Ordi lent au démarage

bonjour
je me permets de vous contactez pour que vous puissiez m'aider à résoudre un problème.
mon ordi est lent au démarage et il est aussi lent tout le tem qu'il est allumé, quand je suis internet il rame, de plus je recoi des pub qui ne servent a rien.
merci bcp de maider svp.
Configuration: Windows XP
Internet Explorer 7.0

30 réponses

Résumé de la discussion

Le problème central décrit est un ordinateur lent au démarrage et pendant l’utilisation, avec des pages internet qui rame et des publicités indésirables sous Windows XP et Internet Explorer 7. Les solutions proposées évoquent notamment un formatage du système avec sauvegarde des données et réinstallation, puis l’installation d’un antivirus et des outils de diagnostic pour détecter les éléments indésirables. D’autres conseils suggèrent l’utilisation d’outils spécialisés comme HijackThis et Navilog pour analyser les processus et les extensions clefs, puis partager un rapport pour identifier les programmes responsables. En cas de besoin, les rapports existent en version bêta et montrent des éléments tels que des suites de sécurité, des modules publicitaires et des services système à vérifier.

Bobot (l’IA à votre service)
  1. alors pour ton ordi jte conseil de télécharger le logiciel c cleaner qui nettoie toutes les traces qui occupe inutilement ton pc.
    Tu peu aussi supprimer le contenu de ton dossier prefecht (ossi des traces)
    tu va dans ton disque local, puis dans le dossier windows puis tu klik sur le dossier prefecht et tu supprime tous son contenue!!!
    jte donne le lien pour le logiciel
    https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
    @ plus tien moi o new stp
    0
    1. bonjour sanchez j
      quand tu fais Ctrl+Alt+Suppr
      que vois tu dans les performances ?
      Si c'est 100 % c'est sur tu as un logiciel espion, voir un ou des virus..
      Tiens nous au courant...
      0
      1. merci de me répondre aussi vite
        j'ai fais ce que vos mavez demander et ce n'est pas a 100% donc voila.
        merci.
        0
        1. ok
          défragmentes tes disk dur..
          et fais un nettoyage avec le lien de pierrot68100
          0
          1. telecharge ccleaner et fais le nettoyage .
            dans l'onglet outils/demarrage ne laisse que l'essentiel : antivirus , msn , wifi (si tu l'a)
            0
            1. bonjour j'ai des espiologiciel et des publiciel comment faire pour les enlever.
              merci
              0
              1. j'ai fais tout ce que vous mavez demander et quand jouvre un dossier sa rame un peu moin mai quand je sui sur le net il y a un message me disan que la perte e mon ordi est du a des espiologicel ou des publiciel.
                pouvez-vous maider svp.
                0
                1. ok, on va passer à la vitesse supèrieur...

                  Tu vas m'envoyer une rapport hijackthis..

                  le tuto en bas là :
                  http://www.tutopat.com/viewtopic.php?t=265

                  lien dernière Mise a jour :
                  https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/

                  et aussi un rapport Navilog :

                  télécharge sur le bureau
                  Navilog1.exe :http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
                  = double-clic dessus pour l'installer et le lancer
                  Quand installé
                  = taper F
                  = Appuyer sur une touche jusqu' arriver aux options
                  = Choisir option 1 ( = taper 1 )
                  ne pas utiliser les autres sans avis , il peut y avoir des processus légitimes

                  un rapport : fixnavi.txt
                  dans ==> C :
                  le copier/coller dans la réponse

                  Télécharge sur ton bureau Clean (zip) :http://www.malekal.com/download/clean.zip
                  = Clic droit sur Clean.zip et Extraire ici ( ou extraire sans confirmation ou tout ou unzip)
                  =double-clic Dossier Clean
                  = double-clic Clean. ( avec comme symbole une roue dentée)
                  = Option 1 = taper 1
                  = copier/coller le rapport dans la réponse

                  On résume, 2 rapports, 1 hijack+ 1Navilog merci !

