Bonjour, 
ai suivi à la lettre le mode opératoire de nettoyage pc en 4 phases (démarrage en mode sans echec, lancement antivir, redémarrage en mode normal puis lancement hijackthis. 
je colle ci-dessous le rapport . Merci de votre aide!  
====================================== 
Logfile of HijackThis v1.99.1 
Scan saved at 09:19:26, on 29/11/2006 
Platform: Windows 2000 SP4 (WinNT 5.00.2195) 
MSIE: Internet Explorer v5.00 (5.00.2920.0000) 
  
Running processes: 
C:\WINNT\System32\smss.exe 
C:\WINNT\system32\winlogon.exe 
C:\WINNT\system32\services.exe 
C:\WINNT\system32\lsass.exe 
C:\WINNT\system32\Ati2evxx.exe 
C:\WINNT\system32\svchost.exe 
C:\WINNT\system32\ZoneLabs\vsmon.exe 
C:\WINNT\system32\spoolsv.exe 
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe 
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe 
C:\PROGRA~1\AVGFRE~1\avgamsvr.exe 
C:\PROGRA~1\AVGFRE~1\avgupsvc.exe 
C:\PROGRA~1\AVGFRE~1\avgemc.exe 
C:\WINNT\system32\drivers\CDAC11BA.EXE 
C:\WINNT\System32\cisvc.exe 
C:\WINNT\System32\svchost.exe 
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe 
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe 
C:\PROGRA~1\EFFICI~1\ENTERN~1\app\pppoeservice.exe 
C:\WINNT\system32\regsvc.exe 
C:\WINNT\system32\MSTask.exe 
C:\WINNT\System32\tcpsvcs.exe 
C:\WINNT\System32\snmp.exe 
C:\WINNT\system32\stisvc.exe 
C:\WINNT\System32\WBEM\WinMgmt.exe 
C:\WINNT\system32\svchost.exe 
C:\WINNT\system32\Ati2evxx.exe 
C:\WINNT\Explorer.EXE 
C:\WINNT\System32\cidaemon.exe 
C:\Program Files\Brain Codec\isamonitor.exe 
C:\Program Files\Brain Codec\pmsngr.exe 
C:\Program Files\Brain Codec\isamini.exe 
C:\Program Files\Brain Codec\pmmon.exe 
C:\Program Files\Alcohol Soft\Alcohol 120\Alcohol.exe 
C:\PROGRA~1\AVGFRE~1\avgcc.exe 
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE 
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe 
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe 
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe 
C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe 
C:\Program Files\QuickTime\qttask.exe 
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe 
C:\WINNT\system32\internat.exe 
C:\WINNT\system32\NOTEPAD.EXE 
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe 
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe 
C:\PROGRA~1\AVGFRE~1\avgwb.dat 
C:\Program Files\Hijackthis\HijackThis.exe 
C:\WINNT\system32\ZoneLabs\UpdClient.exe 
  
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com/ 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.netissimo.tm.fr 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fourni par  
  
Netissimo 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens 
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat  
  
5.0\Reader\ActiveX\AcroIEHelper.ocx 
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program  
  
files\google\googletoolbar2.dll 
O2 - BHO: (no name) - {ae18da4e-be15-4925-81bb-890c04af0200} - C:\Program Files\Brain Codec\isaddon.dll 
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} -  
  
C:\WINNT\system32\msdxm.ocx 
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll 
O3 - Toolbar: Protection Bar - {96ebbe6a-2864-4345-b32b-26ee9be524b5} - C:\Program Files\Brain  
  
Codec\iesplugin.dll 
O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon 
O4 - HKLM\..\Run: [updReg] C:\WINNT\UpdReg.EXE 
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" 
O4 - HKLM\..\Run: [Alcohol.exe Autorun] C:\Program Files\Alcohol Soft\Alcohol 120\Alcohol.exe /startup 
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\AVGFRE~1\avgcc.exe /STARTUP 
O4 - HKLM\..\Run: [shStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE 
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common  
  
Framework\UpdaterUI.exe" /StartedFromRunKey 
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" 
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay 
O4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI  
  
HYDRAVISION\HydraDM.exe 
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime 
O4 - HKLM\..\Run: [h3yb0y] C:\WINDOWS\SYSTEM32\DRIVERS\awf\LSASS.exe  
  
C:\WINDOWS\SYSTEM32\DRIVERS\awf\service.exe C:\WINDOWS\SYSTEM32\DRIVERS\awf\conf.dll 
O4 - HKLM\..\Run: [h3yb0y1] C:\WINDOWS\SYSTEM32\DRIVERS\awf\LSASS.exe  
  
C:\WINDOWS\SYSTEM32\DRIVERS\awf\system.exe C:\WINDOWS\SYSTEM32\DRIVERS\awf\serv-u.ini 
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min 
O4 - HKCU\..\Run: [internat.exe] internat.exe 
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program  
  
files\google\GoogleToolbar2.dll/cmwordtrans.html 
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html 
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html 
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html 
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program  
  
files\google\GoogleToolbar2.dll/cmcache.html 
O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe 
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program  
  
Files\ICQLite\ICQLite.exe 
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm 
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -  
  
C:\WINNT\web\related.htm 
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program  
  
Files\IrfanView\Ebay\Ebay.htm 
O14 - IERESET.INF: START_PAGE_URL=http://www.netissimo.tm.fr 
O16 - DPF: Interface Chat Voila - http://chat7.x-echo.com/version5/Applet/vchatsign.cab 
O16 - DPF: teleir_cert - https://static.ir.dgi.minefi.gouv.fr/secure...teleir_cert.cab 
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -  
  
http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab 
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -  
  
http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab 
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -  
  
http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab 
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -  
  
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.3.102.cab 
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} -  
  
http://installs.hotbar.com/installs/hbtool...SG2/hbtools.cab 
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -  
  
http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab 
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -  
  
http://messenger.msn.com/download/msnmesse...pdownloader.cab 
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) -  
  
http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab 
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -  
  
http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab 
O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) -  
  
http://f012.mail.caramail.lycos.fr/app/upl...ileUploader.cab 
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -  
  
http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab 
O21 - SSODL: emptins - {588599f4-de26-4c28-ba14-f4eb17e33481} - C:\WINNT\system32\xxfgmy.dll 
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program  
  
Files\AntiVir PersonalEdition Classic\sched.exe 
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir  
  
PersonalEdition Classic\avguard.exe 
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe 
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe 
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\AVGFRE~1\avgamsvr.exe 
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\AVGFRE~1\avgupsvc.exe 
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\AVGFRE~1\avgemc.exe 
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\system32\drivers\CDAC11BA.EXE 
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. -  
  
C:\WINNT\System32\dmadmin.exe 
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers  
  
communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe 
O23 - Service: Service Framework McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program  
  
Files\Network Associates\Common Framework\FrameworkService.exe 
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network  
  
Associates\VirusScan\Mcshield.exe 
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program  
  
Files\Network Associates\VirusScan\VsTskMgr.exe 
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner -  
  
C:\PROGRA~1\EFFICI~1\ENTERN~1\app\pppoeservice.exe 
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra  
  
Pro Home 2007\Win32\RpcDataSrv.exe 
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Pro  
  
Home 2007\RpcSandraSrv.exe 
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe