Infecter par un certain

Bonjour a tous
un scan avec avg m'a averti que j'etais infecter par "dropper.nuclear.a" seulement voila ; aucune donnée sur le web a propos de cette infection . malgres tout, les pages web de spyware et autres spam ne cessent de s'afficher intempestivement. que dois-je faire ?
d'avance merci a celui qui se penchera sur mon probleme.
Configuration: Windows XP
Internet Explorer 6.0

5 réponses

  1. salut,
    bienvenue sur le forum.As tu fais analyser ton pc avec c cleaner,spybot ou ad aware ,si non,fais ces analyses et colle moi les rapports ici
    Merci.

    le temps est fait pour apprendre..........
    0
    1. tout d'abord merci de ton aide
      soucis bisard avec adaware il se bloque en plein millieux de mon scann il est rester bloquer . tout simplement . sinon comment avoir un rapport avec spyboot.
      desolé je debute..
      0
      1. Si ca bloque c est mauvais signe ,ca veut dire que ton pc rame.
        Peux tu me mettre un log hyjackthis ici stp
        0
    2. ok desolé par contre il ne bloc pas en faisant un scann rapide
      voici le rapport

      Ad-Aware SE Build 1.06r1
      Logfile Created on:jeudi 24 mai 2007 23:14:09
      Created with Ad-Aware SE Personal, free for private use.
      Using definitions file:SE1R172 22.05.2007
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

      References detected during the scan:
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
      MRU List(TAC index:0):10 total references
      Tracking Cookie(TAC index:3):1 total references
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

      Ad-Aware SE Settings
      ===========================
      Set : Search for negligible risk entries
      Set : Safe mode (always request confirmation)
      Set : Scan active processes
      Set : Scan registry
      Set : Deep-scan registry
      Set : Scan my IE Favorites for banned URLs
      Set : Scan my Hosts file

      Extended Ad-Aware SE Settings
      ===========================
      Set : Unload recognized processes & modules during scan
      Set : Scan registry for all users instead of current user only
      Set : Always try to unload modules before deletion
      Set : During removal, unload Explorer and IE if necessary
      Set : Let Windows remove files in use at next reboot
      Set : Delete quarantined objects after restoring
      Set : Include basic Ad-Aware settings in log file
      Set : Include additional Ad-Aware settings in log file
      Set : Include reference summary in log file
      Set : Include alternate data stream details in log file
      Set : Play sound at scan completion if scan locates critical objects

      24-05-2007 23:14:09 - Scan started. (Smart mode)

      Listing running processes
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

      #:1 [smss.exe]
      FilePath : \SystemRoot\System32\
      ProcessID : 516
      ThreadCreationTime : 24-05-2007 18:24:30
      BasePriority : Normal

      #:2 [csrss.exe]
      FilePath : \??\C:\WINDOWS\system32\
      ProcessID : 568
      ThreadCreationTime : 24-05-2007 18:24:32
      BasePriority : Normal

      #:3 [winlogon.exe]
      FilePath : \??\C:\WINDOWS\system32\
      ProcessID : 604
      ThreadCreationTime : 24-05-2007 18:24:35
      BasePriority : High

      #:4 [services.exe]
      FilePath : C:\WINDOWS\system32\
      ProcessID : 648
      ThreadCreationTime : 24-05-2007 18:24:37
      BasePriority : Normal
      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
      ProductVersion : 5.1.2600.2180
      ProductName : Système d'exploitation Microsoft® Windows®
      CompanyName : Microsoft Corporation
      FileDescription : Applications Services et Contrôleur
      InternalName : services.exe
      LegalCopyright : © Microsoft Corporation. Tous droits réservés.
      OriginalFilename : services.exe

      #:5 [lsass.exe]
      FilePath : C:\WINDOWS\system32\
      ProcessID : 668
      ThreadCreationTime : 24-05-2007 18:24:37
      BasePriority : Normal
      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
      ProductVersion : 5.1.2600.2180
      ProductName : Microsoft® Windows® Operating System
      CompanyName : Microsoft Corporation
      FileDescription : LSA Shell (Export Version)
      InternalName : lsass.exe
      LegalCopyright : © Microsoft Corporation. All rights reserved.
      OriginalFilename : lsass.exe

      #:6 [ati2evxx.exe]
      FilePath : C:\WINDOWS\system32\
      ProcessID : 820
      ThreadCreationTime : 24-05-2007 18:24:39
      BasePriority : Normal
      FileVersion : 6.14.10.4112
      ProductVersion : 6.14.10.4112.02
      ProductName : ATI External Event Utility for WindowsNT and Windows9X
      CompanyName : ATI Technologies Inc.
      FileDescription : ATI External Event Utility EXE Module
      InternalName : ATI2EVXX.EXE
      LegalCopyright : Copyright © 1999-2004 ATI Technologies Inc.
      OriginalFilename : ATI2EVXX.EXE

