Virus ou autre sur mon pc

Résolu
Bonjour,j'ai un pc voila 1 mois et je crois avoir un virus ou autre
je galere a le(s) trouver et le(s) virer
si quelqu'un peu me venir en aide s
ça me rend fou
voila mon rapport hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:55:15, on 10/02/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\1202289613=0\strpmon.exe
C:\Program Files\Common Files\Nettordinateur\stm.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\explorer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - C:\PROGRA~1\ORANGE~1\TOOLBA~2.DLL
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange Toolbar FR\ToolbarContainer234.dll
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\1202289613=0\strpmon.exe" dm=http://www.xxxcounter.de ad=http://www.xxxcounter.de sd=http://repay.www.xxxcounter.de
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Salestart(1)] "C:\Program Files\Common Files\Nettordinateur\stm.exe" dm=http://nettordinateur.com ad=http://nettordinateur.com sd=http://paylogs.nettordinateur.com
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\LAGRIV~1\AppData\Local\Temp\opnom.dll,#1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\LAGRIV~1\AppData\Local\Temp\awtuu.dll,c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: traduire la page - C:\Users\LAGRIV~1\AppData\Local\Temp\cce24D6.html
O8 - Extra context menu item: traduire le texte sélectionné - C:\Users\LAGRIV~1\AppData\Local\Temp\cce24F6.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - https://www.f-secure.com/en/home/support
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B137F01C-BE9C-4C2D-BC8E-8E7AF30E086E}: NameServer = 192.168.1.1
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

--
End of file - 9462 bytes

J'ai fais assi un scan avec avg anti spyware
la voici

+ Créé à: 14:14:09 08/02/2008

+ Résultat de l'analyse:

:mozilla.376:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.313:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.434:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.61:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.62:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.63:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.64:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.65:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.66:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.67:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.68:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.69:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.70:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.914:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.97:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
C:\Users\LA GRIVE\AppData\Roaming\Microsoft\Windows\Cookies\la_grive@2o7[2].txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.215:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.216:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.217:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.219:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.220:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.221:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.388:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.389:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.390:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.391:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.392:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.393:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.354:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.15:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.16:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.17:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.18:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.19:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.521:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.277:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Users\LA GRIVE\AppData\Roaming\Microsoft\Windows\Cookies\la_grive@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.33:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.225:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.226:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.227:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.228:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.229:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.230:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.231:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.394:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.395:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.396:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.721:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Commission-junction : Nettoyé.
:mozilla.722:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Commission-junction : Nettoyé.
:mozilla.377:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Dealtime : Nettoyé.
:mozilla.378:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Dealtime : Nettoyé.
:mozilla.41:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
C:\Users\LA GRIVE\AppData\Roaming\Microsoft\Windows\Cookies\Low\la_grive@doubleclick[1].txt -> TrackingCookie.Doubleclick : Nettoyé.
C:\Users\LA GRIVE\AppData\Roaming\Microsoft\Windows\Cookies\la_grive@doubleclick[2].txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.296:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.449:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.450:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.451:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.452:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.606:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.607:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.350:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.369:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.372:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.384:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.387:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.50:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.60:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.632:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.72:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.758:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.81:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.847:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.86:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.93:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.954:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.968:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.983:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.443:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.444:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.445:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.788:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.822:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.476:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.477:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.232:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Information : Nettoyé.
:mozilla.233:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Information : Nettoyé.
:mozilla.234:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Information : Nettoyé.
:mozilla.682:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Komtrack : Nettoyé.
:mozilla.684:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Komtrack : Nettoyé.
:mozilla.792:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Liveperson : Nettoyé.
:mozilla.42:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.43:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
C:\Users\LA GRIVE\AppData\Roaming\Microsoft\Windows\Cookies\Low\la_grive@mediaplex[1].txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.323:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.324:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
C:\Users\LA GRIVE\AppData\Roaming\Microsoft\Windows\Cookies\la_grive@perf.overture[1].txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.958:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Realmedia : Nettoyé.
:mozilla.959:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Realmedia : Nettoyé.
:mozilla.223:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Revenue : Nettoyé.
:mozilla.315:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.316:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.317:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.318:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.319:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.320:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.321:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
C:\Users\LA GRIVE\AppData\Roaming\Microsoft\Windows\Cookies\la_grive@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Nettoyé.
C:\Users\LA GRIVE\AppData\Roaming\Microsoft\Windows\Cookies\la_grive@serving-sys[1].txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.622:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Skype : Nettoyé.
:mozilla.966:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Skype : Nettoyé.
:mozilla.967:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Skype : Nettoyé.
:mozilla.106:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.107:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.108:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.109:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
C:\Users\LA GRIVE\AppData\Roaming\Microsoft\Windows\Cookies\Low\la_grive@smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.964:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.132:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.133:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.134:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.135:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.136:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.222:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Tribalfusion : Nettoyé.
:mozilla.111:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.112:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.113:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.146:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Webtrends : Nettoyé.
:mozilla.410:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Xhit : Nettoyé.
:mozilla.608:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.609:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.610:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.611:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
C:\Users\LA GRIVE\AppData\Roaming\Microsoft\Windows\Cookies\Low\la_grive@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.598:C:\Users\LA GRIVE\AppData\Roaming\Mozilla\Firefox\Profiles\knhc5i9x.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.

Fin du rapport
et un autre un peu plus tard

+ Créé à: 12:55:19 10/02/2008

+ Résultat de l'analyse:

C:\Users\LA GRIVE\AppData\Roaming\Microsoft\Windows\Cookies\Low\la_grive@advertising[2].txt -> TrackingCookie.Advertising : Aucune action entreprise.
C:\Users\LA GRIVE\AppData\Roaming\Microsoft\Windows\Cookies\Low\la_grive@mediaplex[1].txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
C:\Users\LA GRIVE\AppData\Roaming\Microsoft\Windows\Cookies\Low\la_grive@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : Aucune action entreprise.

Fin du rapport

J'ai essayerun scan en ligne impossible j'ai tout essayer

Il y a un message qui me dis de temps en temps buffer overrun detected
voilou merci de votre aide par avances
Configuration: windos vista
Internet Explorer

59 réponses

Résumé de la discussion

Le problème central est une suspicion d’infection sur Windows Vista, appuyée par un log HijackThis révélant des entrées au démarrage et des composants malveillants comme des barres d’outils et BHO. Des éléments de réponse incluent l’analyse et le nettoyage via AVG et des outils anti-malware, puis l’exécution de ComboFix qui a supprimé des fichiers indésirables et signalé des sites infectés. Le rapport ComboFix mentionne la création d’un point de restauration et la suppression de fichiers indésirables, avec des indices sur des emplacements douteux comme qmgr.dat et des entrées BITS. En cas de besoin, une restauration système et une vérification des modules d’intégration Google Desktop et des services non identifiés devraient être envisagées pour prévenir de nouvelles réinfections.

Bobot (l’IA à votre service)
  1. slt je n'est jamais utiliser hijackthis mais ce antitrojan https://www.cnetfrance.fr/telecharger/trojan-remover-11008989s.htm et tu le met à jour puis redemarre ton pc. Et met moi au courant ok
    0
    1. Contributeur sécurité
      je n'est jamais utiliser hijackthis Hijackthis est un scanner ..... pas un nettoyeur

      dans ce cas précis, on a une infection Smitfraud.....
      0
  2. Contributeur sécurité
    Salut !

    Déjà deux antivirus = CONFLIT !

    en plus ce sont des Passoires.... on verra a la fin !
    pour l'instant,

    Sous Vista !
    Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

    regarde ce tuto http://www.libellules.ch/adc.php

    Télécharge SmitfraudFix
    Utilitaire de S!Ri: Moe et balltrap34

    Installe le à la racine de C : tuto d'utilisation
    Double clique sur l'exe pour le décompresser et lancer le fix.
    Utilisation option 1 Recherche :
    Double clique sur smitfraudfix.cmd
    Sélectionne 1 pour créer un rapport des fichiers responsables de l'infection.

    Ne fais rien d'autre sans notre avis

    Copie/colle le sur ta prochaine réponse sur ce post stp.

    Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

    to be continued.......
    0
    1. non comment trojanver s'intalle or hijackthis est un desinfecteur y'aura pas de conflit telecharge le logi il est très puissant
      0
      1. slt

        thijackthis est un desinfecteur

        MOUAaaaaaaaaaaaaaarrfffffffffffffffffffff !!!!!!!!!!!

        0
    2. voila le raport
      merci pour l'aide
      SmitFraudFix v2.286

      Scan done at 15:55:07,15, 10/02/2008
      Run from C:\Users\LA GRIVE\Desktop\SmitfraudFix
      OS: Microsoft Windows [version 6.0.6000] - Windows_NT
      The filesystem type is NTFS
      Fix run in normal mode

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\Windows\system32\csrss.exe
      C:\Windows\system32\wininit.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\services.exe
      C:\Windows\system32\lsass.exe
      C:\Windows\system32\lsm.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\winlogon.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\SLsvc.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\Windows\System32\spoolsv.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Common Files\1202289613=0\strpmon.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\Program Files\Common Files\Nettordinateur\stm.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Windows\system32\PnkBstrA.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\SearchIndexer.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Windows Media Player\wmpnetwk.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\WUDFHost.exe
      C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Windows\system32\cmd.exe
      C:\Windows\system32\conime.exe
      C:\Windows\system32\wbem\wmiprvse.exe
      C:\Windows\system32\wbem\wmiprvse.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\LA GRIVE

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\LA GRIVE\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\LAGRIV~1\FAVORI~1

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, following keys are not inevitably infected!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, following keys are not inevitably infected!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, following keys are not inevitably infected!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, following keys are not inevitably infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~3\\GOEC62~1.DLL"
      "LoadAppInit_DLLs"=dword:00000001

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, following keys are not inevitably infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

      »»»»»»»»»»»»»»»»»»»»»»»» Rustock

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: Carte réseau Fast Ethernet Realtek RTL8139/810x Family
      DNS Server Search Order: 192.168.1.1

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{B137F01C-BE9C-4C2D-BC8E-8E7AF30E086E}: NameServer=192.168.1.1
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{B137F01C-BE9C-4C2D-BC8E-8E7AF30E086E}: NameServer=192.168.1.1
      HKLM\SYSTEM\CS2\Services\Tcpip\..\{B137F01C-BE9C-4C2D-BC8E-8E7AF30E086E}: NameServer=192.168.1.1

      »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection
      0
      1. Contributeur sécurité
        Nettoyage:

        # Redémarre l'ordinateur en mode sans échec (au démarrage de l'ordinateur, tapoter F8 )
        # Double clique sur SmitfraudFix.exe
        # Sélectionner 2 et pressez Entrée dans le menu pour supprimer les fichiers responsables de l'infection.
        # A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et pressez Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection.
        Le fix déterminera si le fichier wininet.dll est infecté. A la question: Corriger le fichier infecté ? répondre O (oui) et pressez Entrée pour remplacer le fichier corrompu.
        # Un redémarrage sera peut être nécessaire pour terminer la procedure de nettoyage. Le rapport se trouve à la racine du disque système C:\rapport.txt /list
        Poste le rapport dans ton prochain message et un nouveau Hijackthis scan log file stp !
        0
        1. et voila

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 16:33:28, on 10/02/2008
          Platform: Windows Vista (WinNT 6.00.1904)
          MSIE: Internet Explorer v7.00 (7.00.6000.16575)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Common Files\1202289613=0\strpmon.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
          C:\Program Files\Common Files\Nettordinateur\stm.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Windows\System32\mobsync.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - C:\PROGRA~1\ORANGE~1\TOOLBA~2.DLL
          O1 - Hosts: ::1 localhost
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
          O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange Toolbar FR\ToolbarContainer234.dll
          O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\1202289613=0\strpmon.exe" dm=http://www.xxxcounter.de ad=http://www.xxxcounter.de sd=http://repay.www.xxxcounter.de
          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
          O4 - HKLM\..\Run: [Salestart(1)] "C:\Program Files\Common Files\Nettordinateur\stm.exe" dm=http://nettordinateur.com ad=http://nettordinateur.com sd=http://paylogs.nettordinateur.com
          O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
          O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
          O8 - Extra context menu item: traduire la page - C:\Users\LAGRIV~1\AppData\Local\Temp\cce24D6.html
          O8 - Extra context menu item: traduire le texte sélectionné - C:\Users\LAGRIV~1\AppData\Local\Temp\cce24F6.html
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
          O13 - Gopher Prefix:
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O17 - HKLM\System\CCS\Services\Tcpip\..\{B137F01C-BE9C-4C2D-BC8E-8E7AF30E086E}: NameServer = 192.168.1.1
          O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
          O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
          O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
          O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
          O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
          0
          1. Contributeur sécurité
            ou est le rapport Smitfraud ?
            Le rapport se trouve à la racine du disque système C:\rapport.txt
            J'en ai besoin !
            0
            1. Je l'avais mais je le trouve plus dans C:
              doi je refaire
              # Redémarre l'ordinateur en mode sans échec (au démarrage de l'ordinateur, tapoter F8 )
              # Double clique sur SmitfraudFix.exe
              # Sélectionner 2 et pressez Entrée dans le menu pour supprimer les fichiers responsables de l'infection.
              # A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et pressez Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection.
              Le fix déterminera si le fichier wininet.dll est infecté. A la question: Corriger le fichier infecté ? répondre O (oui) et pressez Entrée pour remplacer le fichier corrompu.
              # Un redémarrage sera peut être nécessaire pour terminer la procedure de nettoyage. Le rapport se trouve à la racine du disque système C:\rapport.txt /list
              Poste le rapport dans ton prochain message et un nouveau Hijackthis scan log file stp !
              0
              1. Contributeur sécurité
                refais moi un logfile HJT's on verra ensuite ....
                0
                1. Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 17:59:49, on 10/02/2008
                  Platform: Windows Vista (WinNT 6.00.1904)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16575)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Common Files\1202289613=0\strpmon.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                  C:\Program Files\Common Files\Nettordinateur\stm.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Windows\System32\mobsync.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - C:\PROGRA~1\ORANGE~1\TOOLBA~2.DLL
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                  O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange Toolbar FR\ToolbarContainer234.dll
                  O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\1202289613=0\strpmon.exe" dm=http://www.xxxcounter.de ad=http://www.xxxcounter.de sd=http://repay.www.xxxcounter.de
                  O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                  O4 - HKLM\..\Run: [Salestart(1)] "C:\Program Files\Common Files\Nettordinateur\stm.exe" dm=http://nettordinateur.com ad=http://nettordinateur.com sd=http://paylogs.nettordinateur.com
                  O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                  O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                  O8 - Extra context menu item: traduire la page - C:\Users\LAGRIV~1\AppData\Local\Temp\cce24D6.html
                  O8 - Extra context menu item: traduire le texte sélectionné - C:\Users\LAGRIV~1\AppData\Local\Temp\cce24F6.html
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                  O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                  O13 - Gopher Prefix:
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{B137F01C-BE9C-4C2D-BC8E-8E7AF30E086E}: NameServer = 192.168.1.1
                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                  O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                  O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                  O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                  0
                  1. Contributeur sécurité
                    on reprend du début ....

                    Double clique sur smitfraudfix.cmd
                    Sélectionne 1 pour créer un rapport des fichiers responsables de l'infection.

                    Ne fais rien d'autre sans notre avis

                    Copie/colle le sur ta prochaine réponse sur ce post stp.

                    Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
                    0
                    1. et voici

                      SmitFraudFix v2.286

                      Scan done at 18:34:35,37, 10/02/2008
                      Run from C:\Users\LA GRIVE\Desktop\SmitfraudFix
                      OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                      The filesystem type is NTFS
                      Fix run in normal mode

                      »»»»»»»»»»»»»»»»»»»»»»»» Process

                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\wininit.exe
                      C:\Windows\system32\services.exe
                      C:\Windows\system32\lsass.exe
                      C:\Windows\system32\lsm.exe
                      C:\Windows\system32\winlogon.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\SLsvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\Windows\System32\spoolsv.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\Explorer.EXE
                      C:\Program Files\Common Files\1202289613=0\strpmon.exe
                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                      C:\Program Files\Common Files\Nettordinateur\stm.exe
                      C:\Program Files\Windows Sidebar\sidebar.exe
                      C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Windows\ehome\ehtray.exe
                      C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\Windows\ehome\ehmsas.exe
                      C:\Program Files\Windows Sidebar\sidebar.exe
                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                      C:\Windows\system32\PnkBstrA.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\SearchIndexer.exe
                      C:\Windows\system32\WUDFHost.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Windows\System32\mobsync.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\Program Files\Windows Media Player\wmpnetwk.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                      C:\Program Files\Windows Live\Messenger\usnsvc.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\Windows\system32\cmd.exe
                      C:\Windows\system32\conime.exe
                      C:\Windows\system32\SearchProtocolHost.exe
                      C:\Windows\system32\SearchFilterHost.exe
                      C:\Windows\system32\wbem\wmiprvse.exe

                      »»»»»»»»»»»»»»»»»»»»»»»» hosts

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\LA GRIVE

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\LA GRIVE\Application Data

                      »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\LAGRIV~1\FAVORI~1

                      »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                      »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                      »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                      !!!Attention, following keys are not inevitably infected!!!

                      IEDFix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                      !!!Attention, following keys are not inevitably infected!!!

                      VACFix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                      !!!Attention, following keys are not inevitably infected!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                      !!!Attention, following keys are not inevitably infected!!!

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                      "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~3\\GOEC62~1.DLL"
                      "LoadAppInit_DLLs"=dword:00000001

                      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                      !!!Attention, following keys are not inevitably infected!!!

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                      »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                      »»»»»»»»»»»»»»»»»»»»»»»» DNS

                      Description: Carte réseau Fast Ethernet Realtek RTL8139/810x Family
                      DNS Server Search Order: 192.168.1.1

                      HKLM\SYSTEM\CCS\Services\Tcpip\..\{B137F01C-BE9C-4C2D-BC8E-8E7AF30E086E}: NameServer=192.168.1.1
                      HKLM\SYSTEM\CS1\Services\Tcpip\..\{B137F01C-BE9C-4C2D-BC8E-8E7AF30E086E}: NameServer=192.168.1.1
                      HKLM\SYSTEM\CS2\Services\Tcpip\..\{B137F01C-BE9C-4C2D-BC8E-8E7AF30E086E}: NameServer=192.168.1.1

                      »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                      »»»»»»»»»»»»»»»»»»»»»»»» End
                      0
                      1. Contributeur sécurité
                        ok ! on continue !

                        Redémarre en mode sans échec :
                        Pour cela, tapotes la touche F8 (Si F8 ne marche pas utilise la touche F5).

                        dès le début de l’allumage du pc sans t’arrêter.
                        Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                        Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                        tuto comment faire
                        http://www.commentcamarche.net/faq/sujet 5004 windows xp demarrage en mode sans echec
                        -------------------------------------------------------------------------------
                        Double clique sur smitfraudfix.cmd
                        Cette fois choisit l’option 2,
                        répond oui (o) à tout

                        Une fois le nettoyage terminé, SmitFraudfix ouvre le rapport de nettoyage sur le bloc-note.
                        Redémarre l'ordinateur en mode normal (comme d'habitude),
                        Sur le bureau doit se trouver le rapport enregistré (sinon il est sur le Poste de Travail / Disque C / rapport.txt)
                        Refais un log Hitjackthis et poste les rapports s'il te plait !

                        refais un HJT ensuite et poste le ensuite.
                        0
                        1. SmitFraudFix v2.286

                          Scan done at 18:49:43,55, 10/02/2008
                          Run from C:\Users\LA GRIVE\Desktop\SmitfraudFix
                          OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                          The filesystem type is NTFS
                          Fix run in safe mode

                          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                          !!!Attention, following keys are not inevitably infected!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                          »»»»»»»»»»»»»»»»»»»»»»»» hosts

                          127.0.0.1 localhost
                          ::1 localhost

                          »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                          VACFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                          S!Ri's WS2Fix: LSP not Found.

                          »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                          GenericRenosFix by S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                          IEDFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» DNS

                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{B137F01C-BE9C-4C2D-BC8E-8E7AF30E086E}: NameServer=192.168.1.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{B137F01C-BE9C-4C2D-BC8E-8E7AF30E086E}: NameServer=192.168.1.1
                          HKLM\SYSTEM\CS2\Services\Tcpip\..\{B137F01C-BE9C-4C2D-BC8E-8E7AF30E086E}: NameServer=192.168.1.1

                          »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

                          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                          !!!Attention, following keys are not inevitably infected!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                          »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                          Registry Cleaning done.

                          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                          !!!Attention, following keys are not inevitably infected!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» End

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 18:58:13, on 10/02/2008
                          Platform: Windows Vista (WinNT 6.00.1904)
                          MSIE: Internet Explorer v7.00 (7.00.6000.16575)
                          Boot mode: Normal

                          Running processes:
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\Explorer.EXE
                          C:\Program Files\Common Files\1202289613=0\strpmon.exe
                          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                          C:\Program Files\Common Files\Nettordinateur\stm.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\Windows\ehome\ehtray.exe
                          C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
                          C:\Program Files\Windows Media Player\wmpnscfg.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          C:\Windows\ehome\ehmsas.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                          C:\Windows\system32\SearchFilterHost.exe
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                          R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - C:\PROGRA~1\ORANGE~1\TOOLBA~2.DLL
                          O1 - Hosts: ::1 localhost
                          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                          O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                          O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                          O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange Toolbar FR\ToolbarContainer234.dll
                          O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\1202289613=0\strpmon.exe" dm=http://www.xxxcounter.de ad=http://www.xxxcounter.de sd=http://repay.www.xxxcounter.de
                          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                          O4 - HKLM\..\Run: [Salestart(1)] "C:\Program Files\Common Files\Nettordinateur\stm.exe" dm=http://nettordinateur.com ad=http://nettordinateur.com sd=http://paylogs.nettordinateur.com
                          O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
                          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                          O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                          O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                          O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
                          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                          O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                          O8 - Extra context menu item: traduire la page - C:\Users\LAGRIV~1\AppData\Local\Temp\cce24D6.html
                          O8 - Extra context menu item: traduire le texte sélectionné - C:\Users\LAGRIV~1\AppData\Local\Temp\cce24F6.html
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                          O13 - Gopher Prefix:
                          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                          O17 - HKLM\System\CCS\Services\Tcpip\..\{B137F01C-BE9C-4C2D-BC8E-8E7AF30E086E}: NameServer = 192.168.1.1
                          O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                          O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                          O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                          O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                          O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                          O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                          0
                          1. Contributeur sécurité
                            Télécharge OTMoveIt (de Old_Timer) sur ton Bureau.

                            double-clique sur OTMoveIt.exe pour le lancer.
                            copie la liste qui se trouve en citation ci-dessous,
                            et colle-la dans le cadre de gauche de OTMoveIt : Paste List of Files/Folders to be moved.

                            C:\Program Files\Common Files\1202289613=0\strpmon.exe
                            C:\Program Files\Common Files\Nettordinateur\stm.exe


                            clique sur MoveIt! pour lancer la suppression.
                            le résultat apparaitra dans le cadre "Results".
                            clique sur Exit pour fermer.
                            poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
                            il te sera peut-être demander de redémarrer le pc pour achever la suppression.
                            si c'est le cas accepte par Yes.

                            remet un HJT dans la foulée pour vérif' stp ! c'est presque bon.

                            Jo.
                            0
                            1. [Custom Input]
                              < C:\Program Files\Common Files\1202289613=0\strpmon.exe >
                              File/Folder C:\Program Files\Common Files\1202289613=0\strpmon.exe not found.
                              < C:\Program Files\Common Files\Nettordinateur\stm.exe >
                              File/Folder C:\Program Files\Common Files\Nettordinateur\stm.exe not found.

                              OTMoveIt2 v1.0.19 log created on 02102008_192033

                              et le htj merci pour ta patience jorginho67

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 19:23:28, on 10/02/2008
                              Platform: Windows Vista (WinNT 6.00.1904)
                              MSIE: Internet Explorer v7.00 (7.00.6000.16575)
                              Boot mode: Normal

                              Running processes:
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\Explorer.EXE
                              C:\Program Files\Common Files\1202289613=0\strpmon.exe
                              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                              C:\Program Files\Common Files\Nettordinateur\stm.exe
                              C:\Program Files\Windows Sidebar\sidebar.exe
                              C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Windows\ehome\ehtray.exe
                              C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
                              C:\Program Files\Windows Media Player\wmpnscfg.exe
                              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              C:\Windows\ehome\ehmsas.exe
                              C:\Program Files\Windows Sidebar\sidebar.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - C:\PROGRA~1\ORANGE~1\TOOLBA~2.DLL
                              O1 - Hosts: ::1 localhost
                              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                              O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                              O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                              O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange Toolbar FR\ToolbarContainer234.dll
                              O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\1202289613=0\strpmon.exe" dm=http://www.xxxcounter.de ad=http://www.xxxcounter.de sd=http://repay.www.xxxcounter.de
                              O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                              O4 - HKLM\..\Run: [Salestart(1)] "C:\Program Files\Common Files\Nettordinateur\stm.exe" dm=http://nettordinateur.com ad=http://nettordinateur.com sd=http://paylogs.nettordinateur.com
                              O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
                              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                              O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                              O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                              O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
                              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                              O8 - Extra context menu item: traduire la page - C:\Users\LAGRIV~1\AppData\Local\Temp\cce24D6.html
                              O8 - Extra context menu item: traduire le texte sélectionné - C:\Users\LAGRIV~1\AppData\Local\Temp\cce24F6.html
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                              O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                              O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                              O13 - Gopher Prefix:
                              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                              O17 - HKLM\System\CCS\Services\Tcpip\..\{B137F01C-BE9C-4C2D-BC8E-8E7AF30E086E}: NameServer = 192.168.1.1
                              O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                              O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                              O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                              O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                              O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                              O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                              O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                              0
                              1. Contributeur sécurité
                                on a du loupé quelque chose !
                                C:\ > Program Files\ > Common Files\ > 1202289613=0\ > strpmon.exe supprimes moi ça stp

                                la même pour
                                C:\Program Files\Common Files\Nettordinateur\stm.exe

                                si tu réussi, reposte un nouveau scan hjt
                                0
                                1. j'espère que c'est ça

                                  [Custom Input]
                                  < C:\Program Files\Common Files\1202289613=0\strpmon.exe >
                                  File/Folder C:\Program Files\Common Files\1202289613=0\strpmon.exe not found.
                                  < C:\Program Files\Common Files\Nettordinateur\stm.exe >
                                  File/Folder C:\Program Files\Common Files\Nettordinateur\stm.exe not found.

                                  OTMoveIt2 v1.0.19 log created on 02102008_193619

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 19:39:26, on 10/02/2008
                                  Platform: Windows Vista (WinNT 6.00.1904)
                                  MSIE: Internet Explorer v7.00 (7.00.6000.16575)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\Windows\system32\Dwm.exe
                                  C:\Windows\system32\taskeng.exe
                                  C:\Windows\Explorer.EXE
                                  C:\Program Files\Common Files\1202289613=0\strpmon.exe
                                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                  C:\Program Files\Common Files\Nettordinateur\stm.exe
                                  C:\Program Files\Windows Sidebar\sidebar.exe
                                  C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                  C:\Windows\ehome\ehtray.exe
                                  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
                                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                  C:\Windows\ehome\ehmsas.exe
                                  C:\Program Files\Windows Sidebar\sidebar.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                  R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - C:\PROGRA~1\ORANGE~1\TOOLBA~2.DLL
                                  O1 - Hosts: ::1 localhost
                                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                                  O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                  O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange Toolbar FR\ToolbarContainer234.dll
                                  O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\1202289613=0\strpmon.exe" dm=http://www.xxxcounter.de ad=http://www.xxxcounter.de sd=http://repay.www.xxxcounter.de
                                  O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                  O4 - HKLM\..\Run: [Salestart(1)] "C:\Program Files\Common Files\Nettordinateur\stm.exe" dm=http://nettordinateur.com ad=http://nettordinateur.com sd=http://paylogs.nettordinateur.com
                                  O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
                                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                  O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                  O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                  O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
                                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                  O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
                                  O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
                                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                                  O8 - Extra context menu item: traduire la page - C:\Users\LAGRIV~1\AppData\Local\Temp\cce24D6.html
                                  O8 - Extra context menu item: traduire le texte sélectionné - C:\Users\LAGRIV~1\AppData\Local\Temp\cce24F6.html
                                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                  O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                  O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                                  O13 - Gopher Prefix:
                                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                  O17 - HKLM\System\CCS\Services\Tcpip\..\{B137F01C-BE9C-4C2D-BC8E-8E7AF30E086E}: NameServer = 192.168.1.1
                                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                  O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                  O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                  O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                                  O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                  O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                                  0
                                  1. Contributeur sécurité
                                    derme, là c'est moi qui me suis mal exprimé !!!
                                    je voulais dire en manuel, tu suis le chemin indiqué et tu les supprimes !
                                    C:\ > Program Files\ > Common Files\ > 1202289613=0\ > strpmon.exe supprimes moi ça stp

                                    la même pour
                                    C:\Program Files\Common Files\Nettordinateur\stm.exe

                                    Nettordinateur regarde dans " ajout/suppression de programmes et supprime le si tu le trouves !
                                    0
                                    1. c'est fait je les aient envoyer a la poubelle et vider la corbeille

                                      et htj au cas ou

                                      Logfile of Trend Micro HijackThis v2.0.2
                                      Scan saved at 20:08:16, on 10/02/2008
                                      Platform: Windows Vista (WinNT 6.00.1904)
                                      MSIE: Internet Explorer v7.00 (7.00.6000.16575)
                                      Boot mode: Normal

                                      Running processes:
                                      C:\Windows\system32\Dwm.exe
                                      C:\Windows\system32\taskeng.exe
                                      C:\Windows\Explorer.EXE
                                      C:\Program Files\Common Files\1202289613=0\strpmon.exe
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                      C:\Program Files\Common Files\Nettordinateur\stm.exe
                                      C:\Program Files\Windows Sidebar\sidebar.exe
                                      C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                      C:\Windows\ehome\ehtray.exe
                                      C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
                                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                      C:\Windows\ehome\ehmsas.exe
                                      C:\Program Files\Windows Sidebar\sidebar.exe
                                      C:\Program Files\Internet Explorer\iexplore.exe
                                      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                      R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - C:\PROGRA~1\ORANGE~1\TOOLBA~2.DLL
                                      O1 - Hosts: ::1 localhost
                                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                      O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                                      O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                      O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange Toolbar FR\ToolbarContainer234.dll
                                      O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\1202289613=0\strpmon.exe" dm=http://www.xxxcounter.de ad=http://www.xxxcounter.de sd=http://repay.www.xxxcounter.de
                                      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                      O4 - HKLM\..\Run: [Salestart(1)] "C:\Program Files\Common Files\Nettordinateur\stm.exe" dm=http://nettordinateur.com ad=http://nettordinateur.com sd=http://paylogs.nettordinateur.com
                                      O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
                                      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                      O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                      O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                      O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
                                      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                      O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
                                      O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
                                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                                      O8 - Extra context menu item: traduire la page - C:\Users\LAGRIV~1\AppData\Local\Temp\cce24D6.html
                                      O8 - Extra context menu item: traduire le texte sélectionné - C:\Users\LAGRIV~1\AppData\Local\Temp\cce24F6.html
                                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                                      O13 - Gopher Prefix:
                                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                      O17 - HKLM\System\CCS\Services\Tcpip\..\{B137F01C-BE9C-4C2D-BC8E-8E7AF30E086E}: NameServer = 192.168.1.1
                                      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                      O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                      O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                                      O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                      O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                                      O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                                      0
                                      • 1
                                      • 2
                                      • 3