Analyse d'un HijackThis

Bonjour,

Je ne sais pas pourquoi, mais, mon pc me fait une peu de soucis, explication, il rame énormément, il se coupe et redémarre tout seul. Si je fait un scanne qu'il soit local ou via Internet, le PC bloque et plante aussi, alors, j'ai lancé un Hijackthis, pourriez-vous l'analyser et me dire si quelque n'est pas normal après étude. je vous remercie tous

Logfile of HijackThis v1.99.1
Scan saved at 13:09:30, on 26/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender Professional Edition\vsserv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Softwin\BitDefender Professional Edition\bdmcon.exe
C:\Program Files\Softwin\BitDefender Professional Edition\bdswitch.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
D:\creativemediasource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\bibi\Bureau\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: BHO pour Compagnon Web Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Compagnon Web Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [BDMCon] C:\Program Files\Softwin\BitDefender Professional Edition\\bdmcon.exe
O4 - HKLM\..\Run: [BDNewsAgent] C:\Program Files\Softwin\BitDefender Professional Edition\\bdnagent.exe
O4 - HKLM\..\Run: [BDSwitchAgent] C:\Program Files\Softwin\BitDefender Professional Edition\bdswitch.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKCU\..\Run: [Creative Detector] D:\creativemediasource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = D:\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/...
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{016254FB-FCA8-4DA4-9257-A19520F09586}: NameServer = 80.10.246.1 80.10.246.132
O17 - HKLM\System\CS1\Services\Tcpip\..\{016254FB-FCA8-4DA4-9257-A19520F09586}: NameServer = 80.10.246.1 80.10.246.132
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender Professional Edition\vsserv.exe" /service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

12 réponses

  1. Bonjour,

    Bon, j'ai suivi les instructions du mss 11, après, j'ai voulu faire un scanne online le pc le scanne démarre et s'arrete, en local il plante purement et simplement et je dois rebooter ?? étrange non.

    Est-il possible d'un virus puise engendrer des actions pareilles ?

    Quelle autre solution ai-je ?

    je pense que je vais formater le C ce soir

    Encore merci de ton aide
    0
    1. Contributeur
      hello
      fais une vérification de ton wind au redémarrage, ^tre patient, c'est un peu longuet
      chemin pour :
      déma>poste de trav>HDD>clic droit>Propriétés>onglet outils>vérifier maintenant>coche les 2 carrés>démarrer
      0
      1. Bonsoir,
        Avant toute chose merci du cuop de main, bon, j'a fait comme tu l'as ecris les deux actions et nettoyage ds hijackthis.
        Ensuite, je suis allé sur le net pour Bitdefender 8 et le scanne online, j'ai toujours le même problème après un certain temps qui n'est pas très long d'ailleurs, il plante, je suis obligé de rebooter à la sauvage. je crois que je vais être obligé de faire un format c pour retrouver quelque chose de clean.

        Si tu as une idée, je vais attendre encore un peu.

        A+
        merci
        0
        1. Contributeur
          hello
          "No action taken."<=== ceci apparaît uniquement avec le online !
          en clair : pas d action correctrice effectuée

          de tte façon, pas dramatique les cookies-traceurs

          tu nettoies ainsi ces traces :
          déma>pano config>options internet> clic sur effacer cookies et tempraires + historique
          fais ceci aussi
          déma>poste de travail>HDD>WINDOWS>prefetch>vire tt à la poubelle sauf laiout

          ton p-feu est-il incorporé à bitdef ???

          on va faire un peu de ménage :
          ouvre hijack
          coche et fixe ce qui suit :

          O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE

          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot

          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe

          O4 - HKCU\..\Run: [Creative Detector] D:\creativemediasource\Detector\CTDetect.exe /R

          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

          O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = D:\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          +
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
          O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/...
          ============

          à quoi te sers CreativeDetector ??
          =======
          essaie à nouveau les scans préconisés

          0
          1. Salut,

            avant toute chose merci de te pencher sur mon cas, mais, le rapport que tu as là est un rapport local, je réitére mes propos, je ne peux pas faire de scanne en ligne car si je lance un test le pc plante que se soit Ewido ou BitDefender.
            0
            1. Contributeur
              bsr
              rapport Ewido
              tu as fait le online
              donc rien n est corrigé
              il faut télécharger le progr

              essaie d etre attentif à ce qui est marqué ds le tuto !!!

              recommence
              0
              1. Bonsoir,

                J'ai fait comme il est dit en instruction.
                défrag en F8
                analyse avec ewido
                rapport ci-joint.

                mais, il faut savoir que je ne peux pas faire de scanne dès que je le fais que se soit en local avec bitdefender7.2 ou en ligne, le pc plante, je ne sais que faire, je dois avoir quelque chose mais quoi ??

                voici le rapport les autres sont déjà en ligne..
                merci du cup de main quand même.

                --------------------------------------------------------
                ewido anti-spyware - Scan Report
                ---------------------------------------------------------

                + Created at: 22:13:46 27/06/2006

                + Scan result:

                C:\Documents and Settings\bibi\Cookies\bibi@247realmedia[1].txt -> TrackingCookie.247realmedia : No action taken.
                C:\Documents and Settings\bibi\Cookies\bibi@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
                C:\Documents and Settings\bibi\Cookies\bibi@atdmt[1].txt -> TrackingCookie.Atdmt : No action taken.
                C:\Documents and Settings\bibi\Cookies\bibi@bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken.
                C:\Documents and Settings\bibi\Cookies\bibi@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
                C:\Documents and Settings\bibi\Cookies\bibi@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
                C:\Documents and Settings\bibi\Cookies\bibi@serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
                C:\Documents and Settings\bibi\Cookies\bibi@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : No action taken.

                ::Report end

                A+
                0
                1. Contributeur
                  bsr

                  du boulot suppl

                  faire une défragmentation en sans échec

                  3/ - Ewido (download)- gratuit même après 14 jours d’essai
                  http://perso.wanadoo.fr/entraide-hijackthis/Ewido/
                  Copie/COLLE le rapport généré sur ce forum

                  4/ - Ccleaner : ( nettoyeur de registre, cookies+temps+tempos+prefetch+historique+etc..)
                  Télécharge ici :
                  https://www.ccleaner.com/ccleaner/download
                  Tutorial ici:
                  https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

                  5/ - Scan online avec BitDefender (fonctionne uniquement sous Internet Explorer en acceptant l’ activX)
                  https://assiste.com/404_La_page_demandee_n_existe_pas.php
                  http://www.bitdefender.fr/scan8/ie.html
                  Copie/COLLE le rapport entier
                  0
                  1. Bonjour,

                    Je ne sais pas pourquoi, mais, mon pc me fait une peu de soucis, explication, il rame énormément, il se coupe et redémarre tout seul. Si je fait un scanne qu'il soit local ou via Internet, le PC bloque et plante aussi, alors, j'ai lancé un Hijackthis, pourriez-vous l'analyser et me dire si quelque n'est pas normal après étude. je vous remercie tous

                    Logfile of HijackThis v1.99.1
                    Scan saved at 13:09:30, on 26/06/2006
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Ahead\InCD\InCDsrv.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                    C:\WINDOWS\system32\CTsvcCDA.EXE
                    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                    C:\WINDOWS\system32\nvsvc32.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
                    C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
                    C:\Program Files\Softwin\BitDefender Professional Edition\vsserv.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Softwin\BitDefender Professional Edition\bdmcon.exe
                    C:\Program Files\Softwin\BitDefender Professional Edition\bdswitch.exe
                    C:\WINDOWS\system32\LVCOMSX.EXE
                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                    C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
                    D:\creativemediasource\Detector\CTDetect.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\Documents and Settings\bibi\Bureau\HijackThis.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Spybot - Search & Destroy\SDHelper.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
                    O2 - BHO: BHO pour Compagnon Web Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                    O3 - Toolbar: Compagnon Web Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                    O4 - HKLM\..\Run: [BDMCon] C:\Program Files\Softwin\BitDefender Professional Edition\\bdmcon.exe
                    O4 - HKLM\..\Run: [BDNewsAgent] C:\Program Files\Softwin\BitDefender Professional Edition\\bdnagent.exe
                    O4 - HKLM\..\Run: [BDSwitchAgent] C:\Program Files\Softwin\BitDefender Professional Edition\bdswitch.exe
                    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
                    O4 - HKCU\..\Run: [Creative Detector] D:\creativemediasource\Detector\CTDetect.exe /R
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = D:\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\MICROS~1\OFFICE11\EXCEL.EXE/3000
                    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\MICROS~1\OFFICE11\REFIEBAR.DLL
                    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                    O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe
                    O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe
                    O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                    O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/...
                    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{016254FB-FCA8-4DA4-9257-A19520F09586}: NameServer = 80.10.246.1 80.10.246.132
                    O17 - HKLM\System\CS1\Services\Tcpip\..\{016254FB-FCA8-4DA4-9257-A19520F09586}: NameServer = 80.10.246.1 80.10.246.132
                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
                    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
                    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                    O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\TuneUp Utilities 2006\WinStylerThemeSvc.exe
                    O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender Professional Edition\vsserv.exe" /service (file missing)
                    O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

                    [ Répondre à pascalrosny ][ Dernière contribution ]
                    [ Alerter un modérateur ][ Autres messages de pascalrosny ]

                    < 1 > - analyse d'un HijackThis
                    Ajouté par ^^Marie^^ (26/06/2006 à 14:50 GMT+2)
                    Salut,

                    Peut-être commencer par la case départ ::

                    Télécharge et colle les 2 rapports dans l’ordre

                    A - ad-aware version 1.06
                    (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite
                    voir demo
                    http://pageperso.aol.fr/balltrap34/adwseflash.zip

                    B - spybot version 1.4
                    (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite
                    voir demo d utilisation
                    http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

                    C - Ccleaner : ( nettoyeur de registre, cookies+temps+tempos+prefetch+historique+etc..)
                    Télécharge ici :
                    https://www.ccleaner.com/ccleaner/download
                    Tutorial ici:
                    https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

                    =======================================

                    D - Ewido (download)- gratuit même après 14 jours d’essai
                    http://perso.wanadoo.fr/entraide-hijackthis/Ewido/
                    Copie/COLLE le rapport généré sur ce forum
                    Pour certaines versions de Windows antérieures à XP, Ewido peut ne pas être compatible
                    Dans ce cas, il te faudra utiliser a-squared free et demander une clef pour son usage gratuit
                    https://www.emsisoft.com/fr/

                    E - Scan online avec BitDefender (fonctionne uniquement sous Internet Explorer en acceptant l’ activX)
                    https://assiste.com/404_La_page_demandee_n_existe_pas.php
                    http://www.bitdefender.fr/scan8/ie.html
                    Copie/COLLE le rapport entier

                    ENSUITE :

                    Smitfraudfix

                    1°/ - Télécharge le logiciel SmitfraudFix ((crée par S!Ri J)
                    http://siri.urz.free.fr/Fix/SmitfraudFix.zip et décompresse le.

                    - Ouvre le dossier "SmitfraudFix" qui sera apparu, double clic sur "Smitfraudfix.cmd", choisis l’option 1, un log va être généré…

                    Tutorial imagée à lire :
                    http://siri.urz.free.fr/Fix/SmitfraudFix.php

                    Copie-COLLE ce dernier dans un message sur le forum.

                    ENSUITE

                    2°/ - Démarre en mode sans échec :

                    Pour cela, tu tapotes la touche F8 dès le début de l’allumage du PC sans t’arrêter
                    Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape ‘Entrée’ sur ton clavier.

                    Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres, c’est normal !
                    (Si F8 ne marche pas utilise la touche F5).

                    3°/ - Relance le programme Smitfraud,
                    Cette fois choisit l’option 2, répond OUI à tout ;
                    Sauvegarde le rapport, redémarre en mode normal,
                    Copie-COLLE le rapport sauvegardé sur le forum.

                    Bon courage
                    A++

                    --
                    Le signe le plus évident d'un cancer social... c'est la disparition du sens
                    de l'humour, dommage c'est la forme la plus saine de la lucidité
                    [ Continuer la discussion ][ Répondre à ^^Marie^^ ]
                    [ Alerter un modérateur ][ Autres messages de ^^Marie^^ ]

                    < 2 > - analyse d'un HijackThis
                    Ajouté par pascalrosny (26/06/2006 à 21:06 GMT+2)
                    Suite de ma petite histoire, j'ai fait les démarches qui étaient proposées, voici:

                    Premier le rapport de Adaware
                    Deuxième le rapport SmitFraudFix
                    En trois Hijackthis

                    J'ai essayé de faire un scanne en ligne, mais le pc plante a chaque fois, je ne comprends pas, si je fais un scanne local idem, je pense que je suis plomber, mais, je préfére attendre une réponse de votre part.

                    Merci de votre aide

                    1

                    Ad-Aware SE Build 1.06r1
                    Logfile Created on:lundi 26 juin 2006 19:08:30
                    Created with Ad-Aware SE Personal, free for private use.
                    Using definitions file:SE1R112 15.06.2006
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    References detected during the scan:
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    Tracking Cookie(TAC index:3):1 total references
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    Ad-Aware SE Settings
                    ===========================
                    Set : Search for negligible risk entries
                    Set : Safe mode (always request confirmation)
                    Set : Scan active processes
                    Set : Scan registry
                    Set : Deep-scan registry
                    Set : Scan my IE Favorites for banned URLs
                    Set : Scan my Hosts file

                    Extended Ad-Aware SE Settings
                    ===========================
                    Set : Unload recognized processes & modules during scan
                    Set : Scan registry for all users instead of current user only
                    Set : Always try to unload modules before deletion
                    Set : During removal, unload Explorer and IE if necessary
                    Set : Let Windows remove files in use at next reboot
                    Set : Delete quarantined objects after restoring
                    Set : Include basic Ad-Aware settings in log file
                    Set : Include additional Ad-Aware settings in log file
                    Set : Include reference summary in log file
                    Set : Include alternate data stream details in log file
                    Set : Play sound at scan completion if scan locates critical objects

                    26-06-2006 19:08:30 - Scan started. (Smart mode)

                    Listing running processes
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    #:1 [smss.exe]
                    FilePath : \SystemRoot\System32\
                    ProcessID : 704
                    ThreadCreationTime : 26-06-2006 16:37:35
                    BasePriority : Normal

                    #:2 [csrss.exe]
                    FilePath : \??\C:\WINDOWS\system32\
                    ProcessID : 764
                    ThreadCreationTime : 26-06-2006 16:37:39
                    BasePriority : Normal

