Ralentissement ordi

Bonjour,

Je suis sur Vista. Depuis quelques semaines, mon ordi se bloque par intermittence très régulièrement.
J'ai vidé tous mes fichiers temporaires, défragmenté l'ordi mais rien de change.

J'ai regardé les processus dans le gestionnaire des taches mais je ne détecte pas de processus suspect.
Dans tous les cas, les moments d'interruption correspondent à des pics de mémoire sur l'affichage Performances.

Je ne sais pas quoi faire. Merci beaucoup si vous pouvez m'éclairer
:)
Configuration: Windows Vista
Firefox 3.0.8

9 réponses

  1. telechage hickthis & fais un scan puis poste le rapport
    0
    1. Merci pour cette réactivité
      Voici le rapport:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 16:08:47, on 06/04/2009
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16809)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
      C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\Nero\Nero 7\InCD\InCD.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\ASUS\ATK Media\DMedia.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAANOTIF.EXE
      C:\Windows\System32\rundll32.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\ASUS\ASUS Live Update\ALU.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\PowerForPhone\PowerForPhone.exe
      C:\Windows\ASScrPro.exe
      C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
      C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\PDFCreator\PDFCreator.exe
      C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
      C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\Infineon\Security Platform Software\PSDrt.exe
      C:\Program Files\Infineon\Security Platform Software\SpTna.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Windows\system32\wuauclt.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Windows\system32\Taskmgr.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.asus.com/fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      O1 - Hosts: ::1 localhost
      O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
      O2 - BHO: ASUS Security Protect Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [Skytel] Skytel.exe
      O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
      O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
      O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone.exe
      O4 - HKLM\..\Run: [IFXSPMGT] C:\Windows\system32\ifxspmgt.exe /NotifyLogon
      O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
      O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
      O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll,RegisterModule
      O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: PDFCreator.lnk = C:\Program Files\PDFCreator\PDFCreator.exe
      O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
      O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
      O13 - Gopher Prefix:
      O16 - DPF: {C72A0388-1423-4B8D-87B9-A92A29752772} (Perspectix P'X5 Configurator (vUSM)) - https://www.usmshop.com/vusm/plugin/plugin/npvusm-5.0.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O20 - AppInit_DLLs: APSHook.dll
      O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
      O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
      O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
      O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Windows\system32\ifxspmgt.exe
      O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Windows\system32\ifxtcs.exe
      O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
      O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
      O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
      O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
      O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Windows\system32\IfxPsdSv.exe
      O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
      O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe
      0
  2. c quoi ton antivirus c'est bien avast parce que l'a il reste une trace de symantec ( norton )

    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe­

    supprime tout ca 'cest a dire la clé du registre + desinstalle avast & mais antivir ou avg antivirs free( avg a 1 anti spyware ... antivirus...) je te conseillerai avg free antivirus

    telecharge malware byte's fais la mise a jour puis fais un scan complet
    0
    1. & enleve tout les trucs de symantecs il est vraiment nul c'est une grosse passoire avast familliale aussi

      prend avg free
      0
      1. Contributeur sécurité
        slt

        sur un prdi un seul antivirus

        pour virer avast

        https://www.avast.com/fr-fr/uninstall-utility

        pour virer norton

        http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924
        0
        1. Merci
          Voici le résultat du scan.

          Malwarebytes' Anti-Malware 1.35
          Version de la base de données: 1945
          Windows 6.0.6000

          07/04/2009 08:23:14
          mbam-log-2009-04-07 (08-23-13).txt

          Type de recherche: Examen complet (C:\|D:\|E:\|)
          Eléments examinés: 189277
          Temps écoulé: 5 hour(s), 25 minute(s), 29 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 0
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 0

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Apparemment rien. Pourtant les ralentissements continuent...
          0
      2. Contributeur sécurité
        tu as viré un des antivirus?

        tu peux faire DR web

        puis

        Télécharge ici :

        http://images.malwareremoval.com/random/RSIT.exe

        random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

        Double-clique sur RSIT.exe afin de lancer RSIT.

        Clique Continue à l'écran Disclaimer.

        Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

        Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

        Poste le contenu de log.txt (<<qui sera affiché)
        ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

        NB : Les rapports sont sauvegardés dans le dossier C:\rsit
        0
        1. bonjour

          J'ai fait tout ce que vous m'avez conseillé.
          Le DR Web n'a rien detecté même en analyse complète.

