Attaque de spyware Au secours

J'ai des spyware qui m'ouvrent en permanence des pages de pubs ONLY THE BEST.
J'ai déjà vu sur d'autres reponses dans ce forum ce qu'il fallait faire mais je ne connais pas les lignes a éliminer.
si quelqu'un pouvait m'aider son aide serait la bienvenue (très)
merci d'avance.
Voici ce que donne hijachthis :

Logfile of HijackThis v1.99.1
Scan saved at 18:06:42, on 19/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\apign32.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Norton SystemWorks\Norton CleanSweep\CsinsmNT.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Sonic\RecordNow!\RecordNow.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Thomas\LOCALS~1\Temp\Répertoire temporaire 1 pour hijackthis.zip\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\taskmgr.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\dcnwk.dll/sp.html#83556
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\dcnwk.dll/sp.html#83556
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\dcnwk.dll/sp.html#83556
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\dcnwk.dll/sp.html#83556
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\dcnwk.dll/sp.html#83556
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\dcnwk.dll/sp.html#83556
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {EF00589F-4853-36A5-3704-A19633EDC95B} - C:\WINDOWS\d3wa32.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ntvp.exe] C:\WINDOWS\system32\ntvp.exe
O4 - HKLM\..\Run: [apign32.exe] C:\WINDOWS\apign32.exe
O4 - HKLM\..\RunOnce: [crna32.exe] C:\WINDOWS\system32\crna32.exe
O4 - HKLM\..\RunOnce: [sdkri.exe] C:\WINDOWS\system32\sdkri.exe
O4 - HKLM\..\RunOnce: [iplj.exe] C:\WINDOWS\system32\iplj.exe
O4 - HKLM\..\RunOnce: [crpn32.exe] C:\WINDOWS\system32\crpn32.exe
O4 - HKLM\..\RunOnce: [winee32.exe] C:\WINDOWS\winee32.exe
O4 - HKLM\..\RunOnce: [appsg.exe] C:\WINDOWS\appsg.exe
O4 - HKLM\..\RunOnce: [ntsj.exe] C:\WINDOWS\ntsj.exe
O4 - HKLM\..\RunOnce: [javarq32.exe] C:\WINDOWS\system32\javarq32.exe
O4 - HKLM\..\RunOnce: [javatm.exe] C:\WINDOWS\system32\javatm.exe
O4 - HKLM\..\RunOnce: [sdkvs.exe] C:\WINDOWS\sdkvs.exe
O4 - HKLM\..\RunOnce: [windb.exe] C:\WINDOWS\windb.exe
O4 - HKLM\..\RunOnce: [ipym.exe] C:\WINDOWS\system32\ipym.exe
O4 - HKLM\..\RunOnce: [sysdn.exe] C:\WINDOWS\system32\sysdn.exe
O4 - HKLM\..\RunOnce: [apine.exe] C:\WINDOWS\apine.exe
O4 - HKLM\..\RunOnce: [ntdy.exe] C:\WINDOWS\ntdy.exe
O4 - HKLM\..\RunOnce: [appby.exe] C:\WINDOWS\system32\appby.exe
O4 - HKLM\..\RunOnce: [appel.exe] C:\WINDOWS\appel.exe
O4 - HKLM\..\RunOnce: [mskf32.exe] C:\WINDOWS\system32\mskf32.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CleanSweep Smart Sweep-Internet Sweep.lnk = C:\Program Files\Norton SystemWorks\Norton CleanSweep\CsinsmNT.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://home.free.fr/
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.bitstream.com/wfplayer/tdserver.cab
O16 - DPF: {0594AF7E-573B-40DF-8165-E47AB2EAEFE8} - http://akamai.downloadv3.com/binaries/P2EClient/EGAUTH_1014_FR_XP.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20030625/qtinstall.info.apple.com/abarth/fr/win/QuickTimeInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {86EEF11E-FF16-48CE-B1A2-474B663041A9} - http://1073145110000.kit.sexequalite.com/14595/CD/SublimAnal.exe
O16 - DPF: {94F5DCB7-816C-4B94-A2C1-856C6E323C5B} - http://akamai.downloadv3.com/binaries/LiveService/LiveService_4_FR_XP.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {EEECA057-AD0F-44A7-8BE5-8634CEDBDBD1} - http://akamai.downloadv3.com/binaries/IA/netpe32_FR_XP.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe

18 réponses

  1. Salut, télécharge un anti-spyware ceci t'aidera a les éliminé...
    Sur ton log je vois bcp de choses de ad-aware

    Supprime ceci

    O4 - HKLM\..\Run: [apign32.exe] C:\WINDOWS\apign32.exe
    O4 - HKLM\..\RunOnce: [crna32.exe] C:\WINDOWS\system32\crna32.exe
    O4 - HKLM\..\RunOnce: [sdkri.exe] C:\WINDOWS\system32\sdkri.exe
    O4 - HKLM\..\RunOnce: [iplj.exe] C:\WINDOWS\system32\iplj.exe
    O4 - HKLM\..\RunOnce: [crpn32.exe] C:\WINDOWS\system32\crpn32.exe
    O4 - HKLM\..\RunOnce: [winee32.exe] C:\WINDOWS\winee32.exe
    O4 - HKLM\..\RunOnce: [appsg.exe] C:\WINDOWS\appsg.exe
    O4 - HKLM\..\RunOnce: [ntsj.exe] C:\WINDOWS\ntsj.exe
    O4 - HKLM\..\RunOnce: [javarq32.exe] C:\WINDOWS\system32\javarq32.exe
    O4 - HKLM\..\RunOnce: [javatm.exe] C:\WINDOWS\system32\javatm.exe
    O4 - HKLM\..\RunOnce: [sdkvs.exe] C:\WINDOWS\sdkvs.exe
    O4 - HKLM\..\RunOnce: [windb.exe] C:\WINDOWS\windb.exe
    O4 - HKLM\..\RunOnce: [ipym.exe] C:\WINDOWS\system32\ipym.exe
    O4 - HKLM\..\RunOnce: [sysdn.exe] C:\WINDOWS\system32\sysdn.exe
    O4 - HKLM\..\RunOnce: [apine.exe] C:\WINDOWS\apine.exe
    O4 - HKLM\..\RunOnce: [ntdy.exe] C:\WINDOWS\ntdy.exe
    O4 - HKLM\..\RunOnce: [appby.exe] C:\WINDOWS\system32\appby.exe
    O4 - HKLM\..\RunOnce: [appel.exe] C:\WINDOWS\appel.exe
    O4 - HKLM\..\RunOnce: [mskf32.exe] C:\WINDOWS\system32\mskf32.exe

    tien moi au courant

    Si tu vx faire une analyse anti spyware gratuite va sur

    http://www.trendmicro.com/spyware-scan/
    0
    1. Contributeur sécurité
      salut

      ► imprime ceci pour ne rien oublier et tous faire
      tous faire dans l ordre imperativement
      -------------------------
      ► tous da bord telecharge ces programmes si tu ne les a pas et met les a jour mais ne les utilise pas encore et verifie que tu as les bonnes version c est imperatif

      ad-aware (1)version 1.06

      (ici) http://www.florensac-chasse-trap.com/ section virus
      voir demo
      http://pageperso.aol.fr/balltrap34/adwseflash.zip
      0
      1. ok les gars merci beaucoup
        j'y vais et je vous dit où j'en suis
        a tout à l'heure
        0
        1. Contributeur sécurité
          oki
          a++
          0
          1. voila c'est fait mais en même temps que j'écris ces lignes j'ai re-une publicité only the best qui apparait....flute !!
            je te donne le nouveau scan de hijack :