      #:7 [svchost.exe]
      FilePath : C:\WINDOWS\system32\
      ProcessID : 844
      ThreadCreationTime : 24-05-2007 18:24:39
      BasePriority : Normal
      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
      ProductVersion : 5.1.2600.2180
      ProductName : Microsoft® Windows® Operating System
      CompanyName : Microsoft Corporation
      FileDescription : Generic Host Process for Win32 Services
      InternalName : svchost.exe
      LegalCopyright : © Microsoft Corporation. All rights reserved.
      OriginalFilename : svchost.exe

      #:8 [svchost.exe]
      FilePath : C:\WINDOWS\system32\
      ProcessID : 904
      ThreadCreationTime : 24-05-2007 18:24:40
      BasePriority : Normal
      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
      ProductVersion : 5.1.2600.2180
      ProductName : Microsoft® Windows® Operating System
      CompanyName : Microsoft Corporation
      FileDescription : Generic Host Process for Win32 Services
      InternalName : svchost.exe
      LegalCopyright : © Microsoft Corporation. All rights reserved.
      OriginalFilename : svchost.exe

      #:9 [svchost.exe]
      FilePath : C:\WINDOWS\System32\
      ProcessID : 988
      ThreadCreationTime : 24-05-2007 18:24:41
      BasePriority : Normal
      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
      ProductVersion : 5.1.2600.2180
      ProductName : Microsoft® Windows® Operating System
      CompanyName : Microsoft Corporation
      FileDescription : Generic Host Process for Win32 Services
      InternalName : svchost.exe
      LegalCopyright : © Microsoft Corporation. All rights reserved.
      OriginalFilename : svchost.exe

      #:10 [svchost.exe]
      FilePath : C:\WINDOWS\system32\
      ProcessID : 1052
      ThreadCreationTime : 24-05-2007 18:24:41
      BasePriority : Normal
      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
      ProductVersion : 5.1.2600.2180
      ProductName : Microsoft® Windows® Operating System
      CompanyName : Microsoft Corporation
      FileDescription : Generic Host Process for Win32 Services
      InternalName : svchost.exe
      LegalCopyright : © Microsoft Corporation. All rights reserved.
      OriginalFilename : svchost.exe

      #:11 [svchost.exe]
      FilePath : C:\WINDOWS\system32\
      ProcessID : 1176
      ThreadCreationTime : 24-05-2007 18:24:41
      BasePriority : Normal
      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
      ProductVersion : 5.1.2600.2180
      ProductName : Microsoft® Windows® Operating System
      CompanyName : Microsoft Corporation
      FileDescription : Generic Host Process for Win32 Services
      InternalName : svchost.exe
      LegalCopyright : © Microsoft Corporation. All rights reserved.
      OriginalFilename : svchost.exe

      #:12 [aswupdsv.exe]
      FilePath : C:\Program Files\Alwil Software\Avast4\
      ProcessID : 1308
      ThreadCreationTime : 24-05-2007 18:24:43
      BasePriority : Normal
      FileVersion : 4, 7, 997, 0
      ProductVersion : 4, 7, 0, 0
      ProductName : avast! Antivirus
      CompanyName : ALWIL Software
      FileDescription : avast! Antivirus updating service
      InternalName : aswUpdSv.exe
      LegalCopyright : Copyright (c) 2007 ALWIL Software
      OriginalFilename : aswUpdSv.exe

      #:13 [ati2evxx.exe]
      FilePath : C:\WINDOWS\system32\
      ProcessID : 1352
      ThreadCreationTime : 24-05-2007 18:24:44
      BasePriority : Normal
      FileVersion : 6.14.10.4112
      ProductVersion : 6.14.10.4112.02
      ProductName : ATI External Event Utility for WindowsNT and Windows9X
      CompanyName : ATI Technologies Inc.
      FileDescription : ATI External Event Utility EXE Module
      InternalName : ATI2EVXX.EXE
      LegalCopyright : Copyright © 1999-2004 ATI Technologies Inc.
      OriginalFilename : ATI2EVXX.EXE

      #:14 [explorer.exe]
      FilePath : C:\WINDOWS\
      ProcessID : 1400
      ThreadCreationTime : 24-05-2007 18:24:44
      BasePriority : Normal
      FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
      ProductVersion : 6.00.2900.2180
      ProductName : Système d'exploitation Microsoft® Windows®
      CompanyName : Microsoft Corporation
      FileDescription : Explorateur Windows
      InternalName : explorer
      LegalCopyright : © Microsoft Corporation. Tous droits réservés.
      OriginalFilename : EXPLORER.EXE