          Voici suite au RSIT (qui semble avoir un peu foiré sur la fin?) le info.txt (je mets le log.txt dans le message suivant):

          <ital>info.txt logfile of random's system information tool 1.06 2009-04-08 10:08:03

          ======Uninstall list======

          -->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
          -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
          -->C:\Windows\NuNInst.exe /UNINSTALL
          -->C:\Windows\UNNeroBackItUp.exe /UNINSTALL
          -->C:\Windows\UNRecode.exe /UNINSTALL
          -->MsiExec.exe /I{977FBE6C-AE9A-4429-B249-814F0B3A4CB1}
          -->MsiExec.exe /I{9A346205-EA92-4406-B1AB-50379DA3F057}
          32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
          Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{623D32E9-0C62-4453-AD44-98B31F52A5E1}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
          Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
          Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{BB65C393-C76E-4F06-9B0C-2124AA8AF97B}
          Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
          Adobe Flash Player Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
          Adobe Photoshop CS-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}\setup.exe" -l0x40c
          Adobe Reader 8.1.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
          Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
          Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
          Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
          ASUS InstantFun-->MsiExec.exe /I{57B15AD4-8C9D-4164-82BB-E33D8644E757}
          ASUS Live Update-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}\setup.exe" -l0x9
          ASUS Security Protect Manager-->rundll32.exe "C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\SetupHelper.dll",ExecMain /Uninstall {D8D4AF9A-6ADE-4B14-A7F5-BA858792729E}
          ASUS Splendid Video Enhancement Technology-->C:\Program Files\InstallShield Installation Information\{C0FC1C14-4824-4A73-87A6-9E888C9C3102}\SETUP.exe -runfromtemp -l0x0009 -removeonly
          Asus_Camera_ScreenSaver-->"C:\Windows\ASUS Camera ScreenSaver Uninstaller.exe"
          ATK Generic Function Service-->C:\Program Files\InstallShield Installation Information\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}\SETUP.exe -runfromtemp -l0x0009 -removeonly
          ATK Hotkey-->C:\Program Files\InstallShield Installation Information\{3912D529-02BC-4CA8-B5ED-0D0C20EB6003}\SETUP.exe -runfromtemp -l0x0009 -removeonly
          ATK Media-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{139B0FFA-187E-4BA1-BCA6-6B56B2B6AB8C}\SETUP.EXE" -l0x9
          ATKOSD2-->C:\Program Files\InstallShield Installation Information\{5C1DB4ED-E9B4-402D-BB14-D75D97D6C1A6}\SETUP.exe -runfromtemp -l0x0009 -removeonly
          AuthenTec Fingerprint Sensor Minimum Install-->MsiExec.exe /I{9BAF043B-82FC-43E2-96EA-5F68015F4FA2}
          AutoCAD 2008 - Français-->C:\Program Files\AutoCAD 2008\Setup\Setup.exe /P {5783F2D7-6001-040C-0002-0060B0CE6BBA} /M ACAD
          Autodesk 3ds Max 8-->MsiExec.exe /I{DBB313D6-4B13-4961-BD5F-673CDA1793CC}
          Autodesk DWF Viewer 7-->MsiExec.exe /I{9A346205-EA92-4406-B1AB-50379DA3F057}
          AVG 8.5-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
          Backburner-->MsiExec.exe /I{3D347E6D-5A03-4342-B5BA-6A771885F379}
          Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
          Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
          HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
          HP Customer Participation Program 9.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
          HP Imaging Device Functions 9.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
          HP Officejet Pro K8600 Series-->C:\Program Files\HP\Digital Imaging\{69B078F7-E057-4488-AE6B-CB7BBEEE8DA6}\setup\hpzscr01.exe -datfile hpwscr11.dat -forcereboot
          HP Smart Web Printing-->MsiExec.exe /X{415CDA53-9100-476F-A7B2-476691E117C7}
          HP Solution Center 9.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
          HP Update-->MsiExec.exe /X{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}
          HPSSupply-->MsiExec.exe /X{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}
          Infineon TPM Professional Package-->MsiExec.exe /I{D104C1CF-7C12-4D32-9850-DDC99060DE5B}
          Intel(R) PROSet/Wireless Software-->C:\Windows\Installer\iProInst.exe
          Intel® Turbo Memory and Intel® Matrix Storage Manager-->C:\Windows\system32\imsmudlg.exe -uninstall
          iTunes-->MsiExec.exe /I{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}
          Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
          LifeFrame2-->MsiExec.exe /I{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}
          Macromedia Flash Player 8-->RunDll32 advpack.dll,LaunchINFSection C:\Windows\INF\swflash.inf,DefaultUninstall,5
          Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
          mCore-->MsiExec.exe /I{F5D7FAB5-A1FD-4DD3-983E-4155B09D7102}
          mDriver-->MsiExec.exe /I{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}
          mHelp-->MsiExec.exe /I{8C6BB412-D3A8-4AAE-A01B-35B681789D68}
          Microsoft .NET Framework 1.1 Hotfix (KB929729)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M929729\M929729Uninstall.msp"
          Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
          Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
          Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
          mMHouse-->MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
          Motorola SM56 Speakerphone Modem-->rundll32.exe sm56co6a.dll,SM56UnInstaller
          Mozilla Firefox (3.0.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          mPfMgr-->MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
          MPM-->MsiExec.exe /X{BAB0F8F5-282A-45F1-B31A-EB894827456B}
          MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
          MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
          MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
          MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
          NB Probe-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}\setup.exe" -l0x9
          Nero 7 Essentials-->MsiExec.exe /X{97F32DF8-D66E-446A-A425-C1D7B45C1033}
          NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
          OpenOffice.org 2.3-->MsiExec.exe /I{FADB55D0-403F-4413-A268-CF0A6F1185C2}
          Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
          PDFCreator-->C:\Program Files\PDFCreator\unins000.exe
          Picasa 3-->"C:\Program Files\Google\Picasa3\Uninstall.exe"
          Power4Gear eXtreme-->C:\Program Files\InstallShield Installation Information\{8CFEBE9C-F29F-4C49-80E0-7106970F8734}\SETUP.exe -runfromtemp -l0x0009 -removeonly
          PowerForPhone-->C:\Program Files\InstallShield Installation Information\{FC3D290D-79BE-44B7-ABF9-FDD110925930}\setup.exe -runfromtemp -l0x0009 -removeonly
          QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
          RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
          Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\SETUP.exe" -l0x9 -removeonly
          RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\SETUP.EXE" -l0x9 anything
          Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
          USB2.0 1.3M WebCam-->C:\Windows\StkUnist.exe
          VistaFeaturePack-->C:\Program Files\InstallShield Installation Information\{D7E04009-B191-4E9D-9D2D-1BBE57BD8A42}\setup.exe -runfromtemp -l0x0409
          Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
          WinFlash-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DE10AB76-4756-4913-BE25-55D1C1051F9A}\setup.exe" -l0x9
          Wireless Console 2-->C:\Program Files\InstallShield Installation Information\{83F73CB1-7705-49D1-9852-84D839CA2A45}\SETUP.exe -runfromtemp -l0x0009 -removeonly