                    #:3 [winlogon.exe]
                    FilePath : \??\C:\WINDOWS\system32\
                    ProcessID : 788
                    ThreadCreationTime : 26-06-2006 16:37:40
                    BasePriority : High

                    #:4 [services.exe]
                    FilePath : C:\WINDOWS\system32\
                    ProcessID : 836
                    ThreadCreationTime : 26-06-2006 16:37:40
                    BasePriority : Normal
                    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 5.1.2600.2180
                    ProductName : Système d'exploitation Microsoft® Windows®
                    CompanyName : Microsoft Corporation
                    FileDescription : Applications Services et Contrôleur
                    InternalName : services.exe
                    LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                    OriginalFilename : services.exe

                    #:5 [lsass.exe]
                    FilePath : C:\WINDOWS\system32\
                    ProcessID : 848
                    ThreadCreationTime : 26-06-2006 16:37:40
                    BasePriority : Normal
                    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 5.1.2600.2180
                    ProductName : Microsoft® Windows® Operating System
                    CompanyName : Microsoft Corporation
                    FileDescription : LSA Shell (Export Version)
                    InternalName : lsass.exe
                    LegalCopyright : © Microsoft Corporation. All rights reserved.
                    OriginalFilename : lsass.exe

                    #:6 [svchost.exe]
                    FilePath : C:\WINDOWS\system32\
                    ProcessID : 992
                    ThreadCreationTime : 26-06-2006 16:37:40
                    BasePriority : Normal
                    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 5.1.2600.2180
                    ProductName : Microsoft® Windows® Operating System
                    CompanyName : Microsoft Corporation
                    FileDescription : Generic Host Process for Win32 Services
                    InternalName : svchost.exe
                    LegalCopyright : © Microsoft Corporation. All rights reserved.
                    OriginalFilename : svchost.exe

                    #:7 [svchost.exe]
                    FilePath : C:\WINDOWS\system32\
                    ProcessID : 1052
                    ThreadCreationTime : 26-06-2006 16:37:41
                    BasePriority : Normal
                    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 5.1.2600.2180
                    ProductName : Microsoft® Windows® Operating System
                    CompanyName : Microsoft Corporation
                    FileDescription : Generic Host Process for Win32 Services
                    InternalName : svchost.exe
                    LegalCopyright : © Microsoft Corporation. All rights reserved.
                    OriginalFilename : svchost.exe

                    #:8 [svchost.exe]
                    FilePath : C:\WINDOWS\System32\
                    ProcessID : 1092
                    ThreadCreationTime : 26-06-2006 16:37:41
                    BasePriority : Normal
                    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 5.1.2600.2180
                    ProductName : Microsoft® Windows® Operating System
                    CompanyName : Microsoft Corporation
                    FileDescription : Generic Host Process for Win32 Services
                    InternalName : svchost.exe
                    LegalCopyright : © Microsoft Corporation. All rights reserved.
                    OriginalFilename : svchost.exe

                    #:9 [incdsrv.exe]
                    FilePath : C:\Program Files\Ahead\InCD\
                    ProcessID : 1112
                    ThreadCreationTime : 26-06-2006 16:37:41
                    BasePriority : Normal
                    FileVersion : 4, 3, 23, 2
                    ProductVersion : 4, 3, 23, 2
                    ProductName : Nero AG incdsrv
                    CompanyName : Nero AG
                    FileDescription : incdsrv
                    InternalName : incdsrv
                    LegalCopyright : Copyright 1995-2006 Nero AG and its licensors. All Rights Reserved.
                    LegalTrademarks : InCD is a trademark of Nero AG
                    OriginalFilename : incdsrv.exe

                    #:10 [svchost.exe]
                    FilePath : C:\WINDOWS\System32\
                    ProcessID : 1248
                    ThreadCreationTime : 26-06-2006 16:37:42
                    BasePriority : Normal
                    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 5.1.2600.2180
                    ProductName : Microsoft® Windows® Operating System
                    CompanyName : Microsoft Corporation
                    FileDescription : Generic Host Process for Win32 Services
                    InternalName : svchost.exe
                    LegalCopyright : © Microsoft Corporation. All rights reserved.
                    OriginalFilename : svchost.exe

                    #:11 [svchost.exe]
                    FilePath : C:\WINDOWS\System32\
                    ProcessID : 1320
                    ThreadCreationTime : 26-06-2006 16:37:42
                    BasePriority : Normal
                    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 5.1.2600.2180
                    ProductName : Microsoft® Windows® Operating System
                    CompanyName : Microsoft Corporation
                    FileDescription : Generic Host Process for Win32 Services
                    InternalName : svchost.exe
                    LegalCopyright : © Microsoft Corporation. All rights reserved.
                    OriginalFilename : svchost.exe

                    #:12 [spoolsv.exe]
                    FilePath : C:\WINDOWS\system32\
                    ProcessID : 1428
                    ThreadCreationTime : 26-06-2006 16:37:43
                    BasePriority : Normal
                    FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
                    ProductVersion : 5.1.2600.2696
                    ProductName : Microsoft® Windows® Operating System
                    CompanyName : Microsoft Corporation
                    FileDescription : Spooler SubSystem App
                    InternalName : spoolsv.exe
                    LegalCopyright : © Microsoft Corporation. All rights reserved.
                    OriginalFilename : spoolsv.exe

                    #:13 [lvprcsrv.exe]
                    FilePath : c:\program files\fichiers communs\logitech\lvmvfm\
                    ProcessID : 1464
                    ThreadCreationTime : 26-06-2006 16:37:43
                    BasePriority : Normal
                    FileVersion : 9.5.0.1098
                    ProductVersion : 9.5.0.1098
                    ProductName : Logitech QuickCam
                    CompanyName : Logitech Inc.
                    FileDescription : Logitech LVPrcSrv Module.
                    InternalName : LVPrcSrv.exe
                    LegalCopyright : (c) 1996-2006 Logitech. All rights reserved.
                    OriginalFilename : LVPrcSrv.exe

                    #:14 [ctsvccda.exe]
                    FilePath : C:\WINDOWS\system32\
                    ProcessID : 1540
                    ThreadCreationTime : 26-06-2006 16:37:43
                    BasePriority : Normal
                    FileVersion : 1.0.1.0
                    ProductVersion : 1.0.0.0
                    ProductName : Creative Service for CDROM Access
                    CompanyName : Creative Technology Ltd
                    FileDescription : Creative Service for CDROM Access
                    InternalName : CTsvcCDAEXE
                    LegalCopyright : Copyright (c) Creative Technology Ltd., 1999. All rights reserved.
                    OriginalFilename : CTsvcCDA.EXE

                    #:15 [mdm.exe]
                    FilePath : C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\
                    ProcessID : 1584
                    ThreadCreationTime : 26-06-2006 16:37:43
                    BasePriority : Normal
                    FileVersion : 7.00.9466
                    ProductVersion : 7.00.9466
                    ProductName : Microsoft® Visual Studio .NET
                    CompanyName : Microsoft Corporation
                    FileDescription : Machine Debug Manager
                    InternalName : mdm.exe
                    LegalCopyright : © Microsoft Corporation. All rights reserved.
                    OriginalFilename : mdm.exe

