.132
O17 - HKLM\System\CCS\Services\Tcpip\..\{D6CF6B85-DDF3-4DE1-A87D-F804EF5BA883}: NameServer = 81.253.149.1 80.10.246.3
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files (x86)\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files (x86)\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSer64.exe
O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files (x86)\ma-config.com\maconfservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
Configuration: Windows Vista
Internet Explorer 7.0

22 réponses

  1. salut

    Lances Malwarebyte's .

    Fais un scan dit "complet" ( sélectionnes bien tous tes disks avant le scan ! ).

    --> Laisses le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
    --> à la fin tu cliques sur "résultat" .
    --> Vérifies que tous les objets infectés soient validés, puis cliques sur " suppression " .

    Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

    Postes le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)
    0
    1. Contributeur sécurité
      bonjour, tu désinstalleras ton hijackthis car il n'est plus d'actualité "périmé" et tu le réinstalles comme expliqué car la il est mal installé , Merci

      télécharge Hijackthis : http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis

      .cliques sur download
      .cliques sur download Hijackthis installer
      .enregistres le sur le bureau
      .Tu fermes tout les programmes ouverts y compris le navigateur. sauf ton anti-virus et pare-feux
      .installes le , il va s'installer par défaut dans C:\Program Files\Trend Micro\HijackThis
      .Cliques sur "Do a system scan and save the logfile"
      .Cela va t'ouvrir un bloc note à la fin du scan.
      .Copie son contenu et poste le dans ton prochain message. sinon le rapport est dans C:\Program Files\Trend Micro\HijackThis\ hijackthis "document texte"

      si besion d'aide pour l'installation : https://www.malekal.com/tutoriel-hijackthis/

      des expliquations en images pour l'utiliser : http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
      0
      1. Voila le rapport du nouveau hijak 'en effet je n'ai plus de message d'erreur :):

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 21:32:29, on 27/11/2008
        Platform: Windows Vista SP1 (WinNT 6.00.1905)
        MSIE: Internet Explorer v7.00 (7.00.6001.18000)
        Boot mode: Normal

        Running processes:
        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
        C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
        C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
        C:\Program Files (x86)\Logitech\QuickCam\Quickcam.exe
        C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe
        C:\Program Files (x86)\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
        C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
        C:\Program Files (x86)\Internet Explorer\ieuser.exe
        C:\Windows\SysWOW64\conime.exe
        C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = https://laptopadviser.com/malware-removal/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://laptopadviser.com/malware-removal/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://laptopadviser.com/malware-removal/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://laptopadviser.com/malware-removal/
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://laptopadviser.com/malware-removal/
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
        F2 - REG:system.ini: UserInit=userinit.exe
        O1 - Hosts: ::1 localhost
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
        O2 - BHO: (no name) - {64466B8E-20A7-4A4A-AFF4-AAD9CA68B52C} - C:\Program Files (x86)\WebMediaViewer\hpmun.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
        O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
        O3 - Toolbar: Browser Toolbar - {2EEF94DF-75F6-42E9-B7FB-AF5A170A6E2E} - C:\Program Files (x86)\WebMediaViewer\browseul.dll
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
        O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files (x86)\Logitech\QuickCam\Quickcam.exe" /hide
        O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe"
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files (x86)\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
        O4 - HKLM\..\Policies\Explorer\Run: [QuickTime Task] C:\Program Files (x86)\WebMediaViewer\qttask.exe
        O4 - HKLM\..\Policies\Explorer\Run: [VMware hptray] C:\Program Files (x86)\WebMediaViewer\hpmon.exe
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
        O9 - Extra button: (no name) - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.expresstoolie.com/redirect.php (file missing)
        O9 - Extra 'Tools' menuitem: IExplorer Security - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.expresstoolie.com/redirect.php (file missing)
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
        O13 - Gopher Prefix:
        O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
        O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{4D2DEA76-48B7-4B44-872F-8DFE332E63AD}: NameServer = 81.253.149.9 80.10.246.132
        O17 - HKLM\System\CCS\Services\Tcpip\..\{D6CF6B85-DDF3-4DE1-A87D-F804EF5BA883}: NameServer = 81.253.149.1 80.10.246.3
        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
        O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files (x86)\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
        O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files (x86)\GIGABYTE\EnergySaver\GSvr.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
        O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSer64.exe
        O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
        O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files (x86)\ma-config.com\maconfservice.exe
        O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
        O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
        O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
        O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
        O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
        O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
        O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
        O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
        O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
        O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
        O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
        O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
        O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
        O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
        O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
        O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
        0
        1. et voici le raaport de smit :

