Spayware impossible àse débarasser

Bonjour,
je resois sans cesse sur mon onglet internet explorer des onglets d centre de sécurité windows qui m averti que des logiciels espions on envahis mon PC .de plus je recois des pub intempestives . j ai donc téléchargé plusieurs logiciels :

ccleaner
spyware sécur
spyware doctor
avast
hijack this
avg anti-syware

et voii le rapport

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:39:16, on 26/11/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16546)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Windows\system32\svchost.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Users\Lucie\AppData\Local\fvnngfnfeu.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\System32\p2phost.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\WINDOWS\System32\rundll32.exe
C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [fvnngfnfeu] c:\users\lucie\appdata\local\fvnngfnfeu.exe fvnngfnfeu
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [CollaborationHost] C:\Windows\system32\p2phost.exe -s
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Outil de détection de support de Cyber-shot Viewer.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O13 - Gopher Prefix:
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 11419 bytes
Configuration: Windows Vista
Internet Explorer 7.0

29 réponses

Résumé de la discussion

Plusieurs alertes du centre de sécurité Windows apparaissent sur Internet Explorer, signalant des logiciels espions et des publicités intempestives, poussant à installer des outils comme CCleaner, Spyware Doctor, Avast et HijackThis. Le rapport HijackThis v2.0.2 et la liste de processus montrent de nombreuses entrées, certaines légitimes (Avast, Google Updater, HP services), d'autres potentiellement indésirables dans les clés et le démarrage. La meilleure réponse recommande d'utiliser Avira AntiVir Personal Edition Classic, avec un rapport détaillé et une analyse des résultats de scan et des processus afin d'identifier les éléments suspects. En contexte, le rapport date de 2007 et mentionne des services légitimes tels que HP QuickPlay, Google Updater ou Skype, soulignant l'importance de vérifier dépendances et chemins d'exécution avant toute suppression.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    slt

    tu dis avoir télécharger
    spyware sécur

    et c'est pas bon car c'est un espion!!!!!!!!! qui entraine des pubs!

    _______________

    Fais un clic droit sur ce lien : (IL-MAFIOSO)
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
    Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Laisse-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
    Copie-colle l'intégralité dans une réponse. Referme le blocnote.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
    1. merci pour l'info !cest dingue ca ! j ai fais tous ce que tu m'a dit, et lorsque je double clic il me demande de choisir ma langue en tapant sur la lettre F. lorsque je le fais, il s'inscrit : accès refusé . Le bad !
      comment je fais ?merci bcp
      1. Contributeur sécurité
        pardon tu as vista fais comme ça:

        Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

        - Va dans démarrer puis panneau de configuration
        - Double Clique sur l'icône "Comptes d'utilisateurs"
        - Clique ensuite sur désactiver et valide.

        Télécharge maintenant Navilog1 depuis-ce lien :

        http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

        Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
        Ensuite double clique sur navilog1.exe pour lancer l'installation.
        Une fois l'installation terminée, Fais un Clic-droit sur le raccourci Navilog1 présent sur ton bureau et choisis "Exécuter

        en tant qu'administrateur".

        Au menu principal, Fais le choix 1
        Laisse toi guider et patiente.
        Patiente jusqu'au message :
        *** Analyse Termine le ..... ***
        Appuie sur une touche le blocnote va s'ouvrir.
        Copie-colle l'intégralité du rapport dans une réponse.
        Referme le blocnote
        Le rapport fixnavi.txt est en outre sauvegardé dans %systemdrive%.
        1. Contributeur sécurité
          oui ca ce peux
          si ca bloque

          Lance AVG ANTI ROOTKIT :

          http://www.libellules.ch/dotclear/index.php?2007/03/28/1781-avg-anti-rootkit
          1. voila, comme tu m'as dis g télécharger avg anti rootkit et j ai lancé le scann.
            1. Contributeur sécurité
              ok nettoie avec puis :