                  Il n'y a pas de femmes frigides. Il n'y a que de mauvaises langues.
                  [Coluche]
                  0
                  1. voila le rapor
                    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                    Scan saved at 17:06:04, on 13/09/2007
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\WINDOWS\SOUNDMAN.EXE
                    C:\WINDOWS\ALCWZRD.EXE
                    C:\WINDOWS\system32\LEXBCES.EXE
                    C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
                    C:\WINDOWS\system32\LEXPPS.EXE
                    C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Apps\Powercinema\PCMService.exe
                    C:\apps\ABoard\ABoard.exe
                    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
                    C:\apps\ABoard\AOSD.exe
                    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
                    C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                    C:\Program Files\Analog Devices\Core\smax4pnp.exe
                    C:\Program Files\QuickTime\qttask.exe
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\WINDOWS\vsnp2std.exe
                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    C:\Program Files\MSN Messenger\MsnMsgr.Exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\DAEMON Tools\daemon.exe
                    c:\progra~1\intern~1\iexplore.exe
                    C:\Program Files\DialMessenger\dialmessenger.exe
                    C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                    C:\WINDOWS\System32\FTRTSVC.exe
                    C:\Program Files\Hercules\WiFi Station pour Livebox\WifiStationLB.exe
                    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                    C:\WINDOWS\system32\slserv.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\PROGRA~1\Wanadoo\ComComp.exe
                    C:\PROGRA~1\Wanadoo\Toaster.exe
                    C:\PROGRA~1\Wanadoo\Inactivity.exe
                    C:\PROGRA~1\Wanadoo\PollingModule.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                    C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    C:\Program Files\iPod\bin\iPodService.exe
                    C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                    C:\PROGRA~1\Wanadoo\Watch.exe
                    C:\Program Files\MSN Messenger\usnsvc.exe
                    C:\Program Files\eMule\emule.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\Documents and Settings\sanchez justin\Bureau\HiJackThis_v2.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://french.icrfast.com/index.php?rvs=hompag
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.packardbell.com/pb/fr/FR/content/home
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                    O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                    O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
                    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                    O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
                    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                    O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Fichiers communs\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"
                    O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
                    O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
                    O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
                    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                    O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
                    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
                    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                    O4 - HKLM\..\Run: [Hide 4 Mp3 Dvd] C:\Documents and Settings\All Users\Application Data\Cool bolt hide 4\Iso Fork.exe
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                    O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    O4 - HKLM\..\Run: [hldivjvprk] c:\windows\system32\hldivjvprk.exe hldivjvprk
                    O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                    O4 - HKCU\..\Run: [messengerskinner] C:\Documents and Settings\sanchez justin\Bureau\MessengerSkinner\MessengerSkinner.exe
                    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                    O4 - HKCU\..\Run: [Math type] C:\DOCUME~1\SANCHE~1\APPLIC~1\SENDBI~1\ford flaw extra.exe
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
                    O4 - HKCU\..\Run: [DialMessenger] "C:\Program Files\DialMessenger\dialmessenger.exe" -background
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O4 - Global Startup: WiFi Station pour Livebox.lnk = ?
                    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                    O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.09\AMVConverter\grab.html
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                    O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.09\MediaManager\grab.html
                    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                    O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
                    O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                    O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                    O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
                    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                    O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
                    O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
                    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
                    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                    O23 - Service: MysqlInventime - Unknown owner - c:\mysql\bin\mysqld-nt.exe
                    O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                    O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
                    O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
                    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                    O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
                    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                    O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
                    O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
                    O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
                    0
                    1. ok, n'oublis pas Navilog !

                      Ensuite suite à ton rapport..
                      Tu as installé 2 anti-virus AVAST+NOrton !
                      Désinstalle AVAST
                      le tuto ici :
                      Pour suppimer Avast
                      https://www.avast.com/fr-fr/uninstall-utility
                      j'aime mieux ce tuto
                      http://tutopat.hostonet.org/viewtopic.php?t=2417

                      ensuite tu vas suivre ces conseils :

                      relance hijack this
                      Scan only
                      sur ta gauche, tu vas cocher les cases qui ressembles à celles là :

                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                      O4 - HKCU\..\Run: [messengerskinner] C:\Documents and Settings\sanchez justin\Bureau\MessengerSkinner\MessengerSkinner.exe
                      O4 - HKCU\..\Run: [Math type] C:\DOCUME~1\SANCHE~1\APPLIC~1\SENDBI~1\ford flaw extra.exe
                      O4 - HKCU\..\Run: [DialMessenger] "C:\Program Files\DialMessenger\dialmessenger.exe" -background
                      O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                      O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe

                      Clic sur Fix checked

                      refait un hijack, c'est pas fini...