          SmitFraudFix v2.378

          Scan done at 21:19:33,55, 27/11/2008
          Run from C:\Users\maquisard\SmitfraudFix
          OS: Microsoft Windows [version 6.0.6001] - Windows_NT
          The filesystem type is NTFS
          Fix run in safe mode

          »»»»»»»»»»»»»»»»»»»»»»»» Process

          C:\Windows\system32\csrss.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\winlogon.exe
          C:\Windows\system32\services.exe
          C:\Windows\system32\lsass.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files (x86)\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\Explorer.EXE
          C:\Windows\system32\cmd.exe
          C:\Windows\system32\wbem\wmiprvse.exe

          »»»»»»»»»»»»»»»»»»»»»»»» hosts

          »»»»»»»»»»»»»»»»»»»»»»»» C:\

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\maquisard

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\MAQUIS~1\AppData\Local\Temp

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\maquisard\Application Data

          »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\MAQUIS~1\FAVORI~1

          »»»»»»»»»»»»»»»»»»»»»»»» Desktop

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

          »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

          »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

          »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
          !!!Attention, following keys are not inevitably infected!!!

          o4Patch
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
          !!!Attention, following keys are not inevitably infected!!!

          IEDFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» VACFix
          !!!Attention, following keys are not inevitably infected!!!

          VACFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
          !!!Attention, following keys are not inevitably infected!!!

          404Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
          !!!Attention, following keys are not inevitably infected!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
          !!!Attention, following keys are not inevitably infected!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLs"=""
          "LoadAppInit_DLLs"=dword:00000000

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
          !!!Attention, following keys are not inevitably infected!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "Userinit"="userinit.exe"

          »»»»»»»»»»»»»»»»»»»»»»»» RK

          »»»»»»»»»»»»»»»»»»»»»»»» DNS

          HKLM\SYSTEM\CCS\Services\Tcpip\..\{0D76806A-E59E-49CA-A074-AADFFEEEC6AD}: DhcpNameServer=10.0.0.138
          HKLM\SYSTEM\CCS\Services\Tcpip\..\{4D2DEA76-48B7-4B44-872F-8DFE332E63AD}: NameServer=81.253.149.9 80.10.246.132
          HKLM\SYSTEM\CCS\Services\Tcpip\..\{CFAFEFDC-D2A4-452C-B3DB-8C6CFFB7F88C}: DhcpNameServer=81.253.149.9 80.10.246.132 80.10.246.130 81.253.149.10
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{0D76806A-E59E-49CA-A074-AADFFEEEC6AD}: DhcpNameServer=10.0.0.138
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{4D2DEA76-48B7-4B44-872F-8DFE332E63AD}: NameServer=81.253.149.9 80.10.246.132
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{CFAFEFDC-D2A4-452C-B3DB-8C6CFFB7F88C}: DhcpNameServer=81.253.149.9 80.10.246.132 80.10.246.130 81.253.149.10
          HKLM\SYSTEM\CS2\Services\Tcpip\..\{0D76806A-E59E-49CA-A074-AADFFEEEC6AD}: DhcpNameServer=10.0.0.138
          HKLM\SYSTEM\CS2\Services\Tcpip\..\{4D2DEA76-48B7-4B44-872F-8DFE332E63AD}: NameServer=81.253.149.9 80.10.246.132
          HKLM\SYSTEM\CS2\Services\Tcpip\..\{CFAFEFDC-D2A4-452C-B3DB-8C6CFFB7F88C}: DhcpNameServer=81.253.149.9 80.10.246.132 80.10.246.130 81.253.149.10
          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.138
          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.138
          HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.138

          »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

          »»»»»»»»»»»»»»»»»»»»»»»» End
          0
          1. Contributeur sécurité
            qu'as tu fait avec smitfraudfix car tu l'a fais en mode sans echec et quel option as tu choisi 1 ou 2 ???? car je ne vois pas les infection dessus alors quel sont bien sur hijackthis que tu as fais après le scan de smitfraudfix , donc perso je te demanderais de virer ton rapport smitfraudfix et d'en refaire un nouveau mais en mode normal et option 1 comme expliqué dans la procédure http://siri.urz.free.fr/Fix/SmitfraudFix.php

            le mieux serait que tu désaxctives tes protections résidente "anti-virus et anti-spyware" le temps de faire l'analyse.

            et télécharge SmitfraudFix.exe.

            Regarde le tuto: http://siri.urz.free.fr/Fix/SmitfraudFix.php

            Exécute le en choisissant l’option 1
            il va générer un rapport

            Copie/colle le sur le poste stp.

            Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus, ect...) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
            0
            1. J'ai un problème avec smit le logiciel se lance mais en cours de scan, la fenêtre disparait définitevement.J'ai uniquement réussi à lancer une option 1 en safe mode don voici le rapport :

              SmitFraudFix v2.378

              Scan done at 22:01:47,41, 27/11/2008
              Run from C:\Users\maquisard\SmitfraudFix
              OS: Microsoft Windows [version 6.0.6001] - Windows_NT
              The filesystem type is NTFS
              Fix run in safe mode

              »»»»»»»»»»»»»»»»»»»»»»»» Process

              C:\Windows\system32\csrss.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files (x86)\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\Explorer.EXE
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Windows\system32\cmd.exe

              »»»»»»»»»»»»»»»»»»»»»»»» hosts

              »»»»»»»»»»»»»»»»»»»»»»»» C:\

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\maquisard

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\MAQUIS~1\AppData\Local\Temp

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\maquisard\Application Data

              »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\MAQUIS~1\FAVORI~1

              »»»»»»»»»»»»»»»»»»»»»»»» Desktop

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

              »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

              »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

              »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
              !!!Attention, following keys are not inevitably infected!!!

              o4Patch
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
              !!!Attention, following keys are not inevitably infected!!!

              IEDFix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» VACFix
              !!!Attention, following keys are not inevitably infected!!!

              VACFix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
              !!!Attention, following keys are not inevitably infected!!!

              404Fix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
              !!!Attention, following keys are not inevitably infected!!!

              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll

              »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
              !!!Attention, following keys are not inevitably infected!!!

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
              "AppInit_DLLs"=""
              "LoadAppInit_DLLs"=dword:00000000

              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
              !!!Attention, following keys are not inevitably infected!!!

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
              "Userinit"="userinit.exe"

              »»»»»»»»»»»»»»»»»»»»»»»» RK

              »»»»»»»»»»»»»»»»»»»»»»»» DNS

              HKLM\SYSTEM\CCS\Services\Tcpip\..\{0D76806A-E59E-49CA-A074-AADFFEEEC6AD}: DhcpNameServer=10.0.0.138
              HKLM\SYSTEM\CCS\Services\Tcpip\..\{4D2DEA76-48B7-4B44-872F-8DFE332E63AD}: NameServer=81.253.149.9 80.10.246.132
              HKLM\SYSTEM\CCS\Services\Tcpip\..\{CFAFEFDC-D2A4-452C-B3DB-8C6CFFB7F88C}: DhcpNameServer=81.253.149.9 80.10.246.132 80.10.246.130 81.253.149.10
              HKLM\SYSTEM\CCS\Services\Tcpip\..\{D6CF6B85-DDF3-4DE1-A87D-F804EF5BA883}: NameServer=81.253.149.1 80.10.246.3
              HKLM\SYSTEM\CS1\Services\Tcpip\..\{0D76806A-E59E-49CA-A074-AADFFEEEC6AD}: DhcpNameServer=10.0.0.138
              HKLM\SYSTEM\CS1\Services\Tcpip\..\{4D2DEA76-48B7-4B44-872F-8DFE332E63AD}: NameServer=81.253.149.9 80.10.246.132
              HKLM\SYSTEM\CS1\Services\Tcpip\..\{CFAFEFDC-D2A4-452C-B3DB-8C6CFFB7F88C}: DhcpNameServer=81.253.149.9 80.10.246.132 80.10.246.130 81.253.149.10
              HKLM\SYSTEM\CS1\Services\Tcpip\..\{D6CF6B85-DDF3-4DE1-A87D-F804EF5BA883}: NameServer=81.253.149.1 80.10.246.3
              HKLM\SYSTEM\CS2\Services\Tcpip\..\{0D76806A-E59E-49CA-A074-AADFFEEEC6AD}: DhcpNameServer=10.0.0.138
              HKLM\SYSTEM\CS2\Services\Tcpip\..\{4D2DEA76-48B7-4B44-872F-8DFE332E63AD}: NameServer=81.253.149.9 80.10.246.132
              HKLM\SYSTEM\CS2\Services\Tcpip\..\{CFAFEFDC-D2A4-452C-B3DB-8C6CFFB7F88C}: DhcpNameServer=81.253.149.9 80.10.246.132 80.10.246.130 81.253.149.10
              HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.138