      #:15 [ashserv.exe]
      FilePath : C:\Program Files\Alwil Software\Avast4\
      ProcessID : 1472
      ThreadCreationTime : 24-05-2007 18:24:44
      BasePriority : High
      FileVersion : 4, 7, 997, 0
      ProductVersion : 4, 7, 0, 0
      ProductName : avast! Antivirus
      CompanyName : ALWIL Software
      FileDescription : avast! antivirus service
      InternalName : aswServ
      LegalCopyright : Copyright (c) 2007 ALWIL Software
      OriginalFilename : aswServ.exe

      #:16 [ehtray.exe]
      FilePath : C:\WINDOWS\ehome\
      ProcessID : 1636
      ThreadCreationTime : 24-05-2007 18:24:49
      BasePriority : Normal
      FileVersion : 5.1.2700.2180 (private/xpsp_mce.040810-0205)
      ProductVersion : 5.1.2700.2180
      ProductName : Microsoft® Windows® Operating System
      CompanyName : Microsoft Corporation
      FileDescription : Media Center Tray Applet
      InternalName : ehtray
      LegalCopyright : © Microsoft Corporation. All rights reserved.
      OriginalFilename : ehtray.exe

      #:17 [jusched.exe]
      FilePath : C:\Program Files\Java\jre1.5.0_06\bin\
      ProcessID : 1644
      ThreadCreationTime : 24-05-2007 18:24:49
      BasePriority : Normal

      #:18 [hpsysdrv.exe]
      FilePath : C:\windows\system\
      ProcessID : 1656
      ThreadCreationTime : 24-05-2007 18:24:49
      BasePriority : Normal
      FileVersion : 1, 7, 0, 0
      ProductVersion : 1, 7, 0, 0
      ProductName : hpsysdrv
      CompanyName : Hewlett-Packard Company
      FileDescription : hpsysdrv
      InternalName : hpsysdrv
      LegalCopyright : Copyright © 1998
      OriginalFilename : hpsysdrv.exe

      #:19 [hphmon06.exe]
      FilePath : C:\WINDOWS\system32\
      ProcessID : 1692
      ThreadCreationTime : 24-05-2007 18:24:49
      BasePriority : Normal
      FileVersion : 6,0,72
      ProductVersion : 6,0,72
      ProductName : HP Photosmart
      CompanyName : Hewlett-Packard
      FileDescription : HPHmon06
      InternalName : HPHmon06
      LegalCopyright : Copyright (C) 2004
      OriginalFilename : HPHmon06.exe

      #:20 [kbd.exe]
      FilePath : C:\HP\KBD\
      ProcessID : 1700
      ThreadCreationTime : 24-05-2007 18:24:49
      BasePriority : High

      #:21 [atiptaxx.exe]
      FilePath : C:\Program Files\ATI Technologies\ATI Control Panel\
      ProcessID : 1716
      ThreadCreationTime : 24-05-2007 18:24:49
      BasePriority : Normal
      FileVersion : 6.14.10.5140
      ProductVersion : 6.14.10.5140
      ProductName : ATI Desktop Component
      CompanyName : ATI Technologies, Inc.
      FileDescription : ATI Desktop Control Panel
      InternalName : Atiptaxx.exe
      LegalCopyright : Copyright (C) 1998-2005 ATI Technologies Inc.
      OriginalFilename : Atiptaxx.exe

      #:22 [alcxmntr.exe]
      FilePath : C:\WINDOWS\
      ProcessID : 1724
      ThreadCreationTime : 24-05-2007 18:24:49
      BasePriority : Normal
      FileVersion : 1.5
      ProductVersion : 1.5
      ProductName : Realtek Audio - Event Monitor
      CompanyName : Realtek Semiconductor Corp.
      FileDescription : Realtek Audio - Event Monitor
      InternalName : Alcxmntr
      LegalCopyright : Copyright (c) 2004 Realtek Semiconductor Corp.
      OriginalFilename : Alcxmntr.exe

      #:23 [ashdisp.exe]
      FilePath : C:\PROGRA~1\ALWILS~1\Avast4\
      ProcessID : 1748
      ThreadCreationTime : 24-05-2007 18:24:49
      BasePriority : Normal
      FileVersion : 4, 7, 997, 0
      ProductVersion : 4, 7, 0, 0
      ProductName : avast! Antivirus
      CompanyName : ALWIL Software
      FileDescription : avast! service GUI component
      InternalName : aswDisp
      LegalCopyright : Copyright (c) 2007 ALWIL Software
      OriginalFilename : aswDisp.exe

      #:24 [ssaad.exe]
      FilePath : C:\PROGRA~1\Sony\SONICS~1\
      ProcessID : 1764
      ThreadCreationTime : 24-05-2007 18:24:50
      BasePriority : Normal
      FileVersion : 3.4.01.13062
      FileDescription : SonicStage Atrac Hard Disk Monitor
      InternalName : SonicStage Atrac Hard Disk Monitor
      LegalCopyright : Copyright 2005 Sony Corporation

      #:25 [issch.exe]
      FilePath : C:\Program Files\Fichiers communs\InstallShield\UpdateService\
      ProcessID : 1796
      ThreadCreationTime : 24-05-2007 18:24:50
      BasePriority : Normal
      FileVersion : 4, 60, 100, 37068
      ProductVersion : 4, 60
      ProductName : InstallShield Update Service
      CompanyName : Macrovision Corporation
      FileDescription : InstallShield Update Service Scheduler
      InternalName : Scheduler
      LegalCopyright : Copyright (C) 2005 Macrovision Corporation
      OriginalFilename : issch.exe

      #:26 [vvx1000.exe]
      FilePath : C:\WINDOWS\
      ProcessID : 1820
      ThreadCreationTime : 24-05-2007 18:24:50
      BasePriority : Normal

      #:27 [ituneshelper.exe]
      FilePath : C:\Program Files\iTunes\
      ProcessID : 1880
      ThreadCreationTime : 24-05-2007 18:24:51
      BasePriority : Normal
      FileVersion : 7.0.2.16
      ProductVersion : 7.0.2.16
      ProductName : iTunes
      CompanyName : Apple Computer, Inc.
      FileDescription : iTunesHelper Module
      InternalName : iTunesHelper
      LegalCopyright : © 2003-2006 Apple Computer, Inc. All Rights Reserved.
      OriginalFilename : iTunesHelper.exe

      #:28 [winampa.exe]
      FilePath : C:\Program Files\Winamp\
      ProcessID : 1960
      ThreadCreationTime : 24-05-2007 18:24:51
      BasePriority : Normal

      #:29 [spoolsv.exe]
      FilePath : C:\WINDOWS\system32\
      ProcessID : 224
      ThreadCreationTime : 24-05-2007 18:24:54
      BasePriority : Normal
      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
      ProductVersion : 5.1.2600.2180
      ProductName : Microsoft® Windows® Operating System
      CompanyName : Microsoft Corporation
      FileDescription : Spooler SubSystem App
      InternalName : spoolsv.exe
      LegalCopyright : © Microsoft Corporation. All rights reserved.
      OriginalFilename : spoolsv.exe

      #:30 [realsched.exe]
      FilePath : C:\Program Files\Fichiers communs\Real\Update_OB\
      ProcessID : 436
      ThreadCreationTime : 24-05-2007 18:24:58
      BasePriority : Normal
      FileVersion : 0.1.0.3760
      ProductVersion : 0.1.0.3760
      ProductName : RealPlayer (32-bit)
      CompanyName : RealNetworks, Inc.
      FileDescription : RealNetworks Scheduler
      InternalName : schedapp
      LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004
      LegalTrademarks : RealAudio(tm) is a trademark of RealNetworks, Inc.
      OriginalFilename : realsched.exe

      #:31 [msnmsgr.exe]
      FilePath : C:\Program Files\MSN Messenger\
      ProcessID : 1140
      ThreadCreationTime : 24-05-2007 18:25:03
      BasePriority : Normal
      FileVersion : 8.1.0178.00
      ProductVersion : 8.1.0178
      ProductName : Messenger
      CompanyName : Microsoft Corporation
      FileDescription : Messenger
      InternalName : msnmsgr.exe
      LegalCopyright : Copyright (c) Microsoft Corporation. All rights reserved.
      OriginalFilename : msnmsgr.exe

      #:32 [skype.exe]
      FilePath : C:\Program Files\Skype\Phone\
      ProcessID : 1192
      ThreadCreationTime : 24-05-2007 18:25:06
      BasePriority : Normal
      FileVersion : 3.2.0.148
      ProductVersion : 3.2
      ProductName : Skype
      CompanyName : Skype Technologies S.A.
      FileDescription : Skype. Take a deep breath
      InternalName : Skype.exe
      LegalCopyright : (c) Skype Technologies S.A.
      OriginalFilename : Skype.exe

      #:33 [googletoolbarnotifier.exe]
      FilePath : C:\Program Files\Google\GoogleToolbarNotifier\
      ProcessID : 712
      ThreadCreationTime : 24-05-2007 18:25:09
      BasePriority : Normal
      FileVersion : 2, 0, 301, 1654
      ProductVersion : 2, 0, 301, 1654
      ProductName : GoogleToolbarNotifier
      CompanyName : Google Inc.
      FileDescription : GoogleToolbarNotifier
      LegalCopyright : Copyright © 2005-2007
      OriginalFilename : GoogleToolbarNotifier.exe