              Télécharge Catchme de Gmer sur le bureau :

              http://www2.gmer.net/catchme.php

              * Double cliquer sur le fichier catchme.exe pour lancer l'utilitaire.
              * Cliquer sur Scan, Une fenêtre DOS s'ouvrira pour commencer l'analyse.
              * Attendre jusqu'au message « scan completed successfully », puis fermer la fenêtre.
              * Un fichier catchme.log est alors créé sur le bureau contenant le résultat de l'analyse. et me le coller
              1. Contributeur sécurité
                Une fois la recherche terminée, vous n'avez qu'à sélectionner les rootkits à supprimer et nettoyer votre système avec le bouton « Remove selected items ».
                1. la fenêtre dos s ouvre, il y a des inscriptions, mais rien ne se passe.... c 'est inscrit : this scann is sucefully
                  voici le rapport Hijackthis
                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 16:40:08, on 27/11/2007
                  Platform: Windows Vista (WinNT 6.00.1904)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16546)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\System32\smss.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\wininit.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\services.exe
                  C:\Windows\system32\lsass.exe
                  C:\Windows\system32\lsm.exe
                  C:\Windows\system32\winlogon.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\SLsvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\Windows\System32\spoolsv.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  C:\Program Files\HP\QuickPlay\QPService.exe
                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                  C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                  C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                  C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                  C:\Program Files\Java\jre1.6.0\bin\jusched.exe
                  C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Spyware Doctor\svcntaux.exe
                  C:\Program Files\Spyware Doctor\swdsvc.exe
                  C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\WINDOWS\System32\rundll32.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Program Files\Skype\Phone\Skype.exe
                  C:\Windows\system32\SearchIndexer.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\WINDOWS\ehome\ehtray.exe
                  C:\WINDOWS\System32\p2phost.exe
                  C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                  C:\Program Files\Spyware Doctor\SDTrayApp.exe
                  C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                  C:\Windows\system32\DRIVERS\xaudio.exe
                  C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
                  C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
                  C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                  C:\Program Files\Windows Live\Messenger\usnsvc.exe
                  C:\Windows\servicing\TrustedInstaller.exe
                  C:\Windows\system32\conime.exe
                  C:\Program Files\Windows Live Toolbar\msn_sl.exe
                  C:\Windows\system32\SearchProtocolHost.exe
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Users\Lucie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CBAS5MPE\catchme[1].exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\RacAgent.exe
                  C:\Windows\system32\lpremove.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Windows\system32\lpksetup.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                  O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                  O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                  O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                  O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                  O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                  O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
                  O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                  O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [CollaborationHost] C:\Windows\system32\p2phost.exe -s
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [pjglavjtt] c:\users\lucie\appdata\local\pjglavjtt.exe pjglavjtt
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - Startup: Outil de détection de support de Cyber-shot Viewer.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                  O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                  O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                  O13 - Gopher Prefix:
                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
                  O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
                  O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                  O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                  O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
                  O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                  1. Contributeur sécurité
                    Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

                    O4 - HKCU\..\Run: [pjglavjtt] c:\users\lucie\appdata\local\pjglavjtt.exe pjglavjtt

                    __________________

                    télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe (de Old_Timer) sur ton Bureau.
                    double-clique sur OTMoveIt.exe pour le lancer.
                    copie la liste qui se trouve en citation ci-dessous,
                    et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

                    Citation :

                    c:\users\lucie\appdata\local\pjglavjtt.exe

                    clique sur MoveIt! pour lancer la suppression.
                    le résultat apparaitra dans le cadre "Results".
                    clique sur Exit pour fermer.
                    poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                    il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

                    _______________________

                    remplace avast par antivir et colle un rapport:
                    https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)

                    _______________________

                    si tes pbs persistent il me faut: navilog (essaye en desactivant windows defender et spyware docotor

                    Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                    - Va dans démarrer puis panneau de configuration
                    - Double Clique sur l'icône "Comptes d'utilisateurs"
                    - Clique ensuite sur désactiver et valide.

                    Télécharge maintenant Navilog1 depuis-ce lien :

                    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

                    Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
                    Ensuite double clique sur navilog1.exe pour lancer l'installation.
                    Une fois l'installation terminée, Fais un Clic-droit sur le raccourci Navilog1 présent sur ton bureau et choisis "Exécuter

                    en tant qu'administrateur".