              »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

              »»»»»»»»»»»»»»»»»»»»»»»» End
              0
              1. Contributeur sécurité
                faire la recherche en mode sans echec ne me permet pas de voire les processus infectieux car en modes sans echec seul ceux nécessaire au fontionnement de windows sont actif donc aucun malware visible sur hijackthis ils sont ici

                O2 - BHO: (no name) - {64466B8E-20A7-4A4A-AFF4-AAD9CA68B52C} - C:\Program Files (x86)\WebMediaViewer\hpmun.dll

                O3 - Toolbar: Browser Toolbar - {2EEF94DF-75F6-42E9-B7FB-AF5A170A6E2E} - C:\Program Files (x86)\WebMediaViewer\browseul.dll

                O4 - HKLM\..\Policies\Explorer\Run: [QuickTime Task] C:\Program Files (x86)\WebMediaViewer\qttask.exe

                O4 - HKLM\..\Policies\Explorer\Run: [VMware hptray] C:\Program Files (x86)\WebMediaViewer\hpmon.exe

                si tu n'arrives pas à passer smitfraudfix en mode normal même avec ton anti-virus arrêté tu vas passer malwarebytes en mode sans echec tu suis bien les expliquation colles les dans le bloc note cela te permetteras de les consulter en mode sans echec car tu n'aura plus internet pendant l'analyse

                Télécharge Malwarebytes' Anti-Malware: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

                . sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
                . enregistres le sur le bureau
                . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
                . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
                . si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
                . Une fois la mise à jour terminée,fermes Malwarebytes
                . redemarres en mode sans échec pour savoir comment au cas ou tu ne saurrais pas regarde plus bas
                . une fois en mode sans echec tu double-cliques sur l'icône de malwarebytes
                . une fois ouvert rend-toi dans l'onglet, Recherche
                . Sélectionnes Exécuter un examen complet
                . Cliques sur Rechercher
                . Le scan démarre.
                . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
                . Cliques sur Ok pour poursuivre.
                . Si des malwares ont été détectés, cliques sur Afficher les résultats
                . Sélectionnes tout (ou laisses cochés)

                . cliques sur Supprimer la sélection

                . Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                . redemarre le pc
                . une fois redémarré en mode normal double-cliques sur malwarebytes
                . rends toi dans l'onglet rapport/log
                . tu cliques dessus pour l'afficher une fois affiché
                . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
                . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
                . tu cliques droit dans le cadre de la reponse et coller

                Si tu as besoin d'aide regarde ces tutoriels :
                https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
                https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

                (attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...)

                pour redémarrer en mode sans échec : /!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

                . Cliques sur Démarrer
                . Cliques sur Arrêter
                . Sélectionnes Redémarrer et au redémarrage
                . Appuis sur la touche F8 sans discontinuer "1 appuis seconde" dès qu'un écran de texte apparaît puis disparaît
                . Utilises les touches de direction pour sélectionner mode sans échec
                . puis appuis sur ENTRÉE des fois cela peut prendre plusieurs minute entre la validation et l'affichage
                . Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre
                une fois démarré ne t'inquiette pas si les couleurs et les icônes ne sont pas comme d'abitude

                tuto:http://www.vista-xp.fr/forum/topic93.html
                0
                1. J'étais justement en plein scan malwarebyte's quand tu as posté vu que neor me l'avait également conseillé et la je croi squ'on tient quelque chose. La page généré automatiquement dans le navigateur a disapru du coup je pense que l'opération a réussi ( merci beaucoup à vous ! ), enfin j'éspère voici le rapport malwarebytes :

                  Malwarebytes' Anti-Malware 1.30
                  Version de la base de données: 1430
                  Windows 6.0.6001 Service Pack 1

                  27/11/2008 22:39:24
                  mbam-log-2008-11-27 (22-39-24).txt

                  Type de recherche: Examen complet (C:\|D:\|F:\|)
                  Eléments examinés: 145849
                  Temps écoulé: 22 minute(s), 28 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 13
                  Valeur(s) du Registre infectée(s): 4
                  Elément(s) de données du Registre infecté(s): 7
                  Dossier(s) infecté(s): 2
                  Fichier(s) infecté(s): 16

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  HKEY_CLASSES_ROOT\z444.z444mgr (Trojan.BHO) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\z444.z444mgr.1 (Trojan.BHO) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{2eef94df-75f6-42e9-b7fb-af5a170a6e2e} (Trojan.Zlob) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2eef94df-75f6-42e9-b7fb-af5a170a6e2e} (Trojan.Zlob) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{64466b8e-20a7-4a4a-aff4-aad9ca68b52c} (Trojan.Zlob) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64466b8e-20a7-4a4a-aff4-aad9ca68b52c} (Trojan.Zlob) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64466b8e-20a7-4a4a-aff4-aad9ca68b52c} (Trojan.Zlob) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{51b15f5a-e98b-4658-b9cb-9307b74773a7} (Trojan.BHO) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3b8fb116-d358-48a3-a5c7-db84f15cbb04} (Trojan.Zlob) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{3b8fb116-d358-48a3-a5c7-db84f15cbb04} (Trojan.Zlob) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Online Alert Manager (Trojan.Zlob) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IExplorer add-on (Trojan.Zlob) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Browser Toolbar (Trojan.Zlob) -> Quarantined and deleted successfully.

                  Valeur(s) du Registre infectée(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{2eef94df-75f6-42e9-b7fb-af5a170a6e2e} (Trojan.Zlob) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2eef94df-75f6-42e9-b7fb-af5a170a6e2e} (Trojan.Zlob) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\vmware hptray (Trojan.Zlob) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\quicktime task (Trojan.Zlob) -> Quarantined and deleted successfully.

                  Elément(s) de données du Registre infecté(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (https://www.google.com/?gws_rd=ssl -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (https://www.google.com/?gws_rd=ssl -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (https://www.google.com/?gws_rd=ssl -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.Search) -> Bad: (https://laptopadviser.com/malware-removal/ Good: (https://www.google.com/?gws_rd=ssl -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (https://laptopadviser.com/malware-removal/{searchTerms}) Good: (https://www.google.com/?gws_rd=ssl -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (https://www.google.com/?gws_rd=ssl -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) -> Bad: (http://windiwsfsearch.com/search?q=%s) Good: (https://www.google.com/?gws_rd=ssl -> Quarantined and deleted successfully.

                  Dossier(s) infecté(s):
                  C:\Program Files (x86)\WebMediaViewer (Trojan.Zlob) -> Quarantined and deleted successfully.
                  C:\Windows\System32\512686 (Trojan.BHO) -> Quarantined and deleted successfully.

                  Fichier(s) infecté(s):
                  C:\Program Files (x86)\WebMediaViewer\browseul.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
                  C:\Program Files (x86)\WebMediaViewer\hpmun.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
                  C:\Program Files (x86)\WebMediaViewer\browseu.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
                  C:\Program Files (x86)\WebMediaViewer\hpmon.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
                  C:\Program Files (x86)\WebMediaViewer\hpmun.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
                  C:\Program Files (x86)\WebMediaViewer\myd.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
                  C:\Program Files (x86)\WebMediaViewer\mym.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
                  C:\Program Files (x86)\WebMediaViewer\myp.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
                  C:\Program Files (x86)\WebMediaViewer\myv.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
                  C:\Program Files (x86)\WebMediaViewer\ot.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
                  C:\Program Files (x86)\WebMediaViewer\qttask.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
                  C:\Program Files (x86)\WebMediaViewer\qttaskm.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
                  C:\Program Files (x86)\WebMediaViewer\qttasku.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
                  C:\Program Files (x86)\WebMediaViewer\ts.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
                  C:\ProgramData\Microsoft\Windows\Start Menu\Antivirus Scan.url (Trojan.Zlob) -> Quarantined and deleted successfully.
                  C:\ProgramData\Microsoft\Windows\Start Menu\Online Antispyware Test.url (Trojan.Zlob) -> Quarantined and deleted successfully.

                  J'éspère en avoir fini et je ne sais comment vous remercier pour votre aide; vous êtes rapides efficaces et patients avec les gros noobars comme moi alors merci à vous et vive les forums de comment ça marche !

                  PS : en esperant que le probleme soit bel et bien définitevement résolu mais je vais le noter comme tel dans le titre
                  0
                  1. repost un hijackthis STP
                    0
                2. voila :

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 21:32:29, on 27/11/2008
                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                  MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                  Boot mode: Normal

                  Running processes:
                  C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                  C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                  C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
                  C:\Program Files (x86)\Logitech\QuickCam\Quickcam.exe
                  C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe
                  C:\Program Files (x86)\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                  C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
                  C:\Program Files (x86)\Internet Explorer\ieuser.exe
                  C:\Windows\SysWOW64\conime.exe
                  C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

                  R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://windiwsfsearch.com
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://windiwsfsearch.com
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://laptopadviser.com/malware-removal/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://laptopadviser.com/malware-removal/
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://laptopadviser.com/malware-removal/
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
                  F2 - REG:system.ini: UserInit=userinit.exe
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
                  O2 - BHO: (no name) - {64466B8E-20A7-4A4A-AFF4-AAD9CA68B52C} - C:\Program Files (x86)\WebMediaViewer\hpmun.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
                  O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
                  O3 - Toolbar: Browser Toolbar - {2EEF94DF-75F6-42E9-B7FB-AF5A170A6E2E} - C:\Program Files (x86)\WebMediaViewer\browseul.dll
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
                  O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files (x86)\Logitech\QuickCam\Quickcam.exe" /hide
                  O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe"
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files (x86)\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                  O4 - HKLM\..\Policies\Explorer\Run: [QuickTime Task] C:\Program Files (x86)\WebMediaViewer\qttask.exe
                  O4 - HKLM\..\Policies\Explorer\Run: [VMware hptray] C:\Program Files (x86)\WebMediaViewer\hpmon.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
                  O9 - Extra button: (no name) - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.expresstoolie.com/redirect.php (file missing)
                  O9 - Extra 'Tools' menuitem: IExplorer Security - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.expresstoolie.com/redirect.php (file missing)
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
                  O13 - Gopher Prefix:
                  O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                  O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{4D2DEA76-48B7-4B44-872F-8DFE332E63AD}: NameServer = 81.253.149.9 80.10.246.132
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{D6CF6B85-DDF3-4DE1-A87D-F804EF5BA883}: NameServer = 81.253.149.1 80.10.246.3
                  O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                  O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files (x86)\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
                  O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files (x86)\GIGABYTE\EnergySaver\GSvr.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                  O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSer64.exe
                  O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                  O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files (x86)\ma-config.com\maconfservice.exe
                  O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
                  O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                  O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                  O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                  O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
                  O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                  O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
                  O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
                  O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
                  O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
                  O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
                  O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
                  O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
                  O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
                  O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
                  O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
                  0
                  1. Contributeur sécurité
                    si tu le permets je te dis NON c'est pas fini tu met un nouveau hijackthis il y aura surement des lignes à fixer et deux outrois autre manippes mais si tu dis que pour toi c'est bon OK c'est ton pc dans ce cas @+
                    0
                    1. Contributeur sécurité
                      on va veriffier avec otmoveit
                      0
                      1. Contributeur sécurité
                        Télécharge OTMoveIt3 de OldTimer sur ton Bureau en cliquant sur ce lien :

                        http://oldtimer.geekstogo.com/OTMoveIt3.exe

                        Double-clique sur OTMoveIt3.exe pour le lancer.