      #:34 [hpqtra08.exe]
      FilePath : C:\Program Files\HP\Digital Imaging\bin\
      ProcessID : 1536
      ThreadCreationTime : 24-05-2007 18:25:15
      BasePriority : Normal
      FileVersion : 45.4.157.000
      ProductVersion : 045.004.157.000
      ProductName : hp digital imaging - hp all-in-one series
      CompanyName : Hewlett-Packard Co.
      FileDescription : HP Digital Imaging Monitor
      InternalName : HPQTRA00
      LegalCopyright : Copyright (C) Hewlett-Packard Co. 1995-2004
      OriginalFilename : HPQTRA00.EXE
      Comments : HP Digital Imaging Monitor

      #:35 [ehrecvr.exe]
      FilePath : C:\WINDOWS\eHome\
      ProcessID : 940
      ThreadCreationTime : 24-05-2007 18:25:16
      BasePriority : Above Normal
      FileVersion : 5.1.2700.2230 built by: private/xpsp_mce_qfe(wmbla)
      ProductVersion : 5.1.2700.2230
      ProductName : Microsoft® Windows® Operating System
      CompanyName : Microsoft Corporation
      FileDescription : Media Center Receiver Service
      InternalName : ehRecvr
      LegalCopyright : © Microsoft Corporation. All rights reserved.
      OriginalFilename : ehRecvr.exe

      #:36 [ehsched.exe]
      FilePath : C:\WINDOWS\eHome\
      ProcessID : 1772
      ThreadCreationTime : 24-05-2007 18:25:18
      BasePriority : Normal
      FileVersion : 5.1.2700.2180 (private/xpsp_mce.040810-0205)
      ProductVersion : 5.1.2700.2180
      ProductName : Microsoft® Windows® Operating System
      CompanyName : Microsoft Corporation
      FileDescription : Media Center Scheduler Service
      InternalName : ehSched
      LegalCopyright : © Microsoft Corporation. Tous droits réservés.
      OriginalFilename : ehSched.exe

      #:37 [hpzipm12.exe]
      FilePath : C:\WINDOWS\system32\
      ProcessID : 2080
      ThreadCreationTime : 24-05-2007 18:25:22
      BasePriority : Normal
      FileVersion : 9, 0, 0, 0
      ProductVersion : 9, 0, 0, 0
      ProductName : HP PML
      CompanyName : HP
      FileDescription : PML Driver
      InternalName : PmlDrv
      LegalCopyright : Copyright © 1998, 1999 Hewlett-Packard Company
      OriginalFilename : PmlDrv.exe

      #:38 [wkcalrem.exe]
      FilePath : C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\
      ProcessID : 2112
      ThreadCreationTime : 24-05-2007 18:25:23
      BasePriority : Normal
      FileVersion : 8.04.0623.0
      ProductVersion : 8.04.0623.0
      ProductName : Microsoft® Works 8
      CompanyName : Microsoft® Corporation
      FileDescription : Microsoft® Works Calendar Reminder Service
      InternalName : WkCalRem
      LegalCopyright : Copyright © Microsoft Corporation. All rights reserved.
      OriginalFilename : WKCALREM.EXE

      #:39 [svchost.exe]
      FilePath : C:\WINDOWS\system32\
      ProcessID : 2140
      ThreadCreationTime : 24-05-2007 18:25:25
      BasePriority : Normal
      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
      ProductVersion : 5.1.2600.2180
      ProductName : Microsoft® Windows® Operating System
      CompanyName : Microsoft Corporation
      FileDescription : Generic Host Process for Win32 Services
      InternalName : svchost.exe
      LegalCopyright : © Microsoft Corporation. All rights reserved.
      OriginalFilename : svchost.exe

      #:40 [skypepm.exe]
      FilePath : C:\Program Files\Skype\Plugin Manager\
      ProcessID : 2704
      ThreadCreationTime : 24-05-2007 18:26:04
      BasePriority : Normal
      FileVersion : 1.2.0.255
      ProductVersion : 1.0.0.0
      CompanyName : Skype Technologies
      FileDescription : Skype Extras Manager
      LegalCopyright : Skype Limited

      #:41 [ashmaisv.exe]
      FilePath : C:\Program Files\Alwil Software\Avast4\
      ProcessID : 3140
      ThreadCreationTime : 24-05-2007 18:26:36
      BasePriority : Normal

      #:42 [ashwebsv.exe]
      FilePath : C:\Program Files\Alwil Software\Avast4\
      ProcessID : 3296
      ThreadCreationTime : 24-05-2007 18:26:37
      BasePriority : Normal

      #:43 [ipodservice.exe]
      FilePath : C:\Program Files\iPod\bin\
      ProcessID : 3420
      ThreadCreationTime : 24-05-2007 18:26:38
      BasePriority : Normal
      FileVersion : 7.0.2.16
      ProductVersion : 7.0.2.16
      ProductName : iTunes
      CompanyName : Apple Computer, Inc.
      FileDescription : iPodService Module
      InternalName : iPodService
      LegalCopyright : © 2003-2006 Apple Computer, Inc. All Rights Reserved.
      OriginalFilename : iPodService.exe