                    Au menu principal, Fais le choix 1
                    Laisse toi guider et patiente.
                    Patiente jusqu'au message :
                    *** Analyse Termine le ..... ***
                    Appuie sur une touche le blocnote va s'ouvrir.
                    Copie-colle l'intégralité du rapport dans une réponse.
                    Referme le blocnote
                    Le rapport fixnavi.txt est en outre sauvegardé dans %systemdrive%.
                    1. jen suis qu' la première étape et déjà, bonne nvlle, mon lecteur windows média player remarche!! youpi ! tjrs à la première étape,j'ai suivi les instructions à la lettre et je n'arrive pas à retrouver le rapport
                      poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
                      1. Merci pour tous tes conseils ! c'est vraiment sympa, j ai fai omme tu m'a dit, j ai changé d anti virus. Mais qu'est ce que je fais des programmes que tu m a fais télécharger, ainsi que mes anciens progrommes

                        ccleaner
                        spyware doctor
                        avast
                        hijack this
                        avg anti-syware
                        1. AntiVir PersonalEdition Classic
                          Report file date: mardi 27 novembre 2007 17:58

                          Scanning for 835736 virus strains and unwanted programs.

                          Licensed to: Avira AntiVir PersonalEdition Classic
                          Serial number: 0000149996-ADJIE-0001
                          Platform: Windows Vista
                          Windows version: (plain) [6.0.6000]
                          Username: Lucie
                          Computer name: PC-DE-LUCIE

                          Version information:
                          BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                          AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
                          AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
                          LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
                          LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
                          ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
                          ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 14:26:55
                          ANTIVIR2.VDF : 7.0.0.1 2048 Bytes 13/09/2007 14:27:04
                          ANTIVIR3.VDF : 7.0.0.2 2048 Bytes 13/09/2007 14:27:13
                          AVEWIN32.DLL : 7.6.0.15 2806272 Bytes 17/09/2007 17:43:56
                          AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
                          AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
                          AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                          AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 08:46:00
                          AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
                          AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
                          AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
                          NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
                          RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
                          RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
                          SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

                          Configuration settings for the scan:
                          Jobname..........................: Windows System Directory
                          Configuration file...............: C:\Program Files\Avira\AntiVir PersonalEdition Classic\setupprf.dat
                          Logging..........................: low
                          Primary action...................: interactive
                          Secondary action.................: ignore
                          Scan master boot sector..........: off
                          Scan boot sector.................: on
                          Boot sectors.....................: C:,
                          Scan memory......................: on
                          Process scan.....................: on
                          Scan registry....................: on
                          Search for rootkits..............: off
                          Scan all files...................: Intelligent file selection
                          Scan archives....................: on
                          Recursion depth..................: 20
                          Smart extensions.................: on
                          Macro heuristic..................: on
                          File heuristic...................: medium