                      0
                      1. voila le rappor navilog
                        Search Navipromo version 3.0.2 commencé le 13/09/2007 à 17:54:48,20

                        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                        !!! Poster ce rapport sur le forum pour le faire analyser !!!
                        !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

                        Fix lancé depuis C:\Program Files\navilog1
                        Mise a jour le 12.09.2007 a 15h00 by IL-MAFIOSO

                        Microsoft Windows XP [version 5.1.2600]
                        Internet Explorer : 7.0.5730.11

                        *** Recherche Programmes installes ***

                        MessengerSkinner

                        *** Recherche dossiers dans C:\WINDOWS ***

                        *** Recherche dossiers dans C:\Program Files ***

                        C:\Program Files\MessengerSkinner trouvé !

                        *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

                        *** Recherche dossiers dans C:\Documents and Settings\sanchez justin\Application Data ***

                        ...\Application Data\MessengerSkinner trouvé !

                        *** Recherche avec BlackLight Engine/F-secure ***
                        BlackLight Engine est un produit de F-secure, pour + d'infos :
                        https://www.f-secure.com/en

                        Fichier(s) caché(s) dans C:\WINDOWS\system32 :

                        c:\WINDOWS\system32\hldivjvprk.dat
                        c:\windows\system32\hldivjvprk.exe
                        c:\WINDOWS\system32\hldivjvprk_nav.dat
                        c:\WINDOWS\system32\hldivjvprk_navps.dat

                        Processus caché(s) dans C:\WINDOWS\system32 :

                        c:\windows\system32\hldivjvprk.exe

                        *** Recherche avec GenericNaviSearch ***
                        !!! Tous Ces résultats peuvent révéler des fichiers légitimes !!!
                        !!! A verifier impérativement avant toute suppression manuelle !!!

                        * Scan C:\WINDOWS\system32 *

                        Fichiers trouvés :

                        Aucun Fichier trouvé !

                        Fichiers suspects :

                        Aucun Fichier suspect trouvé !

                        *** Recherche fichiers ***

                        C:\WINDOWS\pack.epk trouvé !
                        C:\WINDOWS\system32\nvs2.inf trouvé !

                        *** Recherche cles registre ***

                        HKEY_CURRENT_USER\Software\Lanconfig trouvé !

                        *** Module de Recherche complémentaire ***
                        (Recherche fichiers spécifiques)

                        1)Recherche fichiers connus:

                        2)Recherche Heuristique :

                        C:\WINDOWS\system32\hldivjvprk.dat trouvé !
                        C:\WINDOWS\system32\mgqittg.dat trouvé !
                        C:\WINDOWS\system32\quauelmvbg.dat trouvé !
                        C:\WINDOWS\system32\hldivjvprk_navps.dat trouvé !
                        C:\WINDOWS\system32\mgqittg_navps.dat trouvé !
                        C:\WINDOWS\system32\mgqittg_navup.dat trouvé !

                        3)Recherche Certificats :

                        Certificat Egroup trouvé !

                        *** Analyse Terminé le 13/09/2007 à 18:03:51,81 ***
                        0
                        1. voila le rappor de clean
                          13/09/2007 a 18:09:06,10

                          *** Recherche des fichiers dans C:

                          *** Recherche des fichiers dans C:\WINDOWS\

                          *** Recherche des fichiers dans C:\WINDOWS\system32
                          "C:\Documents and Settings\sanchez justin\Application Data\MessengerSkinner\" FOUND