                        Vérifie que la case devant "Unregister Dll's and Ocx's est bien cochée.

                        Copie la liste qui se trouve en gras ci-dessous,

                        et colle-la dans le cadre de gauche de OTMoveIt : "Paste instructions for item to be moved".

                        :files
                        c:\program files\webmediaviewer\hpmun.dll
                        c:\program files\webmediaviewer\browseul.dll
                        c:\program files\webmediaviewer\qttask.exe
                        c:\program files\webmediaviewer\hpmon.exe

                        :Commands
                        [emptytemp]
                        [reboot]


                        Clique sur "MoveIt!" pour lancer la suppression.

                        Le résultat apparaitra dans le cadre "Results".

                        Clique sur "Exit" pour fermer.

                        Poste le rapport situé dans C:\_OTMoveIt\MovedFiles sous le nom xxxxxx_xxxxxxxxxx.log .

                        Il te sera peut-être demander de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.
                        0
                        1. Arf OK j'avais quelques doutes aussi...
                          C'est quoi Otmoveit ? j'ai regardé avec google mais pas très bien compris
                          Et pour WebMediaViewer ?
                          0
                          1. navnavilog1 supprime webmediaplayer normalement?
                            0
                            1. Contributeur sécurité
                              si c'est fichiers son sur le pc otmoveit les supprimeras
                              0
                              1. Voila le rapport :

                                ========== FILES ==========
                                File/Folder c:\program files\webmediaviewer\hpmun.dll not found.
                                File/Folder c:\program files\webmediaviewer\browseul.dll not found.
                                File/Folder c:\program files\webmediaviewer\qttask.exe not found.
                                File/Folder c:\program files\webmediaviewer\hpmon.exe not found.
                                ========== COMMANDS ==========
                                File delete failed. C:\Users\MAQUIS~1\AppData\Local\Temp\Low\~DF1E43.tmp scheduled to be deleted on reboot.
                                File delete failed. C:\Users\MAQUIS~1\AppData\Local\Temp\Low\~DF1E4E.tmp scheduled to be deleted on reboot.
                                File delete failed. C:\Users\MAQUIS~1\AppData\Local\Temp\Low\~DF4C.tmp scheduled to be deleted on reboot.
                                File delete failed. C:\Users\MAQUIS~1\AppData\Local\Temp\Low\~DF57.tmp scheduled to be deleted on reboot.
                                User's Temp folder emptied.
                                User's Temporary Internet Files folder emptied.
                                User's Internet Explorer cache folder emptied.
                                Local Service Temp folder emptied.
                                Local Service Temporary Internet Files folder emptied.
                                Windows Temp folder emptied.
                                Temp folders emptied.

                                OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11272008_232354
                                0
                                1. Contributeur sécurité
                                  not found: donc plus sur le pc seul reste les lignes à fixer dans hijackthis je t'ai préparrer pendant le scan otmoveit la suite pour finir mais avant peux tu me dire ce que tu utilises comme anti-virus car la tu as avast et avg si tu n'utilise plus avast désinstalles le convenablement d'abord dans ajout suppression des programmes si pas déjà fait, et puis utilises l'utilitaire de désinstallation tu fais ça et puis tu pourras faire la suite 1et 2et 3

                                  1)