                          Start of the scan: mardi 27 novembre 2007 17:58

                          The scan of running processes will be started
                          Scan process 'avscan.exe' - '1' Module(s) have been scanned
                          Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                          Scan process 'avguard.exe' - '1' Module(s) have been scanned
                          Scan process 'sched.exe' - '1' Module(s) have been scanned
                          Scan process 'SearchFilterHost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'VSSVC.exe' - '1' Module(s) have been scanned
                          Scan process 'SearchProtocolHost.exe' - '1' Module(s) have been scanned
                          Scan process 'TrustedInstaller.exe' - '1' Module(s) have been scanned
                          Scan process 'HPHC_Service.exe' - '1' Module(s) have been scanned
                          Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
                          Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
                          Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                          Scan process 'iexplore.exe' - '1' Module(s) have been scanned
                          Scan process 'HPQTOA~1.EXE' - '1' Module(s) have been scanned
                          Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
                          Scan process 'CLSched.exe' - '1' Module(s) have been scanned
                          Scan process 'hpqwmiex.exe' - '1' Module(s) have been scanned
                          Scan process 'XAudio.exe' - '1' Module(s) have been scanned
                          Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
                          Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
                          Scan process 'CLCapSvc.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'guard.exe' - '1' Module(s) have been scanned
                          Scan process 'sidebar.exe' - '1' Module(s) have been scanned
                          Scan process 'rundll32.exe' - '1' Module(s) have been scanned
                          Scan process 'SPUVolumeWatcher.exe' - '1' Module(s) have been scanned
                          Scan process 'GoogleUpdater.exe' - '1' Module(s) have been scanned
                          Scan process 'p2phost.exe' - '1' Module(s) have been scanned
                          Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
                          Scan process 'ehtray.exe' - '1' Module(s) have been scanned
                          Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                          Scan process 'Skype.exe' - '1' Module(s) have been scanned
                          Scan process 'sidebar.exe' - '1' Module(s) have been scanned
                          Scan process 'avgas.exe' - '1' Module(s) have been scanned
                          Scan process 'SDTrayApp.exe' - '1' Module(s) have been scanned
                          Scan process 'jusched.exe' - '1' Module(s) have been scanned
                          Scan process 'HPWAMain.exe' - '1' Module(s) have been scanned
                          Scan process 'WiFiMsg.exe' - '1' Module(s) have been scanned
                          Scan process 'QLBCTRL.exe' - '1' Module(s) have been scanned
                          Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
                          Scan process 'QPService.exe' - '1' Module(s) have been scanned
                          Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
                          Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
                          Scan process 'explorer.exe' - '1' Module(s) have been scanned
                          Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                          Scan process 'dwm.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
                          Scan process 'audiodg.exe' - '0' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                          Scan process 'lsm.exe' - '1' Module(s) have been scanned
                          Scan process 'lsass.exe' - '1' Module(s) have been scanned
                          Scan process 'services.exe' - '1' Module(s) have been scanned
                          Scan process 'csrss.exe' - '1' Module(s) have been scanned
                          Scan process 'wininit.exe' - '1' Module(s) have been scanned
                          Scan process 'csrss.exe' - '1' Module(s) have been scanned
                          Scan process 'smss.exe' - '1' Module(s) have been scanned
                          70 processes with 70 modules were scanned

                          Start scanning boot sectors:
                          Boot sector 'C:\'
                          [NOTE] No virus was found!

                          Starting to scan the registry.
                          The registry was scanned ( '25' files ).

                          Starting the file scan:

                          Begin scan in 'C:\Windows\system32'

                          End of the scan: mardi 27 novembre 2007 18:03
                          Used time: 05:10 min

                          The scan has been done completely.

                          1050 Scanning directories
                          31937 Files were scanned
                          0 viruses and/or unwanted programs were found
                          0 Files were classified as suspicious:
                          0 files were deleted
                          0 files were repaired
                          0 files were moved to quarantine
                          0 files were renamed
                          0 Files cannot be scanned
                          31937 Files not concerned
                          173 Archives were scanned
                          0 Warnings
                          0 Notes

                          Search Navipromo version 3.3.6 commencé le 27/11/2007 à 18:03:45,75

                          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                          !!! Postez ce rapport sur le forum pour le faire analyser !!!
                          !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                          Outil exécuté depuis C:\Program Files\navilog1
                          Mise à jour le 14.11.2007 à 18h00 par IL-MAFIOSO

                          Microsoft Windows Vista 6.0.6000
                          Internet Explorer : 7.0.6000.16546

                          *** Recherche Programmes installés ***

                          *** Recherche dossiers dans C:\Windows ***

                          *** Recherche dossiers dans C:\Program Files ***

                          C:\Program Files\WebMediaPlayer trouvé !

                          *** Recherche dossiers dans C:\ProgramData ***

                          *** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***

                          ...\WebMediaPlayer trouvé !

                          *** Recherche dossiers dans C:\USERS\LUCIE\APPDATA\ROAMING\MICROS~1\WINDOWS\STARTM~1\PROGRAMS ***

                          *** Recherche dossiers dans C:\Users\Lucie\AppData\Local\virtualstore\Program Files ***

                          *** Recherche dossiers dans C:\Users\Lucie\AppData\Roaming ***

                          *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                          pour + d'infos : http://www.gmer.net

                          !! Fichier(s)/processus caché(s) différent(s) !!
                          !! Résultat Catchme non pris en compte par Navilog1 !!

                          *** Recherche avec GenericNaviSearch ***
                          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                          !!! A vérifier impérativement avant toute suppression manuelle !!!