      #:44 [servicelayer.exe]
      FilePath : C:\Program Files\PC Connectivity Solution\
      ProcessID : 3784
      ThreadCreationTime : 24-05-2007 18:26:41
      BasePriority : Normal
      FileVersion : 6, 83, 78, 3
      ProductVersion : 3.1
      ProductName : PC Connectivity Solution
      CompanyName : Nokia.
      FileDescription : ServiceLayer Module
      InternalName : ServiceLayer
      LegalCopyright : Copyright © 2002-2007 Nokia. All Rights Reserved.
      OriginalFilename : ServiceLayer.exe

      #:45 [dllhost.exe]
      FilePath : C:\WINDOWS\system32\
      ProcessID : 3924
      ThreadCreationTime : 24-05-2007 18:26:43
      BasePriority : Normal
      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
      ProductVersion : 5.1.2600.2180
      ProductName : Microsoft® Windows® Operating System
      CompanyName : Microsoft Corporation
      FileDescription : COM Surrogate
      InternalName : dllhost.exe
      LegalCopyright : © Microsoft Corporation. All rights reserved.
      OriginalFilename : dllhost.exe

      #:46 [alg.exe]
      FilePath : C:\WINDOWS\System32\
      ProcessID : 1288
      ThreadCreationTime : 24-05-2007 18:26:49
      BasePriority : Normal
      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
      ProductVersion : 5.1.2600.2180
      ProductName : Microsoft® Windows® Operating System
      CompanyName : Microsoft Corporation
      FileDescription : Application Layer Gateway Service
      InternalName : ALG.exe
      LegalCopyright : © Microsoft Corporation. All rights reserved.
      OriginalFilename : ALG.exe

      #:47 [svchost.exe]
      FilePath : C:\WINDOWS\System32\
      ProcessID : 3496
      ThreadCreationTime : 24-05-2007 18:27:00
      BasePriority : Normal
      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
      ProductVersion : 5.1.2600.2180
      ProductName : Microsoft® Windows® Operating System
      CompanyName : Microsoft Corporation
      FileDescription : Generic Host Process for Win32 Services
      InternalName : svchost.exe
      LegalCopyright : © Microsoft Corporation. All rights reserved.
      OriginalFilename : svchost.exe

      #:48 [ehmsas.exe]
      FilePath : C:\WINDOWS\eHome\
      ProcessID : 3580
      ThreadCreationTime : 24-05-2007 18:27:01
      BasePriority : Normal
      FileVersion : 5.1.2700.2180 (private/xpsp_mce.040810-0205)
      ProductVersion : 5.1.2700.2180
      ProductName : Microsoft® Windows® Operating System
      CompanyName : Microsoft Corporation
      FileDescription : Media Center Media Status Aggregator Service
      InternalName : eHMSAS
      LegalCopyright : © Microsoft Corporation. All rights reserved.
      OriginalFilename : ehMSAS.exe

      #:49 [livecall.exe]
      FilePath : C:\Program Files\MSN Messenger\
      ProcessID : 3812
      ThreadCreationTime : 24-05-2007 18:27:15
      BasePriority : Normal
      FileVersion : 1.1.161.0
      ProductVersion : 1.1.161.0
      ProductName : Windows Live Call
      CompanyName : Microsoft Corporation
      FileDescription : Windows Live Call
      InternalName : livecall
      LegalCopyright : Copyright © 2006 Microsoft Corporation. All rights reserved.
      OriginalFilename : livecall.exe

      #:50 [usnsvc.exe]
      FilePath : C:\Program Files\MSN Messenger\
      ProcessID : 2284
      ThreadCreationTime : 24-05-2007 18:27:28
      BasePriority : Normal
      FileVersion : 8.1.0178.00
      ProductVersion : 8.1.0178
      ProductName : Messenger
      CompanyName : Microsoft Corporation
      FileDescription : Messenger Sharing USN Journal Reader Service
      InternalName : usnsvc.exe
      LegalCopyright : Copyright (c) Microsoft Corporation. All rights reserved.
      OriginalFilename : usnsvc.exe

      #:51 [wuauclt.exe]
      FilePath : C:\WINDOWS\system32\
      ProcessID : 3120
      ThreadCreationTime : 24-05-2007 21:12:39
      BasePriority : Normal
      FileVersion : 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158)
      ProductVersion : 5.4.3790.2180
      ProductName : Système d'exploitation Microsoft® Windows®
      CompanyName : Microsoft Corporation
      FileDescription : Mises à jour automatiques
      InternalName : wuauclt.exe
      LegalCopyright : © Microsoft Corporation. Tous droits réservés.
      OriginalFilename : wuauclt.exe