                                  Tu relances hijackthis comme expliqué pour Fixer les lignes

                                  .Tu fermes tout les programmes ouverts y compris le navigateur. sauf ton anti-virus et pare-feux
                                  .Lances HijackThis
                                  .Cliques sur "Do a system scan only"
                                  .Tu coches les lignes suivantes :
                                  R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = https://laptopadviser.com/malware-removal/
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://laptopadviser.com/malware-removal/
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://laptopadviser.com/malware-removal/
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://laptopadviser.com/malware-removal/
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://laptopadviser.com/malware-removal/
                                  O2 - BHO: (no name) - {64466B8E-20A7-4A4A-AFF4-AAD9CA68B52C} - C:\Program Files (x86)\WebMediaViewer\hpmun.dll
                                  O3 - Toolbar: Browser Toolbar - {2EEF94DF-75F6-42E9-B7FB-AF5A170A6E2E} - C:\Program Files (x86)\WebMediaViewer\browseul.dll
                                  O4 - HKLM\..\Policies\Explorer\Run: [VMware hptray] C:\Program Files (x86)\WebMediaViewer\hpmon.exe
                                  O9 - Extra button: (no name) - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.expresstoolie.com/redirect.php (file missing)
                                  O9 - Extra 'Tools' menuitem: IExplorer Security - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.expresstoolie.com/redirect.php (file missing)


                                  .Tu cliques sur "Fix Checked"
                                  .Tu fermes HijackThis

                                  des expliquations en images : http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm

                                  2)

                                  Tu désinstalles les outils utilisés avec Toolscleaner2 lui tu le supprimeras de sur le bureau manuellement ainsi que le rapport généré qui est dans ton disque dur système sous le nom de " TCleaner "

                                  Télécharge toolscleaner sur ton Bureau : http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner

                                  . Double-cliques sur ToolsCleaner2 "l'as de carreau" et laisse le travailler
                                  . Cliques sur Recherche et laisse le scan se terminer. attention ça peut parraitre long
                                  . Cliques sur Suppression pour finaliser.
                                  . Tu peux, si tu le souhaites, te servir des Options facultatives.
                                  . Clique sur Quitter, pour que le rapport puisse se créer.
                                  . Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse

                                  3)

                                  Redémarres le PC et passes Ccleaner avec ces réglages LA

                                  télécharge Ccleaner à partir de cette adresses

                                  .enregistres le sur le bureau
                                  .double-cliques sur le fichier pour lancer l'installation
                                  .sur la fenêtre de l'installation langage bien choisir français et OK
                                  .cliques sur suivant
                                  .lis la licence et j'accepte
                                  .cliques sur suivant
                                  .la tu ne gardes de coché que mettre un raccourci sur le bureau et puis contrôler automatiquement les mises à jour de Ccleaner
                                  .cliques sur intaller
                                  .cliques sur fermer
                                  .double-cliques sur l'icône de Ccleaner pour l'ouvrir
                                  .une fois ouvert tu cliques sur option et puis avancé
                                  .tu décoches effacer uniquement les fichiers, du dossier temp de windows plus vieux que 48 heures
                                  .cliques sur nettoyeur
                                  .cliques sur windows et dans la colonne avancé
                                  .cochesla première case vieilles données du perfetch que celle-la ce qui te donnes la case vielles données du perfetch et la case avancé qui c'est coché automatiquement mais que celle-la
                                  .cliques sur analyse une fois l'analyse terminé
                                  .cliques sur lancer le nettoyage et sur la demande de confirmation OK il vas falloir que tu le refasses une autre fois une fois fini vériffis en appuiant de nouveau sur analyse pour être sur qu'il n'y est plus rien
                                  .cliques maintenant sur registre et puis sur rechercher les erreurs
                                  .laisses tout cochées et cliques sur réparrer les erreurs sélectionnées
                                  .il te demande de sauvegarder OUI
                                  .tu lui donnes un nom pour pouvoir la retrouver et enregistre
                                  .cliques sur corriger toutes les erreurs sélectionnées et sur la demande de confirmation OK
                                  .il supprime et fermer tu vériffis en relancant rechercher les erreurs
                                  .tu retournes dans option et tu recoches la case effacer uniquement les fichiers, du dossier temp de windows plus vieux que 48 heures et sur nettoyeur, windows sous avancé tu décoches la première case vieilles données du perfetch
                                  .tu peux fermer Ccleaner

                                  pour aider si besion tutoriel: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

                                  0
                                  • 1
                                  • 2