                          * Recherche dans C:\Windows\system32 *

                          * Recherche dans C:\Users\Lucie\AppData\Local\Microsoft *

                          * Recherche dans C:\Users\Lucie\AppData\Local *

                          *** Recherche fichiers ***

                          C:\Windows\system32\nvs2.inf trouvé !

                          *** Recherche clés spécifiques dans le Registre ***

                          *** Module de Recherche complémentaire ***
                          (Recherche fichiers spécifiques)

                          1)Recherche fichiers connus:

                          2)Recherche Heuristique :

                          C:\Users\Lucie\AppData\Local\pjglavjtt.dat trouvé !
                          C:\Users\Lucie\AppData\Local\pjglavjtt_nav.dat trouvé !

                          3)Recherche Certificats :

                          Certificat Egroup trouvé !

                          *** Analyse terminée le 27/11/2007 à 18:04:50,86 ***
                          1. Contributeur sécurité
                            parfait

                            Veille à ce que le contrôle des comptes utilisateurs (UAC) soit désactivé.
                            Fais un Clic-droit sur le raccourci Navilog1 présent sur ton bureau et choisis "Exécuter en tant qu'administrateur".

                            Au menu principal, Fais le choix 2
                            Laisse toi guider et patiente.
                            Le fix va t'informer qu'il va alors redémarrer ton PC
                            Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
                            Appuie sur une touche comme demandé.
                            (si ton Pc ne redémarre pas automatiquement, fais-le toi-même)
                            Au redémarrage de ton PC, choisis ta session habituelle si nécessaire.
                            Patiente jusqu'au message :
                            *** Nettoyage Termine le ..... ***
                            Le blocnote va s'ouvrir.
                            Sauvegarde le rapport de manière à le retrouver
                            Referme le blocnote. Ton bureau va réapparaître
                            Réactive le contrôle des comptes utilisateurs (UAC)

                            PS:Si ton bureau ne réapparaît pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
                            Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
                            Tape explorer et valide. Cela te fera apparaître ton bureau

                            __________________

                            encore des problemes?
                            ________________

                            recolle un rapport hijakthis
                            1. génial !!!! MERCI MERCI !!!

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 19:03:32, on 27/11/2007
                              Platform: Windows Vista (WinNT 6.00.1904)
                              MSIE: Internet Explorer v7.00 (7.00.6000.16546)
                              Boot mode: Normal

                              Running processes:
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\Explorer.EXE
                              C:\Program Files\Windows Defender\MSASCui.exe
                              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              C:\Program Files\HP\QuickPlay\QPService.exe
                              C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                              C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                              C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                              C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                              C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                              C:\Program Files\Java\jre1.6.0\bin\jusched.exe
                              C:\Program Files\Adobe\Reader 8.0\Reader\Reader_SL.exe
                              C:\Program Files\Spyware Doctor\SDTrayApp.exe
                              C:\WINDOWS\System32\rundll32.exe
                              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                              C:\Program Files\Windows Sidebar\sidebar.exe
                              C:\Program Files\Skype\Phone\Skype.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\WINDOWS\ehome\ehtray.exe
                              C:\WINDOWS\System32\p2phost.exe
                              C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                              C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                              C:\Windows\ehome\ehmsas.exe
                              C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
                              C:\Program Files\Windows Sidebar\sidebar.exe
                              C:\Windows\system32\SearchFilterHost.exe
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O1 - Hosts: ::1 localhost
                              O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                              O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                              O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                              O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                              O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                              O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                              O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                              O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                              O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                              O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
                              O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                              O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                              O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                              O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                              O4 - HKCU\..\Run: [CollaborationHost] C:\Windows\system32\p2phost.exe -s
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                              O4 - Startup: Outil de détection de support de Cyber-shot Viewer.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                              O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                              O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                              O13 - Gopher Prefix:
                              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                              O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
                              O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                              O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                              O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                              O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
                              O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
                              O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                              O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                              O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                              O23 - Service: PC Tools Security Service (sdCoreService) - Unknown owner - C:\Program Files\Spyware Doctor\swdsvc.exe (file missing)
                              O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                              O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                              1. aie ! c'est encore moi, mon lecteur windows player fait de nvx des siennes, il ne veut pas s ouvrir ! pourtant j ai fais tou ce que tu m'a dit. merci
                                • 1
                                • 2