      #:52 [ad-aware.exe]
      FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
      ProcessID : 300
      ThreadCreationTime : 24-05-2007 21:13:56
      BasePriority : Normal
      FileVersion : 6.2.0.236
      ProductVersion : SE 106
      ProductName : Lavasoft Ad-Aware SE
      CompanyName : Lavasoft Sweden
      FileDescription : Ad-Aware SE Core application
      InternalName : Ad-Aware.exe
      LegalCopyright : Copyright © Lavasoft AB Sweden
      OriginalFilename : Ad-Aware.exe
      Comments : All Rights Reserved

      Memory scan result:
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
      New critical objects: 0
      Objects found so far: 0

      Started registry scan
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

      Registry Scan result:
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
      New critical objects: 0
      Objects found so far: 0

      Started deep registry scan
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

      Deep registry scan result:
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
      New critical objects: 0
      Objects found so far: 0

      Started Tracking Cookie scan
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

      Tracking Cookie Object Recognized!
      Type : IECache Entry
      Data : hp_administrateur@247realmedia[1].txt
      TAC Rating : 3
      Category : Data Miner
      Comment : Hits:1
      Value : Cookie:hp_administrateur@247realmedia.com/
      Expires : 01-01-2021 02:00:00
      LastSync : Hits:1
      UseCount : 0
      Hits : 1

      Tracking cookie scan result:
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
      New critical objects: 1
      Objects found so far: 1

      Deep scanning and examining files...
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

      Disk Scan Result for C:\WINDOWS
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
      New critical objects: 0
      Objects found so far: 1

      Disk Scan Result for C:\WINDOWS\system32
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
      New critical objects: 0
      Objects found so far: 1

      Disk Scan Result for C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
      New critical objects: 0
      Objects found so far: 1

      Scanning Hosts file......
      Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

      Hosts file scan result:
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
      1 entries scanned.
      New critical objects:0
      Objects found so far: 1

      MRU List Object Recognized!
      Location: : C:\Documents and Settings\HP_Administrateur\recent
      Description : list of recently opened documents

      MRU List Object Recognized!
      Location: : software\microsoft\direct3d\mostrecentapplication
      Description : most recent application to use microsoft direct3d

      MRU List Object Recognized!
      Location: : software\microsoft\direct3d\mostrecentapplication
      Description : most recent application to use microsoft direct X

      MRU List Object Recognized!
      Location: : software\microsoft\directdraw\mostrecentapplication
      Description : most recent application to use microsoft directdraw

      MRU List Object Recognized!
      Location: : S-1-5-21-2527806190-2901631867-3522775852-1007\software\microsoft\internet explorer
      Description : last download directory used in microsoft internet explorer

      MRU List Object Recognized!
      Location: : S-1-5-21-2527806190-2901631867-3522775852-1007\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
      Description : list of recent programs opened

      MRU List Object Recognized!
      Location: : S-1-5-21-2527806190-2901631867-3522775852-1007\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
      Description : list of recently saved files, stored according to file extension

      MRU List Object Recognized!
      Location: : S-1-5-21-2527806190-2901631867-3522775852-1007\software\microsoft\windows\currentversion\explorer\recentdocs
      Description : list of recent documents opened

      MRU List Object Recognized!
      Location: : S-1-5-21-2527806190-2901631867-3522775852-1007\software\realnetworks\realplayer\6.0\preferences
      Description : list of recent skins in realplayer

      MRU List Object Recognized!
      Location: : S-1-5-21-2527806190-2901631867-3522775852-1007\software\microsoft\windows media\wmsdk\general
      Description : windows media sdk

      Performing conditional scans...
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

      Conditional scan result:
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
      New critical objects: 0
      Objects found so far: 11

      23:16:43 Scan Complete

      Summary Of This Scan
      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
      Total scanning time:00:02:33.718
      Objects scanned:116748
      Objects identified:1
      Objects ignored:0
      New critical objects:1
      0
      1. rapport hijackthis