                    #:16 [nvsvc32.exe]
                    FilePath : C:\WINDOWS\system32\
                    ProcessID : 1620
                    ThreadCreationTime : 26-06-2006 16:37:43
                    BasePriority : Normal
                    FileVersion : 6.14.10.7184
                    ProductVersion : 6.14.10.7184
                    ProductName : NVIDIA Driver Helper Service, Version 71.84
                    CompanyName : NVIDIA Corporation
                    FileDescription : NVIDIA Driver Helper Service, Version 71.84
                    InternalName : NVSVC
                    LegalCopyright : (C) NVIDIA Corporation. All rights reserved.
                    OriginalFilename : nvsvc32.exe

                    #:17 [svchost.exe]
                    FilePath : C:\WINDOWS\System32\
                    ProcessID : 1704
                    ThreadCreationTime : 26-06-2006 16:37:43
                    BasePriority : Normal
                    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 5.1.2600.2180
                    ProductName : Microsoft® Windows® Operating System
                    CompanyName : Microsoft Corporation
                    FileDescription : Generic Host Process for Win32 Services
                    InternalName : svchost.exe
                    LegalCopyright : © Microsoft Corporation. All rights reserved.
                    OriginalFilename : svchost.exe

                    #:18 [wdfmgr.exe]
                    FilePath : C:\WINDOWS\system32\
                    ProcessID : 1724
                    ThreadCreationTime : 26-06-2006 16:37:43
                    BasePriority : Normal
                    FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act)
                    ProductVersion : 5.2.3790.1230
                    ProductName : Microsoft® Windows® Operating System
                    CompanyName : Microsoft Corporation
                    FileDescription : Windows User Mode Driver Manager
                    InternalName : WdfMgr
                    LegalCopyright : © Microsoft Corporation. All rights reserved.
                    OriginalFilename : WdfMgr.exe

                    #:19 [xcommsvr.exe]
                    FilePath : C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\
                    ProcessID : 1792
                    ThreadCreationTime : 26-06-2006 16:37:43
                    BasePriority : Normal
                    FileVersion : 1, 7, 0, 4
                    ProductVersion : 1, 7, 0, 4
                    ProductName : Softwin BitDefender Communicator Server
                    CompanyName : Softwin
                    FileDescription : BitDefender Communicator Server
                    InternalName : XCOMMSVR
                    LegalCopyright : Copyright © 2003-2004 Softwin
                    OriginalFilename : xcommsvr.exe
                    Comments : Manages communication between BitDefender components

                    #:20 [bdss.exe]
                    FilePath : C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\
                    ProcessID : 1844
                    ThreadCreationTime : 26-06-2006 16:37:43
                    BasePriority : Normal

                    #:21 [explorer.exe]
                    FilePath : C:\WINDOWS\
                    ProcessID : 292
                    ThreadCreationTime : 26-06-2006 16:37:46
                    BasePriority : Normal
                    FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 6.00.2900.2180
                    ProductName : Système d'exploitation Microsoft® Windows®
                    CompanyName : Microsoft Corporation
                    FileDescription : Explorateur Windows
                    InternalName : explorer
                    LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                    OriginalFilename : EXPLORER.EXE

                    #:22 [vsserv.exe]
                    FilePath : C:\Program Files\Softwin\BitDefender Professional Edition\
                    ProcessID : 440
                    ThreadCreationTime : 26-06-2006 16:37:46
                    BasePriority : Normal

                    #:23 [bdswitch.exe]
                    FilePath : C:\Program Files\Softwin\BitDefender Professional Edition\
                    ProcessID : 496
                    ThreadCreationTime : 26-06-2006 16:37:47
                    BasePriority : Normal

                    #:24 [lvcomsx.exe]
                    FilePath : C:\WINDOWS\system32\
                    ProcessID : 504
                    ThreadCreationTime : 26-06-2006 16:37:47
                    BasePriority : Normal
                    FileVersion : 9.5.0.1098
                    ProductVersion : 9.5.0.1098
                    ProductName : Logitech QuickCam
                    CompanyName : Logitech Inc.
                    FileDescription : LVCom Server
                    InternalName : LVComS.exe
                    LegalCopyright : (c) 1996-2006 Logitech. All rights reserved.
                    OriginalFilename : LVComS.exe

                    #:25 [realsched.exe]
                    FilePath : C:\Program Files\Fichiers communs\Real\Update_OB\
                    ProcessID : 520
                    ThreadCreationTime : 26-06-2006 16:37:47
                    BasePriority : Normal
                    FileVersion : 0.1.0.3510
                    ProductVersion : 0.1.0.3510
                    ProductName : RealPlayer (32-bit)
                    CompanyName : RealNetworks, Inc.
                    FileDescription : RealNetworks Scheduler
                    InternalName : schedapp
                    LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004
                    LegalTrademarks : RealAudio(tm) is a trademark of RealNetworks, Inc.
                    OriginalFilename : realsched.exe

                    #:26 [jusched.exe]
                    FilePath : C:\Program Files\Java\jre1.5.0_07\bin\
                    ProcessID : 528
                    ThreadCreationTime : 26-06-2006 16:37:47
                    BasePriority : Normal

                    #:27 [ctdetect.exe]
                    FilePath : D:\creativemediasource\Detector\
                    ProcessID : 576
                    ThreadCreationTime : 26-06-2006 16:37:47
                    BasePriority : Normal
                    FileVersion : 3.0.2.0
                    ProductVersion : 3.0.0.0
                    ProductName : Creative MediaSource Detector
                    CompanyName : Creative Technology Ltd
                    FileDescription : Creative MediaSource Detector
                    InternalName : CTDetect
                    LegalCopyright : Copyright (c) Creative Technology Ltd., 2003-2004. All rights reserved.
                    OriginalFilename : CTDetect.EXE

                    #:28 [ctfmon.exe]
                    FilePath : C:\WINDOWS\system32\
                    ProcessID : 584
                    ThreadCreationTime : 26-06-2006 16:37:47
                    BasePriority : Normal
                    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 5.1.2600.2180
                    ProductName : Microsoft® Windows® Operating System
                    CompanyName : Microsoft Corporation
                    FileDescription : CTF Loader
                    InternalName : CTFMON
                    LegalCopyright : © Microsoft Corporation. All rights reserved.
                    OriginalFilename : CTFMON.EXE

                    #:29 [alg.exe]
                    FilePath : C:\WINDOWS\System32\
                    ProcessID : 1460
                    ThreadCreationTime : 26-06-2006 16:37:52
                    BasePriority : Normal
                    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 5.1.2600.2180
                    ProductName : Microsoft® Windows® Operating System
                    CompanyName : Microsoft Corporation
                    FileDescription : Application Layer Gateway Service
                    InternalName : ALG.exe
                    LegalCopyright : © Microsoft Corporation. All rights reserved.
                    OriginalFilename : ALG.exe

                    #:30 [iexplore.exe]
                    FilePath : C:\Program Files\Internet Explorer\
                    ProcessID : 122856
                    ThreadCreationTime : 26-06-2006 16:59:52
                    BasePriority : Normal
                    FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 6.00.2900.2180
                    ProductName : Système d'exploitation Microsoft® Windows®
                    CompanyName : Microsoft Corporation
                    FileDescription : Internet Explorer
                    InternalName : iexplore
                    LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                    OriginalFilename : IEXPLORE.EXE

                    #:31 [encwcsvr.exe]
                    FilePath : C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\
                    ProcessID : 118868
                    ThreadCreationTime : 26-06-2006 16:59:53
                    BasePriority : Normal