                          *** Recherche des fichiers dans C:\Program Files
                          "C:\Program Files\Fichiers communs\WhenU\" FOUND
                          "C:\Program Files\Adverts\" FOUND
                          "C:\Program Files\Viewpoint\" FOUND
                          "C:\Program Files\MessengerSkinner\" FOUND
                          *** Fin du rapport !
                          0
                          1. voila le vouveau rappor de hijack
                            Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                            Scan saved at 18:29:34, on 13/09/2007
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            C:\WINDOWS\system32\LEXBCES.EXE
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\WINDOWS\system32\LEXPPS.EXE
                            C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                            C:\WINDOWS\System32\FTRTSVC.exe
                            C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                            C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                            C:\WINDOWS\system32\slserv.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\WINDOWS\SOUNDMAN.EXE
                            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                            C:\WINDOWS\ALCWZRD.EXE
                            C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                            C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                            C:\Apps\Powercinema\PCMService.exe
                            C:\apps\ABoard\ABoard.exe
                            C:\apps\ABoard\AOSD.exe
                            C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
                            C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
                            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                            C:\Program Files\Analog Devices\Core\smax4pnp.exe
                            C:\Program Files\QuickTime\qttask.exe
                            C:\Program Files\iTunes\iTunesHelper.exe
                            C:\WINDOWS\vsnp2std.exe
                            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
                            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                            C:\Program Files\MSN Messenger\MsnMsgr.Exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\DAEMON Tools\daemon.exe
                            C:\Program Files\Hercules\WiFi Station pour Livebox\WifiStationLB.exe
                            C:\Program Files\Internet Explorer\IEXPLORE.EXE
                            C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                            C:\PROGRA~1\Wanadoo\ComComp.exe
                            C:\PROGRA~1\Wanadoo\Toaster.exe
                            C:\PROGRA~1\Wanadoo\Inactivity.exe
                            C:\PROGRA~1\Wanadoo\PollingModule.exe
                            C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                            c:\progra~1\intern~1\iexplore.exe
                            C:\Program Files\iPod\bin\iPodService.exe
                            C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\PROGRA~1\Wanadoo\Watch.exe
                            C:\Program Files\MSN Messenger\usnsvc.exe
                            C:\Program Files\Alwil Software\Avast4\setup\avast.setup
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Messenger\msmsgs.exe
                            C:\Documents and Settings\sanchez justin\Bureau\HiJackThis_v2.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://french.icrfast.com/index.php?rvs=hompag
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.packardbell.com/pb/fr/FR/content/home
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                            R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                            O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                            O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                            O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                            O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                            O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                            O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                            O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                            O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
                            O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
                            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                            O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Fichiers communs\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"
                            O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
                            O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
                            O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                            O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
                            O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                            O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
                            O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                            O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
                            O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                            O4 - HKLM\..\Run: [Hide 4 Mp3 Dvd] C:\Documents and Settings\All Users\Application Data\Cool bolt hide 4\Iso Fork.exe
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                            O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
                            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
                            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                            O4 - Global Startup: WiFi Station pour Livebox.lnk = ?
                            O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                            O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.09\AMVConverter\grab.html
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                            O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.09\MediaManager\grab.html
                            O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                            O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                            O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
                            O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                            O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                            O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                            O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                            O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                            O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
                            O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
                            O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
                            O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                            O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                            O23 - Service: MysqlInventime - Unknown owner - c:\mysql\bin\mysqld-nt.exe
                            O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                            O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                            O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
                            O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
                            O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                            O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                            O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
                            O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                            O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                            O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                            O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
                            O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
                            O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
                            0
                            1. je voulais savoir si vous avez recu les rappor de navilog et de clean car depui taleur j'ai du redémarer mon ordi
                              voila.
                              0
                              1. ok, bien recu...
                                Pour hijack tu as toujours AVAST+NORton :

                                Tu as installé 2 anti-virus AVAST+NOrton !
                                Désinstalle AVAST
                                le tuto ici :
                                Pour suppimer Avast
                                https://www.avast.com/fr-fr/uninstall-utility
                                j'aime mieux ce tuto
                                http://tutopat.hostonet.org/viewtopic.php?t=2417

                                Ensuite pou Navilog démarres en mode sans échec..
                                et lance Navilog choisis l'option 2 cette fois ci !

                                colle le rapport navilog, et encore hijack merci...
                                0
                                1. Avira AntiVir PersonalEdition Classic
                                  *************************************

                                  Copyright © 2007 Avira GmbH.
                                  All rights reserved.

                                  Inhalt
                                  ******

                                  0 Important information
                                  1 System requirements
                                  2 Important requirements for an installation
                                  3 Incompatibilities with other programs
                                  4 Support service
                                  5 Contact address

                                  0 Important information
                                  ***********************

                                  Users who have up to now installed an ANSI version of the Avira
                                  AntiVir PersonalEdition Classic software pack on a Microsoft Windows
                                  NT, Microsoft Windows 2000 or Microsoft Windows XP operating system,
                                  receive update information when attempting to update.