            Logfile of HijackThis v1.99.1
            Scan saved at 20:27:34, on 19/08/2005
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\System32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\LEXBCES.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\LEXPPS.EXE
            C:\WINDOWS\System32\drivers\CDAC11BA.EXE
            C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
            C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
            C:\WINDOWS\system32\CTsvcCDA.exe
            C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
            C:\Program Files\Norton Internet Security\ISSVC.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
            C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
            C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
            C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
            C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
            C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\javabt32.exe
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\WINDOWS\System32\DSentry.exe
            C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
            C:\WINDOWS\system32\dla\tfswctrl.exe
            C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe
            C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
            C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
            C:\WINDOWS\ntxw.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
            C:\WINDOWS\system32\ntvdm.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\DOCUME~1\Thomas\LOCALS~1\Temp\Répertoire temporaire 2 pour hijackthis.zip\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
            R3 - Default URLSearchHook is missing
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
            O2 - BHO: Class - {435DCDD9-3B9E-86B0-4766-2C88AE5BABD3} - C:\WINDOWS\system32\ntfh32.dll
            O2 - BHO: Class - {7F0CB30D-9647-D194-763C-FF4A8B78CA18} - C:\WINDOWS\system32\ierf.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
            O2 - BHO: Class - {BA66EA91-C16C-D1A2-86DA-4CC1F4EF8C99} - C:\WINDOWS\apppm.dll
            O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
            O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
            O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
            O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
            O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
            O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
            O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
            O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
            O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
            O4 - HKLM\..\Run: [winip32.exe] C:\WINDOWS\system32\winip32.exe
            O4 - HKLM\..\Run: [ntxw.exe] C:\WINDOWS\ntxw.exe
            O4 - HKLM\..\RunOnce: [crwn32.exe] C:\WINDOWS\system32\crwn32.exe
            O4 - HKLM\..\RunOnce: [javabt32.exe] C:\WINDOWS\javabt32.exe
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
            O4 - Global Startup: CleanSweep Smart Sweep-Internet Sweep.lnk = C:\Program Files\Norton SystemWorks\Norton CleanSweep\CsinsmNT.exe
            O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
            O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
            O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O14 - IERESET.INF: START_PAGE_URL=http://home.free.fr/
            O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
            O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
            O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
            O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
            O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
            O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
            O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
            O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
            O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
            O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
            O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
            O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
            O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
            O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
            O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Pacsptisvr.exe
            O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
            O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
            O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
            O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
            O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
            O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Sptisrv.exe
            O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
            O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
            0
            1. Contributeur sécurité
              a tu bien fait about buster j usqua qu il ne trouve plus rien?
              0
              1. ouais, je l'ai passé plusieurs fois jusqu'à ce qu'il trouve pus rien
                mais j'ai toujours ces pubs à la con
                j'ai même des alertes de sécurité type SP 2 mais j'ai bien l'impression que c'est pas des trucs Windows qu'ils veulent me faire télécharger...
                Une idée ?
                0
                1. Contributeur sécurité
                  remet un nouvel hijack stp
                  0
                  1. Excuse moi mais je devais me coucher tot parce que je travaillais aujourd'hui. je te donne donc le nouvel hijack:

                    Logfile of HijackThis v1.99.1
                    Scan saved at 13:33:40, on 20/08/2005
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\System32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\LEXBCES.EXE
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\system32\LEXPPS.EXE
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                    C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
                    C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                    C:\WINDOWS\system32\CTsvcCDA.exe
                    C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
                    C:\Program Files\Norton Internet Security\ISSVC.exe
                    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                    C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
                    C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                    C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    C:\WINDOWS\System32\DSentry.exe
                    C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
                    C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
                    C:\Program Files\QuickTime\qttask.exe
                    C:\WINDOWS\system32\dla\tfswctrl.exe
                    C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                    C:\WINDOWS\ntxw.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\WINDOWS\system32\rundll32.exe
                    C:\Program Files\iPod\bin\iPodService.exe
                    C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Documents and Settings\Thomas\Bureau\HijackThis.exe
                    C:\Program Files\Messenger\msmsgs.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    R3 - Default URLSearchHook is missing
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                    O2 - BHO: Class - {5152B2CE-E0B3-1CAE-8534-9EFEF6004087} - C:\WINDOWS\msvd32.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                    O2 - BHO: Class - {E92DD6D2-E4DE-DD00-7878-1BE0937341A2} - C:\WINDOWS\appnq32.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
                    O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                    O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                    O4 - HKLM\..\Run: [winip32.exe] C:\WINDOWS\system32\winip32.exe
                    O4 - HKLM\..\Run: [ntxw.exe] C:\WINDOWS\ntxw.exe
                    O4 - HKLM\..\RunOnce: [crwn32.exe] C:\WINDOWS\system32\crwn32.exe
                    O4 - HKLM\..\RunOnce: [javabt32.exe] C:\WINDOWS\javabt32.exe
                    O4 - HKLM\..\RunOnce: [wingx.exe] C:\WINDOWS\system32\wingx.exe
                    O4 - HKLM\..\RunOnce: [javart.exe] C:\WINDOWS\javart.exe
                    O4 - HKLM\..\RunOnce: [netkl32.exe] C:\WINDOWS\netkl32.exe
                    O4 - HKLM\..\RunOnce: [mfcuo.exe] C:\WINDOWS\mfcuo.exe
                    O4 - HKLM\..\RunOnce: [ieev32.exe] C:\WINDOWS\system32\ieev32.exe
                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [Instant Access] rundll32.exe EGCOMLIB_1035.dll,InstantAccess
                    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
                    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsearch.html
                    O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar2.dll/cmbacklinks.html
                    O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsimilar.html
                    O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar2.dll/cmcache.html
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
                    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O14 - IERESET.INF: START_PAGE_URL=http://home.free.fr/
                    O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\crwn32.exe" /s (file missing)
                    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                    O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
                    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
                    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                    O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
                    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
                    O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
                    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
                    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                    O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
                    O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
                    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Pacsptisvr.exe
                    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                    O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
                    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Sptisrv.exe
                    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                    0
                    1. Excuse moi mais je devais me coucher tot parce que je travaillais aujourd'hui. je te donne donc le nouvel hijack:

                      Logfile of HijackThis v1.99.1
                      Scan saved at 13:33:40, on 20/08/2005
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\System32\Ati2evxx.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\LEXBCES.EXE
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\system32\LEXPPS.EXE
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                      C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
                      C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                      C:\WINDOWS\system32\CTsvcCDA.exe
                      C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
                      C:\Program Files\Norton Internet Security\ISSVC.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                      C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                      C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
                      C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                      C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                      C:\WINDOWS\System32\DSentry.exe
                      C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
                      C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
                      C:\Program Files\QuickTime\qttask.exe
                      C:\WINDOWS\system32\dla\tfswctrl.exe
                      C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                      C:\WINDOWS\ntxw.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\WINDOWS\system32\rundll32.exe
                      C:\Program Files\iPod\bin\iPodService.exe
                      C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Documents and Settings\Thomas\Bureau\HijackThis.exe
                      C:\Program Files\Messenger\msmsgs.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - Default URLSearchHook is missing
                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                      O2 - BHO: Class - {5152B2CE-E0B3-1CAE-8534-9EFEF6004087} - C:\WINDOWS\msvd32.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                      O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                      O2 - BHO: Class - {E92DD6D2-E4DE-DD00-7878-1BE0937341A2} - C:\WINDOWS\appnq32.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                      O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                      O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
                      O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                      O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                      O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                      O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                      O4 - HKLM\..\Run: [winip32.exe] C:\WINDOWS\system32\winip32.exe
                      O4 - HKLM\..\Run: [ntxw.exe] C:\WINDOWS\ntxw.exe
                      O4 - HKLM\..\RunOnce: [crwn32.exe] C:\WINDOWS\system32\crwn32.exe
                      O4 - HKLM\..\RunOnce: [javabt32.exe] C:\WINDOWS\javabt32.exe
                      O4 - HKLM\..\RunOnce: [wingx.exe] C:\WINDOWS\system32\wingx.exe
                      O4 - HKLM\..\RunOnce: [javart.exe] C:\WINDOWS\javart.exe
                      O4 - HKLM\..\RunOnce: [netkl32.exe] C:\WINDOWS\netkl32.exe
                      O4 - HKLM\..\RunOnce: [mfcuo.exe] C:\WINDOWS\mfcuo.exe
                      O4 - HKLM\..\RunOnce: [ieev32.exe] C:\WINDOWS\system32\ieev32.exe
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [Instant Access] rundll32.exe EGCOMLIB_1035.dll,InstantAccess
                      O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
                      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                      O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsearch.html
                      O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar2.dll/cmbacklinks.html
                      O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsimilar.html
                      O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar2.dll/cmcache.html
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
                      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O14 - IERESET.INF: START_PAGE_URL=http://home.free.fr/
                      O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\crwn32.exe" /s (file missing)
                      O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                      O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
                      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
                      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                      O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
                      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                      O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
                      O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
                      O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
                      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                      O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                      O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
                      O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
                      O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Pacsptisvr.exe
                      O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                      O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                      O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                      O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
                      O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Sptisrv.exe
                      O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                      0
                      1. Contributeur sécurité
                        sans redemarrer