                    #:32 [ad-aware.exe]
                    FilePath : D:\Ad-Aware SE Personal\
                    ProcessID : 123876
                    ThreadCreationTime : 26-06-2006 17:05:47
                    BasePriority : Normal
                    FileVersion : 6.2.0.236
                    ProductVersion : SE 106
                    ProductName : Lavasoft Ad-Aware SE
                    CompanyName : Lavasoft Sweden
                    FileDescription : Ad-Aware SE Core application
                    InternalName : Ad-Aware.exe
                    LegalCopyright : Copyright © Lavasoft AB Sweden
                    OriginalFilename : Ad-Aware.exe
                    Comments : All Rights Reserved

                    Memory scan result:
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    New critical objects: 0
                    Objects found so far: 0

                    Started registry scan
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    Registry Scan result:
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    New critical objects: 0
                    Objects found so far: 0

                    Started deep registry scan
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    Deep registry scan result:
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    New critical objects: 0
                    Objects found so far: 0

                    Started Tracking Cookie scan
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    Tracking Cookie Object Recognized!
                    Type : IECache Entry
                    Data : bibi@tribalfusion[1].txt
                    TAC Rating : 3
                    Category : Data Miner
                    Comment : Hits:1
                    Value : Cookie:bibi@tribalfusion.com/
                    Expires : 01-01-2038 02:00:00
                    LastSync : Hits:1
                    UseCount : 0
                    Hits : 1

                    Tracking cookie scan result:
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    New critical objects: 1
                    Objects found so far: 1

                    Deep scanning and examining files...
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    Disk Scan Result for C:\WINDOWS
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    New critical objects: 0
                    Objects found so far: 1

                    Disk Scan Result for C:\WINDOWS\system32
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    New critical objects: 0
                    Objects found so far: 1

                    Disk Scan Result for C:\DOCUME~1\bibi\LOCALS~1\Temp\
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    New critical objects: 0
                    Objects found so far: 1

                    Scanning Hosts file......
                    Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    Hosts file scan result:
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    1 entries scanned.
                    New critical objects:0
                    Objects found so far: 1

                    Performing conditional scans...
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    Conditional scan result:
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    New critical objects: 0
                    Objects found so far: 1

                    19:09:20 Scan Complete

                    Summary Of This Scan
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    Total scanning time:00:00:50.31
                    Objects scanned:82913
                    Objects identified:1
                    Objects ignored:0
                    New critical objects:1

                    2

                    SmitFraudFix v2.65

                    Rapport fait à 21:03:07,96, 26/06/2006
                    Executé à partir de O:\Apps\SmitfraudFix\SmitfraudFix
                    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                    Fix executé en mode normal

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\bibi\Application Data

                    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\bibi\Favoris

                    »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                    "Source"="About:Home"
                    "SubscribedURL"="About:Home"
                    "FriendlyName"="Ma page d'accueil"

                    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Fin

                    3

                    Logfile of HijackThis v1.99.1
                    Scan saved at 20:59:09, on 26/06/2006
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Ahead\InCD\InCDsrv.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                    C:\WINDOWS\system32\CTsvcCDA.EXE
                    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                    C:\WINDOWS\system32\nvsvc32.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
                    C:\Program Files\Softwin\BitDefender Professional Edition\bdswitch.exe
                    C:\WINDOWS\system32\LVCOMSX.EXE
                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                    C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
                    D:\creativemediasource\Detector\CTDetect.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
                    C:\Program Files\Softwin\BitDefender Professional Edition\vsserv.exe
                    c:\program files\softwin\bitdefender professional edition\bdmcon.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCSVR.EXE
                    C:\Documents and Settings\bibi\Bureau\HijackThis.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Spybot - Search & Destroy\SDHelper.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
                    O2 - BHO: BHO pour Compagnon Web Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                    O3 - Toolbar: Compagnon Web Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                    O4 - HKLM\..\Run: [BDMCon] C:\Program Files\Softwin\BitDefender Professional Edition\\bdmcon.exe
                    O4 - HKLM\..\Run: [BDNewsAgent] C:\Program Files\Softwin\BitDefender Professional Edition\\bdnagent.exe
                    O4 - HKLM\..\Run: [BDSwitchAgent] C:\Program Files\Softwin\BitDefender Professional Edition\bdswitch.exe
                    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
                    O4 - HKCU\..\Run: [Creative Detector] D:\creativemediasource\Detector\CTDetect.exe /R
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = D:\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\MICROS~1\OFFICE11\EXCEL.EXE/3000
                    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
                    O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                    O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/...
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{016254FB-FCA8-4DA4-9257-A19520F09586}: NameServer = 80.10.246.1 80.10.246.132
                    O17 - HKLM\System\CS1\Services\Tcpip\..\{016254FB-FCA8-4DA4-9257-A19520F09586}: NameServer = 80.10.246.1 80.10.246.132
                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
                    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
                    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                    O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\TuneUp Utilities 2006\WinStylerThemeSvc.exe
                    O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender Professional Edition\vsserv.exe" /service (file missing)
                    O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
                    0
                    1. Suite de ma petite histoire, j'ai fait les démarches qui étaient proposées, voici:

                      Premier le rapport de Adaware
                      Deuxième le rapport SmitFraudFix
                      En trois Hijackthis

                      J'ai essayé de faire un scanne en ligne, mais le pc plante a chaque fois, je ne comprends pas, si je fais un scanne local idem, je pense que je suis plomber, mais, je préfére attendre une réponse de votre part.

                      Merci de votre aide

                      1

                      Ad-Aware SE Build 1.06r1
                      Logfile Created on:lundi 26 juin 2006 19:08:30
                      Created with Ad-Aware SE Personal, free for private use.
                      Using definitions file:SE1R112 15.06.2006
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                      References detected during the scan:
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      Tracking Cookie(TAC index:3):1 total references
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                      Ad-Aware SE Settings
                      ===========================
                      Set : Search for negligible risk entries
                      Set : Safe mode (always request confirmation)
                      Set : Scan active processes
                      Set : Scan registry
                      Set : Deep-scan registry
                      Set : Scan my IE Favorites for banned URLs
                      Set : Scan my Hosts file

                      Extended Ad-Aware SE Settings
                      ===========================
                      Set : Unload recognized processes & modules during scan
                      Set : Scan registry for all users instead of current user only
                      Set : Always try to unload modules before deletion
                      Set : During removal, unload Explorer and IE if necessary
                      Set : Let Windows remove files in use at next reboot
                      Set : Delete quarantined objects after restoring
                      Set : Include basic Ad-Aware settings in log file
                      Set : Include additional Ad-Aware settings in log file
                      Set : Include reference summary in log file
                      Set : Include alternate data stream details in log file
                      Set : Play sound at scan completion if scan locates critical objects

                      26-06-2006 19:08:30 - Scan started. (Smart mode)

                      Listing running processes
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                      #:1 [smss.exe]
                      FilePath : \SystemRoot\System32\
                      ProcessID : 704
                      ThreadCreationTime : 26-06-2006 16:37:35
                      BasePriority : Normal

                      #:2 [csrss.exe]
                      FilePath : \??\C:\WINDOWS\system32\
                      ProcessID : 764
                      ThreadCreationTime : 26-06-2006 16:37:39
                      BasePriority : Normal

                      #:3 [winlogon.exe]
                      FilePath : \??\C:\WINDOWS\system32\
                      ProcessID : 788
                      ThreadCreationTime : 26-06-2006 16:37:40
                      BasePriority : High