                                  When updating, please proceed as follows:

                                  1. Deinstall the installed version of the Avira AntiVir
                                  PersonalEdition Classic.
                                  2. Download a current software pack from the downoad section of the
                                  Avira AntiVir PersonalEdition Classic website
                                  https://www.avira.com/
                                  3. Install this software pack on your computer.

                                  1 System requirements
                                  *********************

                                  In order for Avira AntiVir PersonalEdition Classic to run properly,
                                  the computer system must fulfill the following requirements:

                                  - Computer: Pentium or higher, at least 133 MHz

                                  - Operating system
                                  - Microsoft Windows Vista or
                                  - Microsoft Windows XP Home or Professional, or
                                  - Microsoft Windows 2000, SP 4 recommended

                                  Avira AntiVir PersonalEdition Classic also supports Microsoft Windows
                                  XP x64 Edition.

                                  The display of the program interfaces can differ, depending on the
                                  operating system used.

                                  - 30 MB free memory on the hard disk (more if quarantine is used)

                                  - Min. 100 MB temporary memory on the hard disk

                                  - Min. 25 MB of free main memory

                                  - For all installations: Internet Explorer 5.0 or higher

                                  - For the installation of Avira AntiVir PersonalEdition Classic:
                                  administrator rights

                                  Note
                                  ----

                                  - If there is no Internet Explorer 5.0 or higher available on your
                                  system, you can download it under the following address:

                                  https://support.microsoft.com/en-us/office/internet-explorer-help-23360e49-9cd3-4dda-ba52-705336cc0de2?ui=en-US&rs=en-001&ad=US

                                  2 Important requirements for an installation
                                  ********************************************

                                  Ensure that the following requirements are fulfilled so that Avira
                                  AntiVir PersonalEdition Classic works properly on your computer:

                                  - System requirements fulfilled
                                  - No other on-access scanner (also called Guard) installed
                                  - Installer has administrator rights
                                  - Internet/Intranet connection available
                                  - All running programs on the computer exited

                                  3 Incompatibilities with other programs
                                  ***************************************

                                  Cygwin

                                  If the Avira AntiVir PersonalEdition Classic runs on a system where
                                  the product Cygwin is installed, you might encounter problems with
                                  updating the Avira AntiVir PersonalEdition Classic. In a worst case
                                  scenario you might not be able to update the Avira AntiVir
                                  PersonalEdition Classic at all. Background to this behavior is the
                                  fact that the cygwin process "cygrun.srv.exe" together with the
                                  Microsoft Client/Server runtime server subsystem ("csrss.exe) causes
                                  a complete load of the system once the update process of the Avira
                                  AntiVir PersonalEdition Classic is started. It is therefore strongly
                                  recommended to deinstall Cygwin before the Avira AntiVir
                                  PersonalEdition Classic is installed.

                                  4 Support service
                                  *****************

                                  If you have problems please try first to solve them using the
                                  integrated help system and the user manual (Download at:
                                  http://www.free-av.com). For harder problem, please feel free to
                                  post a message to our bulletin board at https://support.avira.com/hc/de/community/topics or
                                  to call our Support-Hotline.

                                  Please also feel free to post bug reports, hints, feature requests
                                  and anything else related to the Avira AntiVir PersonalEdition
                                  Classic to this Bulletin Board.

                                  Please note that technical inquiries can only be anserwered via our
                                  Support-Forum or our Support-Hotline.

                                  Support-Forum
                                  -------------

                                  ...our forum is available for you at any time!

                                  The forum, which is subdivided into clear categories offers you the
                                  possibility to exchange yourself online with other users and our
                                  employees of the customer support. An up-to-date, electronic
                                  bulletin board that is coordinated by our moderators is available.
                                  Our experience multiplies with the experience from the users of
                                  AntiVir all over the world. Have a look on it without any
                                  obligation...

                                  https://support.avira.com/hc/de/community/topics

                                  Support-Hotline
                                  ---------------

                                  Germany: 0900 10 11 333 (1,99 Euro/Min*)
                                  Austria: 0900 51 03 61 121 (2,16 Euro/Min*)
                                  Switzerland: 0900 51 03 61 (4,23 CHF/Min*)

                                  * Prices are subject to change.

                                  Mo - Fr between 10 a.m. and 7 p.m.

                                  5 Contact
                                  *********

                                  Avira GmbH
                                  Lindauer Str. 21
                                  D-88069 Tettnang
                                  Germany

                                  Internet: https://www.avira.com/
                                  0
                                  1. AntiVir PersonalEdition Classic
                                    Report file date: jeudi 13 septembre 2007 18:52

                                    Scanning for 1036370 virus strains and unwanted programs.

                                    Licensed to: Avira AntiVir PersonalEdition Classic
                                    Serial number: 0000149996-ADJIE-0001
                                    Platform: Windows XP
                                    Windows version: (Service Pack 2) [5.1.2600]
                                    Username: sanchez justin
                                    Computer name: SN103349230005

                                    Version information:
                                    BUILD.DAT : 269 15604 Bytes 10/09/2007 14:31:00
                                    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 12:16:29
                                    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 11:23:51
                                    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 14:32:47
                                    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 11:35:20
                                    ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 11:32:40
                                    ANTIVIR1.VDF : 6.39.0.129 7251968 Bytes 10/07/2007 11:32:46
                                    ANTIVIR2.VDF : 6.39.1.43 1542656 Bytes 25/08/2007 16:21:02
                                    ANTIVIR3.VDF : 6.39.1.51 29696 Bytes 28/08/2007 06:22:36
                                    AVEWIN32.DLL : 7.6.0.5 2789888 Bytes 29/08/2007 16:09:10
                                    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
                                    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 06:39:17
                                    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
                                    AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 07:46:00
                                    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 06:17:06
                                    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 11:26:33
                                    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 06:10:18
                                    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
                                    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 11:38:13
                                    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 11:50:37
                                    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 08:37:21

                                    Configuration settings for the scan:
                                    Jobname..........................: Windows System Directory
                                    Configuration file...............: C:\Program Files\Avira\AntiVir PersonalEdition Classic\setupprf.dat
                                    Logging..........................: low
                                    Primary action...................: interactive
                                    Secondary action.................: ignore
                                    Scan master boot sector..........: off
                                    Scan boot sector.................: on
                                    Boot sectors.....................: C:,
                                    Scan memory......................: on
                                    Process scan.....................: on
                                    Scan registry....................: on
                                    Search for rootkits..............: off
                                    Scan all files...................: Intelligent file selection
                                    Scan archives....................: on
                                    Recursion depth..................: 20
                                    Smart extensions.................: on
                                    Macro heuristic..................: on
                                    File heuristic...................: medium