                        relance hijack coche ces lignes et ensuite clik sur fix
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\pakpx.dll/sp.html#83556
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        R3 - Default URLSearchHook is missing
                        O2 - BHO: Class - {E92DD6D2-E4DE-DD00-7878-1BE0937341A2} - C:\WINDOWS\appnq32.dll
                        O4 - HKLM\..\Run: [winip32.exe] C:\WINDOWS\system32\winip32.exe
                        O4 - HKLM\..\Run: [ntxw.exe] C:\WINDOWS\ntxw.exe
                        O4 - HKLM\..\RunOnce: [crwn32.exe] C:\WINDOWS\system32\crwn32.exe
                        O4 - HKLM\..\RunOnce: [javabt32.exe] C:\WINDOWS\javabt32.exe
                        O4 - HKLM\..\RunOnce: [wingx.exe] C:\WINDOWS\system32\wingx.exe
                        O4 - HKLM\..\RunOnce: [javart.exe] C:\WINDOWS\javart.exe
                        O4 - HKLM\..\RunOnce: [netkl32.exe] C:\WINDOWS\netkl32.exe
                        O4 - HKLM\..\RunOnce: [mfcuo.exe] C:\WINDOWS\mfcuo.exe
                        O4 - HKLM\..\RunOnce: [ieev32.exe] C:\WINDOWS\system32\ieev32.exe
                        O4 - HKCU\..\Run: [Instant Access] rundll32.exe EGCOMLIB_1035.dll,InstantAccess
                        O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\crwn32.exe" /s (file missing)

                        ----------------------
                        clik sur Démarrer->exécuter->tape: services.msc

                        Double-clique: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I)

                        Règle-le sur "Arrêté" et "Désactivé".

                        -------------------------
                        telecharge ceci
                        Kill Box :

                        (ici) http://www.florensac-chasse-trap.com/ section virus

                        demo http://pageperso.aol.fr/balltrap34/killbox.htm

                        et utilise la methode avec le bloc note

                        met ceci

                        C:\WINDOWS\pakpx.dll/sp.html#83556
                        C:\WINDOWS\pakpx.dll
                        C:\WINDOWS\appnq32.dll
                        C:\WINDOWS\system32\winip32.exe
                        C:\WINDOWS\ntxw.exe
                        C:\WINDOWS\system32\crwn32.exe
                        C:\WINDOWS\javabt32.exe
                        C:\WINDOWS\system32\wingx.exe
                        C:\WINDOWS\javart.exe
                        C:\WINDOWS\netkl32.exe
                        C:\WINDOWS\mfcuo.exe
                        C:\WINDOWS\system32\ieev32.exe
                        EGCOMLIB_1035.dll
                        C:\WINDOWS\system32\crwn32.exe