                      #:4 [services.exe]
                      FilePath : C:\WINDOWS\system32\
                      ProcessID : 836
                      ThreadCreationTime : 26-06-2006 16:37:40
                      BasePriority : Normal
                      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 5.1.2600.2180
                      ProductName : Système d'exploitation Microsoft® Windows®
                      CompanyName : Microsoft Corporation
                      FileDescription : Applications Services et Contrôleur
                      InternalName : services.exe
                      LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                      OriginalFilename : services.exe

                      #:5 [lsass.exe]
                      FilePath : C:\WINDOWS\system32\
                      ProcessID : 848
                      ThreadCreationTime : 26-06-2006 16:37:40
                      BasePriority : Normal
                      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 5.1.2600.2180
                      ProductName : Microsoft® Windows® Operating System
                      CompanyName : Microsoft Corporation
                      FileDescription : LSA Shell (Export Version)
                      InternalName : lsass.exe
                      LegalCopyright : © Microsoft Corporation. All rights reserved.
                      OriginalFilename : lsass.exe

                      #:6 [svchost.exe]
                      FilePath : C:\WINDOWS\system32\
                      ProcessID : 992
                      ThreadCreationTime : 26-06-2006 16:37:40
                      BasePriority : Normal
                      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 5.1.2600.2180
                      ProductName : Microsoft® Windows® Operating System
                      CompanyName : Microsoft Corporation
                      FileDescription : Generic Host Process for Win32 Services
                      InternalName : svchost.exe
                      LegalCopyright : © Microsoft Corporation. All rights reserved.
                      OriginalFilename : svchost.exe

                      #:7 [svchost.exe]
                      FilePath : C:\WINDOWS\system32\
                      ProcessID : 1052
                      ThreadCreationTime : 26-06-2006 16:37:41
                      BasePriority : Normal
                      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 5.1.2600.2180
                      ProductName : Microsoft® Windows® Operating System
                      CompanyName : Microsoft Corporation
                      FileDescription : Generic Host Process for Win32 Services
                      InternalName : svchost.exe
                      LegalCopyright : © Microsoft Corporation. All rights reserved.
                      OriginalFilename : svchost.exe

                      #:8 [svchost.exe]
                      FilePath : C:\WINDOWS\System32\
                      ProcessID : 1092
                      ThreadCreationTime : 26-06-2006 16:37:41
                      BasePriority : Normal
                      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 5.1.2600.2180
                      ProductName : Microsoft® Windows® Operating System
                      CompanyName : Microsoft Corporation
                      FileDescription : Generic Host Process for Win32 Services
                      InternalName : svchost.exe
                      LegalCopyright : © Microsoft Corporation. All rights reserved.
                      OriginalFilename : svchost.exe

                      #:9 [incdsrv.exe]
                      FilePath : C:\Program Files\Ahead\InCD\
                      ProcessID : 1112
                      ThreadCreationTime : 26-06-2006 16:37:41
                      BasePriority : Normal
                      FileVersion : 4, 3, 23, 2
                      ProductVersion : 4, 3, 23, 2
                      ProductName : Nero AG incdsrv
                      CompanyName : Nero AG
                      FileDescription : incdsrv
                      InternalName : incdsrv
                      LegalCopyright : Copyright 1995-2006 Nero AG and its licensors. All Rights Reserved.
                      LegalTrademarks : InCD is a trademark of Nero AG
                      OriginalFilename : incdsrv.exe

                      #:10 [svchost.exe]
                      FilePath : C:\WINDOWS\System32\
                      ProcessID : 1248
                      ThreadCreationTime : 26-06-2006 16:37:42
                      BasePriority : Normal
                      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 5.1.2600.2180
                      ProductName : Microsoft® Windows® Operating System
                      CompanyName : Microsoft Corporation
                      FileDescription : Generic Host Process for Win32 Services
                      InternalName : svchost.exe
                      LegalCopyright : © Microsoft Corporation. All rights reserved.
                      OriginalFilename : svchost.exe

                      #:11 [svchost.exe]
                      FilePath : C:\WINDOWS\System32\
                      ProcessID : 1320
                      ThreadCreationTime : 26-06-2006 16:37:42
                      BasePriority : Normal
                      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 5.1.2600.2180
                      ProductName : Microsoft® Windows® Operating System
                      CompanyName : Microsoft Corporation
                      FileDescription : Generic Host Process for Win32 Services
                      InternalName : svchost.exe
                      LegalCopyright : © Microsoft Corporation. All rights reserved.
                      OriginalFilename : svchost.exe

                      #:12 [spoolsv.exe]
                      FilePath : C:\WINDOWS\system32\
                      ProcessID : 1428
                      ThreadCreationTime : 26-06-2006 16:37:43
                      BasePriority : Normal
                      FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
                      ProductVersion : 5.1.2600.2696
                      ProductName : Microsoft® Windows® Operating System
                      CompanyName : Microsoft Corporation
                      FileDescription : Spooler SubSystem App
                      InternalName : spoolsv.exe
                      LegalCopyright : © Microsoft Corporation. All rights reserved.
                      OriginalFilename : spoolsv.exe

                      #:13 [lvprcsrv.exe]
                      FilePath : c:\program files\fichiers communs\logitech\lvmvfm\
                      ProcessID : 1464
                      ThreadCreationTime : 26-06-2006 16:37:43
                      BasePriority : Normal
                      FileVersion : 9.5.0.1098
                      ProductVersion : 9.5.0.1098
                      ProductName : Logitech QuickCam
                      CompanyName : Logitech Inc.
                      FileDescription : Logitech LVPrcSrv Module.
                      InternalName : LVPrcSrv.exe
                      LegalCopyright : (c) 1996-2006 Logitech. All rights reserved.
                      OriginalFilename : LVPrcSrv.exe

                      #:14 [ctsvccda.exe]
                      FilePath : C:\WINDOWS\system32\
                      ProcessID : 1540
                      ThreadCreationTime : 26-06-2006 16:37:43
                      BasePriority : Normal
                      FileVersion : 1.0.1.0
                      ProductVersion : 1.0.0.0
                      ProductName : Creative Service for CDROM Access
                      CompanyName : Creative Technology Ltd
                      FileDescription : Creative Service for CDROM Access
                      InternalName : CTsvcCDAEXE
                      LegalCopyright : Copyright (c) Creative Technology Ltd., 1999. All rights reserved.
                      OriginalFilename : CTsvcCDA.EXE

                      #:15 [mdm.exe]
                      FilePath : C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\
                      ProcessID : 1584
                      ThreadCreationTime : 26-06-2006 16:37:43
                      BasePriority : Normal
                      FileVersion : 7.00.9466
                      ProductVersion : 7.00.9466
                      ProductName : Microsoft® Visual Studio .NET
                      CompanyName : Microsoft Corporation
                      FileDescription : Machine Debug Manager
                      InternalName : mdm.exe
                      LegalCopyright : © Microsoft Corporation. All rights reserved.
                      OriginalFilename : mdm.exe

                      #:16 [nvsvc32.exe]
                      FilePath : C:\WINDOWS\system32\
                      ProcessID : 1620
                      ThreadCreationTime : 26-06-2006 16:37:43
                      BasePriority : Normal
                      FileVersion : 6.14.10.7184
                      ProductVersion : 6.14.10.7184
                      ProductName : NVIDIA Driver Helper Service, Version 71.84
                      CompanyName : NVIDIA Corporation
                      FileDescription : NVIDIA Driver Helper Service, Version 71.84
                      InternalName : NVSVC
                      LegalCopyright : (C) NVIDIA Corporation. All rights reserved.
                      OriginalFilename : nvsvc32.exe