                                    Start of the scan: jeudi 13 septembre 2007 18:52

                                    The scan of running processes will be started
                                    Scan process 'avscan.exe' - '1' Module(s) have been scanned
                                    Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
                                    Scan process 'notepad.exe' - '1' Module(s) have been scanned
                                    Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
                                    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                                    Scan process 'avguard.exe' - '1' Module(s) have been scanned
                                    Scan process 'sched.exe' - '1' Module(s) have been scanned
                                    Scan process 'wmplayer.exe' - '1' Module(s) have been scanned
                                    Scan process 'iexplore.exe' - '1' Module(s) have been scanned
                                    Scan process 'iexplore.exe' - '1' Module(s) have been scanned
                                    Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
                                    Scan process 'Watch.exe' - '1' Module(s) have been scanned
                                    Scan process 'SAVSCAN.EXE' - '1' Module(s) have been scanned
                                    Scan process 'alg.exe' - '1' Module(s) have been scanned
                                    Scan process 'iexplore.exe' - '1' Module(s) have been scanned
                                    Scan process 'iPodService.exe' - '1' Module(s) have been scanned
                                    Scan process 'ALERTM~1.EXE' - '1' Module(s) have been scanned
                                    Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
                                    Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
                                    Scan process 'Toaster.exe' - '1' Module(s) have been scanned
                                    Scan process 'ComComp.exe' - '1' Module(s) have been scanned
                                    Scan process 'WiFiStationLB.exe' - '1' Module(s) have been scanned
                                    Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
                                    Scan process 'iexplore.exe' - '1' Module(s) have been scanned
                                    Scan process 'daemon.exe' - '1' Module(s) have been scanned
                                    Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                                    Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                                    Scan process 'hldivjvprk.exe' - '1' Module(s) have been scanned
                                    Scan process 'vsnp2std.exe' - '1' Module(s) have been scanned
                                    Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
                                    Scan process 'qttask.exe' - '1' Module(s) have been scanned
                                    Scan process 'smax4pnp.exe' - '1' Module(s) have been scanned
                                    Scan process 'realsched.exe' - '1' Module(s) have been scanned
                                    Scan process 'SMax4.exe' - '1' Module(s) have been scanned
                                    Scan process 'AOSD.EXE' - '1' Module(s) have been scanned
                                    Scan process 'lxbkbmon.exe' - '1' Module(s) have been scanned
                                    Scan process 'lxbkbmgr.exe' - '1' Module(s) have been scanned
                                    Scan process 'ABOARD.EXE' - '1' Module(s) have been scanned
                                    Scan process 'PCMService.exe' - '1' Module(s) have been scanned
                                    Scan process 'symwsc.exe' - '1' Module(s) have been scanned
                                    Scan process 'CCAPP.EXE' - '1' Module(s) have been scanned
                                    Scan process 'jusched.exe' - '1' Module(s) have been scanned
                                    Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
                                    Scan process 'ALCWZRD.EXE' - '1' Module(s) have been scanned
                                    Scan process 'SoundMan.exe' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'slserv.exe' - '1' Module(s) have been scanned
                                    Scan process 'NAVAPSVC.EXE' - '1' Module(s) have been scanned
                                    Scan process 'MDM.EXE' - '1' Module(s) have been scanned
                                    Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
                                    Scan process 'CCPROXY.EXE' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'explorer.exe' - '1' Module(s) have been scanned
                                    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                                    Scan process 'LEXPPS.EXE' - '1' Module(s) have been scanned
                                    Scan process 'LEXBCES.EXE' - '1' Module(s) have been scanned
                                    Scan process 'CCEVTMGR.EXE' - '1' Module(s) have been scanned
                                    Scan process 'SNDSrvc.exe' - '1' Module(s) have been scanned
                                    Scan process 'CCSETMGR.EXE' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'lsass.exe' - '1' Module(s) have been scanned
                                    Scan process 'services.exe' - '1' Module(s) have been scanned
                                    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                                    Scan process 'csrss.exe' - '1' Module(s) have been scanned
                                    Scan process 'smss.exe' - '1' Module(s) have been scanned
                                    69 processes with 69 modules were scanned

                                    Start scanning boot sectors:
                                    Boot sector 'C:\'
                                    [NOTE] No virus was found!

                                    Starting to scan the registry.
                                    C:\Documents and Settings\All Users\Application Data\Cool bolt hide 4\Iso Fork.exe
                                    [DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
                                    [WARNING] The file could not be deleted!
                                    C:\Documents and Settings\All Users\Application Data\Cool bolt hide 4\Iso Fork.exe
                                    [DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen

                                    The registry was scanned ( '45' files ).

                                    Starting the file scan:

                                    Begin scan in 'C:\WINDOWS\system32'

                                    End of the scan: jeudi 13 septembre 2007 18:52
                                    Used time: 00:48 min

                                    The scan has been canceled!

                                    1 Scanning directories
                                    623 Files were scanned
                                    1 viruses and/or unwanted programs were found
                                    0 Files were classified as suspicious:
                                    0 files were deleted
                                    0 files were repaired
                                    0 files were moved to quarantine
                                    0 files were renamed
                                    0 Files cannot be scanned
                                    622 Files not concerned
                                    1 Archives were scanned
                                    1 Warnings
                                    0 Notes
                                    0
                                    1. C'est Quoi ça ?
                                      ok, si tu veux faire comme tu veux, vas-y...
                                      Mais partir dans tout les sens, sans suivre les recommandations, c'est pas sympa pour moi
                                      :-(((((
                                      Tu ne suis pas mes conseils !
                                      Tu fais comme bon te semble..Je laisse la main dsl.
                                      0
                                      1. mais attender je suis dsl mais moi je suis novice je ne compren pas tro au ordi c pour sa que je vous demande de l'aide.
                                        depui taleur je fé se ke vous me dite, je fé ke de relire vos mail et je fé exactement se ke vous me dite .
                                        dsl si je fé nimporte koi mais en tt cas je ne fé pas com bon me semble vu ke ji compren rien.
                                        0
                                        1. svp aider moi, je ne compren pas.
                                          dite moi les choses a faire mais ue seul chose a la foi svp.
                                          il ny a que vous qui pouvez maider.
                                          0
                                          • 1
                                          • 2