                        -------
                        passe a nouveau about buster toujour jusqu a qu il ne trouve plus rien

                        redemarre et refait un hijack
                        0
                        1. Bonjour,

                          http://www.microsoft.com/france/download/

                          J'attire votre attention sur Microsoft AntiSpyware

                          C'est une version Bêta. Mais, depuis avril, elle n'a rien laissé passé.

                          Cordialement

                          La science ne fait que truver ce qui existe depuis toujours
                          Hubert REEVES
                          0
                          1. Bon après avoir écouté vos deux messages
                            je fais passer sans arrêt tous mes logiciels de sécurité
                            après avoir viré ce que tu ma dis balltrap ca a l'air d'aller mieux.
                            Je me méfie...
                            Je vous redonne le hijack et surtout je ne redemarre pas l'ordi en attendant vos posts...

                            Logfile of HijackThis v1.99.1
                            Scan saved at 21:38:43, on 20/08/2005
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\System32\Ati2evxx.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\LEXBCES.EXE
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\WINDOWS\system32\LEXPPS.EXE
                            C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                            C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
                            C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                            C:\WINDOWS\system32\CTsvcCDA.exe
                            C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
                            C:\Program Files\Norton Internet Security\ISSVC.exe
                            C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                            C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                            C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
                            C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                            C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                            C:\WINDOWS\system32\Ati2evxx.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                            C:\WINDOWS\System32\DSentry.exe
                            C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
                            C:\Program Files\QuickTime\qttask.exe
                            C:\WINDOWS\system32\dla\tfswctrl.exe
                            C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
                            C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
                            C:\Program Files\iTunes\iTunesHelper.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                            C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
                            C:\Program Files\iPod\bin\iPodService.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
                            C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
                            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                            C:\PROGRA~1\NORTON~2\NORTON~1\navw32.exe
                            C:\Documents and Settings\Thomas\Mes documents\Programme\aswclnr.exe
                            C:\Documents and Settings\Thomas\Mes documents\Programme\aswclnr.tmp
                            C:\Program Files\Messenger\msmsgs.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Documents and Settings\Thomas\Bureau\HijackThis.exe

                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\merxz.dll/sp.html#37049
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.fr
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\merxz.dll/sp.html#37049
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\merxz.dll/sp.html#37049
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.fr
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\merxz.dll/sp.html#37049
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
                            R3 - Default URLSearchHook is missing
                            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                            O2 - BHO: Class - {A18263D0-5F1E-F10F-818D-9DB070DD5394} - C:\WINDOWS\system32\crar.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                            O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                            O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                            O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                            O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
                            O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                            O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                            O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                            O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                            O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
                            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                            O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                            O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
                            O4 - HKLM\..\Run: [netoj32.exe] C:\WINDOWS\system32\netoj32.exe
                            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
                            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                            O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
                            O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
                            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
                            O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O14 - IERESET.INF: START_PAGE_URL=http://home.free.fr/
                            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                            O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                            O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
                            O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
                            O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                            O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
                            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                            O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                            O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                            O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
                            O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
                            O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                            O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
                            O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                            O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                            O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
                            O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
                            O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Pacsptisvr.exe
                            O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                            O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                            O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                            O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                            O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
                            O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Sptisrv.exe
                            O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                            O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                            0
                            1. Contributeur sécurité
                              tu nas pas desactiver le the timer sa ne peut pas marcher si tu ne le fait pas
                              desactive le
                              refait un hijack et la je te dirait quoi faire
                              0
                              1. Ok balltrap aussitôt dit aussitôt fait...
                                Encore merci pour ton aide .
                                je te donne le nouvel hijack sans tea timer :