                      #:17 [svchost.exe]
                      FilePath : C:\WINDOWS\System32\
                      ProcessID : 1704
                      ThreadCreationTime : 26-06-2006 16:37:43
                      BasePriority : Normal
                      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 5.1.2600.2180
                      ProductName : Microsoft® Windows® Operating System
                      CompanyName : Microsoft Corporation
                      FileDescription : Generic Host Process for Win32 Services
                      InternalName : svchost.exe
                      LegalCopyright : © Microsoft Corporation. All rights reserved.
                      OriginalFilename : svchost.exe

                      #:18 [wdfmgr.exe]
                      FilePath : C:\WINDOWS\system32\
                      ProcessID : 1724
                      ThreadCreationTime : 26-06-2006 16:37:43
                      BasePriority : Normal
                      FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act)
                      ProductVersion : 5.2.3790.1230
                      ProductName : Microsoft® Windows® Operating System
                      CompanyName : Microsoft Corporation
                      FileDescription : Windows User Mode Driver Manager
                      InternalName : WdfMgr
                      LegalCopyright : © Microsoft Corporation. All rights reserved.
                      OriginalFilename : WdfMgr.exe

                      #:19 [xcommsvr.exe]
                      FilePath : C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\
                      ProcessID : 1792
                      ThreadCreationTime : 26-06-2006 16:37:43
                      BasePriority : Normal
                      FileVersion : 1, 7, 0, 4
                      ProductVersion : 1, 7, 0, 4
                      ProductName : Softwin BitDefender Communicator Server
                      CompanyName : Softwin
                      FileDescription : BitDefender Communicator Server
                      InternalName : XCOMMSVR
                      LegalCopyright : Copyright © 2003-2004 Softwin
                      OriginalFilename : xcommsvr.exe
                      Comments : Manages communication between BitDefender components

                      #:20 [bdss.exe]
                      FilePath : C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\
                      ProcessID : 1844
                      ThreadCreationTime : 26-06-2006 16:37:43
                      BasePriority : Normal

                      #:21 [explorer.exe]
                      FilePath : C:\WINDOWS\
                      ProcessID : 292
                      ThreadCreationTime : 26-06-2006 16:37:46
                      BasePriority : Normal
                      FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 6.00.2900.2180
                      ProductName : Système d'exploitation Microsoft® Windows®
                      CompanyName : Microsoft Corporation
                      FileDescription : Explorateur Windows
                      InternalName : explorer
                      LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                      OriginalFilename : EXPLORER.EXE

                      #:22 [vsserv.exe]
                      FilePath : C:\Program Files\Softwin\BitDefender Professional Edition\
                      ProcessID : 440
                      ThreadCreationTime : 26-06-2006 16:37:46
                      BasePriority : Normal

                      #:23 [bdswitch.exe]
                      FilePath : C:\Program Files\Softwin\BitDefender Professional Edition\
                      ProcessID : 496
                      ThreadCreationTime : 26-06-2006 16:37:47
                      BasePriority : Normal

                      #:24 [lvcomsx.exe]
                      FilePath : C:\WINDOWS\system32\
                      ProcessID : 504
                      ThreadCreationTime : 26-06-2006 16:37:47
                      BasePriority : Normal
                      FileVersion : 9.5.0.1098
                      ProductVersion : 9.5.0.1098
                      ProductName : Logitech QuickCam
                      CompanyName : Logitech Inc.
                      FileDescription : LVCom Server
                      InternalName : LVComS.exe
                      LegalCopyright : (c) 1996-2006 Logitech. All rights reserved.
                      OriginalFilename : LVComS.exe

                      #:25 [realsched.exe]
                      FilePath : C:\Program Files\Fichiers communs\Real\Update_OB\
                      ProcessID : 520
                      ThreadCreationTime : 26-06-2006 16:37:47
                      BasePriority : Normal
                      FileVersion : 0.1.0.3510
                      ProductVersion : 0.1.0.3510
                      ProductName : RealPlayer (32-bit)
                      CompanyName : RealNetworks, Inc.
                      FileDescription : RealNetworks Scheduler
                      InternalName : schedapp
                      LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004
                      LegalTrademarks : RealAudio(tm) is a trademark of RealNetworks, Inc.
                      OriginalFilename : realsched.exe

                      #:26 [jusched.exe]
                      FilePath : C:\Program Files\Java\jre1.5.0_07\bin\
                      ProcessID : 528
                      ThreadCreationTime : 26-06-2006 16:37:47
                      BasePriority : Normal

                      #:27 [ctdetect.exe]
                      FilePath : D:\creativemediasource\Detector\
                      ProcessID : 576
                      ThreadCreationTime : 26-06-2006 16:37:47
                      BasePriority : Normal
                      FileVersion : 3.0.2.0
                      ProductVersion : 3.0.0.0
                      ProductName : Creative MediaSource Detector
                      CompanyName : Creative Technology Ltd
                      FileDescription : Creative MediaSource Detector
                      InternalName : CTDetect
                      LegalCopyright : Copyright (c) Creative Technology Ltd., 2003-2004. All rights reserved.
                      OriginalFilename : CTDetect.EXE

                      #:28 [ctfmon.exe]
                      FilePath : C:\WINDOWS\system32\
                      ProcessID : 584
                      ThreadCreationTime : 26-06-2006 16:37:47
                      BasePriority : Normal
                      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 5.1.2600.2180
                      ProductName : Microsoft® Windows® Operating System
                      CompanyName : Microsoft Corporation
                      FileDescription : CTF Loader
                      InternalName : CTFMON
                      LegalCopyright : © Microsoft Corporation. All rights reserved.
                      OriginalFilename : CTFMON.EXE

                      #:29 [alg.exe]
                      FilePath : C:\WINDOWS\System32\
                      ProcessID : 1460
                      ThreadCreationTime : 26-06-2006 16:37:52
                      BasePriority : Normal
                      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 5.1.2600.2180
                      ProductName : Microsoft® Windows® Operating System
                      CompanyName : Microsoft Corporation
                      FileDescription : Application Layer Gateway Service
                      InternalName : ALG.exe
                      LegalCopyright : © Microsoft Corporation. All rights reserved.
                      OriginalFilename : ALG.exe

                      #:30 [iexplore.exe]
                      FilePath : C:\Program Files\Internet Explorer\
                      ProcessID : 122856
                      ThreadCreationTime : 26-06-2006 16:59:52
                      BasePriority : Normal
                      FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 6.00.2900.2180
                      ProductName : Système d'exploitation Microsoft® Windows®
                      CompanyName : Microsoft Corporation
                      FileDescription : Internet Explorer
                      InternalName : iexplore
                      LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                      OriginalFilename : IEXPLORE.EXE

                      #:31 [encwcsvr.exe]
                      FilePath : C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\
                      ProcessID : 118868
                      ThreadCreationTime : 26-06-2006 16:59:53
                      BasePriority : Normal

                      #:32 [ad-aware.exe]
                      FilePath : D:\Ad-Aware SE Personal\
                      ProcessID : 123876
                      ThreadCreationTime : 26-06-2006 17:05:47
                      BasePriority : Normal
                      FileVersion : 6.2.0.236
                      ProductVersion : SE 106
                      ProductName : Lavasoft Ad-Aware SE
                      CompanyName : Lavasoft Sweden
                      FileDescription : Ad-Aware SE Core application
                      InternalName : Ad-Aware.exe
                      LegalCopyright : Copyright © Lavasoft AB Sweden
                      OriginalFilename : Ad-Aware.exe
                      Comments : All Rights Reserved

                      Memory scan result:
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      New critical objects: 0
                      Objects found so far: 0

                      Started registry scan
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                      Registry Scan result:
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      New critical objects: 0
                      Objects found so far: 0

                      Started deep registry scan
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                      Deep registry scan result:
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      New critical objects: 0
                      Objects found so far: 0

                      Started Tracking Cookie scan
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                      Tracking Cookie Object Recognized!
                      Type : IECache Entry
                      Data : bibi@tribalfusion[1].txt
                      TAC Rating : 3
                      Category : Data Miner
                      Comment : Hits:1
                      Value : Cookie:bibi@tribalfusion.com/
                      Expires : 01-01-2038 02:00:00
                      LastSync : Hits:1
                      UseCount : 0
                      Hits : 1

                      Tracking cookie scan result:
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      New critical objects: 1
                      Objects found so far: 1

                      Deep scanning and examining files...
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                      Disk Scan Result for C:\WINDOWS
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      New critical objects: 0
                      Objects found so far: 1

                      Disk Scan Result for C:\WINDOWS\system32
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      New critical objects: 0
                      Objects found so far: 1

                      Disk Scan Result for C:\DOCUME~1\bibi\LOCALS~1\Temp\
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      New critical objects: 0
                      Objects found so far: 1

                      Scanning Hosts file......
                      Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                      Hosts file scan result:
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      1 entries scanned.
                      New critical objects:0
                      Objects found so far: 1

                      Performing conditional scans...
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                      Conditional scan result:
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      New critical objects: 0
                      Objects found so far: 1

                      19:09:20 Scan Complete

                      Summary Of This Scan
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      Total scanning time:00:00:50.31
                      Objects scanned:82913
                      Objects identified:1
                      Objects ignored:0
                      New critical objects:1

                      2

                      SmitFraudFix v2.65

                      Rapport fait à 21:03:07,96, 26/06/2006
                      Executé à partir de O:\Apps\SmitfraudFix\SmitfraudFix
                      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                      Fix executé en mode normal

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\bibi\Application Data

                      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\bibi\Favoris

                      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                      "Source"="About:Home"
                      "SubscribedURL"="About:Home"
                      "FriendlyName"="Ma page d'accueil"

                      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                      »»»»»»»»»»»»»»»»»»»»»»»» Fin

                      3

                      Logfile of HijackThis v1.99.1
                      Scan saved at 20:59:09, on 26/06/2006
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Ahead\InCD\InCDsrv.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                      C:\WINDOWS\system32\CTsvcCDA.EXE
                      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
                      C:\Program Files\Softwin\BitDefender Professional Edition\bdswitch.exe
                      C:\WINDOWS\system32\LVCOMSX.EXE
                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                      C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
                      D:\creativemediasource\Detector\CTDetect.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
                      C:\Program Files\Softwin\BitDefender Professional Edition\vsserv.exe
                      c:\program files\softwin\bitdefender professional edition\bdmcon.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCSVR.EXE
                      C:\Documents and Settings\bibi\Bureau\HijackThis.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Spybot - Search & Destroy\SDHelper.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
                      O2 - BHO: BHO pour Compagnon Web Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                      O3 - Toolbar: Compagnon Web Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                      O4 - HKLM\..\Run: [BDMCon] C:\Program Files\Softwin\BitDefender Professional Edition\\bdmcon.exe
                      O4 - HKLM\..\Run: [BDNewsAgent] C:\Program Files\Softwin\BitDefender Professional Edition\\bdnagent.exe
                      O4 - HKLM\..\Run: [BDSwitchAgent] C:\Program Files\Softwin\BitDefender Professional Edition\bdswitch.exe
                      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
                      O4 - HKCU\..\Run: [Creative Detector] D:\creativemediasource\Detector\CTDetect.exe /R
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = D:\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                      O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                      O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                      O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                      O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\MICROS~1\OFFICE11\EXCEL.EXE/3000
                      O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                      O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
                      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                      O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/...
                      O17 - HKLM\System\CCS\Services\Tcpip\..\{016254FB-FCA8-4DA4-9257-A19520F09586}: NameServer = 80.10.246.1 80.10.246.132
                      O17 - HKLM\System\CS1\Services\Tcpip\..\{016254FB-FCA8-4DA4-9257-A19520F09586}: NameServer = 80.10.246.1 80.10.246.132
                      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                      O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
                      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
                      O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                      O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\TuneUp Utilities 2006\WinStylerThemeSvc.exe
                      O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender Professional Edition\vsserv.exe" /service (file missing)
                      O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
                      0
                      1. Salut,

                        Peut-être commencer par la case départ ::

                        Télécharge et colle les 2 rapports dans l’ordre

                        A - ad-aware version 1.06
                        (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite
                        voir demo
                        http://pageperso.aol.fr/balltrap34/adwseflash.zip

                        B - spybot version 1.4
                        (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite
                        voir demo d utilisation
                        http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

                        C - Ccleaner : ( nettoyeur de registre, cookies+temps+tempos+prefetch+historique+etc..)
                        Télécharge ici :
                        https://www.ccleaner.com/ccleaner/download
                        Tutorial ici:
                        https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

                        =======================================

                        D - Ewido (download)- gratuit même après 14 jours d’essai
                        http://perso.wanadoo.fr/entraide-hijackthis/Ewido/
                        Copie/COLLE le rapport généré sur ce forum
                        Pour certaines versions de Windows antérieures à XP, Ewido peut ne pas être compatible
                        Dans ce cas, il te faudra utiliser a-squared free et demander une clef pour son usage gratuit
                        https://www.emsisoft.com/fr/

                        E - Scan online avec BitDefender (fonctionne uniquement sous Internet Explorer en acceptant l’ activX)
                        https://assiste.com/404_La_page_demandee_n_existe_pas.php
                        http://www.bitdefender.fr/scan8/ie.html
                        Copie/COLLE le rapport entier


                        ENSUITE :


                        Smitfraudfix

                        1°/ - Télécharge le logiciel SmitfraudFix ((crée par S!Ri J)
                        http://siri.urz.free.fr/Fix/SmitfraudFix.zip et décompresse le.

                        - Ouvre le dossier "SmitfraudFix" qui sera apparu, double clic sur "Smitfraudfix.cmd", choisis l’option 1, un log va être généré…

                        Tutorial imagée à lire :
                        http://siri.urz.free.fr/Fix/SmitfraudFix.php

                        Copie-COLLE ce dernier dans un message sur le forum.


                        ENSUITE

                        2°/ - Démarre en mode sans échec :

                        Pour cela, tu tapotes la touche F8 dès le début de l’allumage du PC sans t’arrêter
                        Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape ‘Entrée’ sur ton clavier.

                        Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres, c’est normal !
                        (Si F8 ne marche pas utilise la touche F5).

                        3°/ - Relance le programme Smitfraud,
                        Cette fois choisit l’option 2, répond OUI à tout ;
                        Sauvegarde le rapport, redémarre en mode normal,
                        Copie-COLLE le rapport sauvegardé sur le forum.

                        Bon courage
                        A++

                        0