        Logfile of Trend Micro HijackThis v2.0.0 (BETA)
        Scan saved at 23:44:58, on 24/05/2007
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\ehome\ehtray.exe
        C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
        C:\windows\system\hpsysdrv.exe
        C:\WINDOWS\system32\hphmon06.exe
        C:\HP\KBD\KBD.EXE
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\WINDOWS\ALCXMNTR.EXE
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
        C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
        C:\WINDOWS\vVX1000.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Winamp\winampa.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\MSN Messenger\msnmsgr.exe
        C:\Program Files\Skype\Phone\Skype.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\WINDOWS\eHome\ehRecvr.exe
        C:\WINDOWS\eHome\ehSched.exe
        C:\WINDOWS\system32\HPZipm12.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Skype\Plugin Manager\skypePM.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
        C:\WINDOWS\system32\dllhost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\eHome\ehmsas.exe
        C:\Program Files\MSN Messenger\livecall.exe
        C:\Program Files\MSN Messenger\usnsvc.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Documents and Settings\HP_Administrateur\Bureau\HiJackThis_v2.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?gws_rd=ssl
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.avast.com/registration-free-antivirus?lang=FRE
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
        O3 - Toolbar: (no name) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - (no file)
        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
        O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
        O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
        O4 - HKLM\..\Run: [HPHUPD06] "c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe"
        O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
        O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
        O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
        O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
        O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
        O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
        O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
        O4 - HKLM\..\Run: [PCSuiteTrayApplication] "C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" -startup
        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
        O4 - HKCU\..\Run: [L07FXLRD_932578] "C:\Program Files\Microsoft Etudes\Microsoft Encarta 2007 - Études DVD\EDICT.EXE" -m
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
        O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
        O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Startup: wkcalrem.LNK = C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
        O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
        O4 - Global Startup: Ask Harrap's Shorter.lnk = ?
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O4 - Global Startup: RaConfig2500.lnk = C:\Program Files\RALINK\RT2500 USB Wireless LAN Card\Installer\WINXP\RaConfig2500.exe
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
        O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
        O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
        O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
        O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
        O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
        O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
        O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
        O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
        O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
        O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone (HKLM)
        O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone (HKLM)
        O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone (HKLM)
        O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
        O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone (HKLM)
        O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
        O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
        O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
        O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
        O23 - Service: Service de planification Media Center (ehSched) - Unknown owner - C:\WINDOWS\eHome\ehSched.exe
        O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
        O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
        O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
        O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
        O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
        O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
        O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
        O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
        O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
        O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
        O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
        O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
        O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
        O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
        0
        1. ok donc maintenant fait ceci et colle ton rapport dans ta prochaine reponse

          Fais un clic droit sur ce lien :
          http://perso.orange.fr/il.mafioso/Navifix/Navilog1.zip
          Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
          Fais un clic droit sur navilog1.zip et choisis "tout extraire"
          Ensuite double clique sur navilog1.exe pour lancer l'installation.
          Une fois l'installation terminée, le fix s'exécutera automatiquement.
          (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

          Laisse-toi guider. Au menu principal, choisis 1 et valides.
          (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

          Patiente jusqu'au message :
          *** Analyse Termine le ..... ***
          Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
          Copie-colle l'intégralité dans une réponse. Referme le blocnote.
          Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
          --
          0
      2. voila le rapport
        Search Navipromo version 2.0.2 commencé le 25/05/2007 à 0:11:56.05

        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
        !!! Poster ce rapport sur le forum pour le faire analyser !!!
        !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

        Fix lancé depuis C:\Program Files\navilog1
        Mise a jour le 17.05.2007 a 23h00 by IL-MAFIOSO

        Executé en mode normal

        *** Recherche Programmes installes ***

        *** Recherche dossiers dans C:\WINDOWS ***

        *** Recherche dossiers dans C:\Program Files ***

        C:\Program Files\MessengerSkinner trouvé !

        *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

        *** Recherche dossiers dans C:\Documents and Settings\HP_Administrateur\Application Data ***

        ...\Application Data\MessengerSkinner trouvé !

        *** Recherche avec BlackLight Engine/F-secure ***
        BlackLight Engine est un produit de F-secure, pour + d'infos :
        https://www.f-secure.com/en

        Fichier(s) caché(s) dans C:\WINDOWS\system32 :

        c:\WINDOWS\system32\dvmnqtqx.dat
        C:\windows\system32\dvmnqtqx.exe
        c:\WINDOWS\system32\dvmnqtqx_nav.dat
        c:\WINDOWS\system32\dvmnqtqx_navps.dat

        Processus caché(s) dans C:\WINDOWS\system32 :

        C:\windows\system32\dvmnqtqx.exe

        *** Recherche fichiers ***

        C:\WINDOWS\pack.epk trouvé !

        *** Recherche cles registre ***

        Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]

        Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]

        Recherche Clé Magic Control

        HKEY_CURRENT_USER\Software\Lanconfig trouvé !
        HKEY_USERS\S-1-5-21-2527806190-2901631867-3522775852-1007\Software\Lanconfig trouvé !

        *** Module de Recherche complémentaire ***
        (Recherche fichiers spécifiques)

        1)Recherche fichiers connus:

        2)Recherche Heuristique :
        *
        C:\WINDOWS\system32\dvmnqtqx.dat trouvé !
        **
        C:\WINDOWS\system32\dvmnqtqx.dat trouvé !
        ***
        ****
        *****
        ******
        *******
        ********

        *** Analyse Terminé le 25/05/2007 à 0:19:53.80 ***
        0