                                Logfile of HijackThis v1.99.1
                                Scan saved at 10:18:36, on 21/08/2005
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\System32\Ati2evxx.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\LEXBCES.EXE
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\WINDOWS\system32\LEXPPS.EXE
                                C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                                C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
                                C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                                C:\WINDOWS\system32\CTsvcCDA.exe
                                C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
                                C:\Program Files\Norton Internet Security\ISSVC.exe
                                C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                                C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                                C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
                                C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                                C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                                C:\WINDOWS\system32\Ati2evxx.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                C:\WINDOWS\System32\DSentry.exe
                                C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
                                C:\Program Files\QuickTime\qttask.exe
                                C:\WINDOWS\system32\dla\tfswctrl.exe
                                C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
                                C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
                                C:\Program Files\iTunes\iTunesHelper.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                                C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
                                C:\Program Files\iPod\bin\iPodService.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
                                C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
                                C:\Program Files\Messenger\msmsgs.exe
                                C:\Documents and Settings\Thomas\Bureau\HijackThis.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\akvxp.dll/sp.html#37049
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\akvxp.dll/sp.html#37049
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\akvxp.dll/sp.html#37049
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\akvxp.dll/sp.html#37049
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
                                R3 - Default URLSearchHook is missing
                                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                                O2 - BHO: Class - {A18263D0-5F1E-F10F-818D-9DB070DD5394} - C:\WINDOWS\system32\crar.dll (file missing)
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                                O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                                O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
                                O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                                O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                                O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                                O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
                                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                                O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                                O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
                                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
                                O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                                O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
                                O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
                                O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O14 - IERESET.INF: START_PAGE_URL=http://home.free.fr/
                                O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                                O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                                O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
                                O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
                                O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                                O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
                                O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                                O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                                O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                                O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                                O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
                                O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
                                O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
                                O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                                O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                                O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
                                O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
                                O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Pacsptisvr.exe
                                O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                                O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                                O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                                O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                                O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
                                O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Sptisrv.exe
                                O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                                O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                                0
                                1. Contributeur sécurité
                                  relance hijack coche ces lignes et ensuite clik sur fix

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\akvxp.dll/sp.html#37049
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\akvxp.dll/sp.html#37049
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\akvxp.dll/sp.html#37049
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\akvxp.dll/sp.html#37049
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
                                  R3 - Default URLSearchHook is missing
                                  O2 - BHO: Class - {A18263D0-5F1E-F10F-818D-9DB070DD5394} - C:\WINDOWS\system32\crar.dll (file missing)

                                  ----------------------
                                  redemarre en mode sans echec

                                  mode sans echec pour cela tu tapote la touche f8
                                  des le debut de l allumage du pc sans t arreter
                                  une fenetre vas souvrir tute deplace avec les fleches du clavier sur demarreren mode sans echec
                                  une fois sur le bureau il ni auras pas toutes les couleurs et autres c est normal.si f8 ne marche pas utilise la touche f5
                                  -------------------------
                                  recherche et suppr ceci

                                  attention seulement les fichiers si tu trouve
                                  C:\WINDOWS\system32\akvxp.dll/sp.html#37049
                                  C:\WINDOWS\system32\akvxp.dll
                                  C:\WINDOWS\system32\crar.dll

                                  -----------------
                                  redemarre et nouvel hijack
                                  0
                                  1. Excuse moi Balltrap de ne pas t'avoir répondu avant mais avec la fin des vacances, j'ai eu peu de temps libre pour m'occuper de mon ordinateur.
                                    N'empêche on a reussi ( surtout toi ) on a enlever les spywares.
                                    Je te dis donc un grand merci pour ton aide précieuse et peut être à une prochaine fois sur ce forum ( le + tard possible j'espère )
                                    Merci encore
                                    Antoine
                                    0
                                    1. Contributeur sécurité
                                      content pour toi
                                      et a++
                                      0