          ======Security center information======

          AV: AVG Anti-Virus Free
          AS: AVG Anti-Virus Free (disabled)
          AS: Windows Defender (disabled)

          ======System event log======

          Computer Name: Bumbo
          Event Code: 10002
          Message: Le module d’extensibilité WLAN s’est arrêté.

          Chemin d’accès du module : C:\Windows\System32\IWMSSvc.dll

          Record Number: 127963
          Source Name: Microsoft-Windows-WLAN-AutoConfig
          Time Written: 20090407153435.065400-000
          Event Type: Avertissement
          User: AUTORITE NT\SYSTEM

          Computer Name: Bumbo
          Event Code: 7000
          Message: Le service ghaio n'a pas pu démarrer en raison de l'erreur :
          ghaio n'est pas une application Win32 valide.
          Record Number: 128024
          Source Name: Service Control Manager
          Time Written: 20090407170911.000000-000
          Event Type: Erreur
          User:

          Computer Name: Bumbo
          Event Code: 7011
          Message: Le dépassement de délai (30000 millisecondes) a été atteint lors de l’attente de la réponse transactionnelle du service IFXTCS.
          Record Number: 128133
          Source Name: Service Control Manager
          Time Written: 20090408055259.000000-000
          Event Type: Erreur
          User:

          Computer Name: Bumbo
          Event Code: 7011
          Message: Le dépassement de délai (30000 millisecondes) a été atteint lors de l’attente de la réponse transactionnelle du service IFXTCS.
          Record Number: 128142
          Source Name: Service Control Manager
          Time Written: 20090408073800.000000-000
          Event Type: Erreur
          User:

          Computer Name: Bumbo
          Event Code: 541
          Message: Une opération en cours a été interrompue par un événement de gestion de l’alimentation.
          Record Number: 128145
          Source Name: Microsoft-Windows-TBS
          Time Written: 20090408073803.454600-000
          Event Type: Avertissement
          User: AUTORITE NT\SERVICE LOCAL

          =====Application event log=====

          Computer Name: Bumbo
          Event Code: 5007
          Message: Impossible d’analyser le fichier cible de la plateforme de signalement de problèmes Windows (fichier DLL contenant la liste des problèmes de l’ordinateur et nécessitant la collecte de données supplémentaires à des fins de diagnostic). Le code d’erreur était : 8014FFF9.
          Record Number: 25910
          Source Name: WerSvc
          Time Written: 20090406154339.000000-000
          Event Type: Erreur
          User:

          Computer Name: Bumbo
          Event Code: 1002
          Message: Le programme firefox.exe version 1.9.0.3372 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans l’application Rapports et solutions aux problèmes du Panneau de configuration. ID de processus : 460 Heure de début : 01c9b770c20f69e0 Heure de fin : 78
          Record Number: 25937
          Source Name: Application Hang
          Time Written: 20090407111754.000000-000
          Event Type: Erreur
          User:

          Computer Name: Bumbo
          Event Code: 5007
          Message: Impossible d’analyser le fichier cible de la plateforme de signalement de problèmes Windows (fichier DLL contenant la liste des problèmes de l’ordinateur et nécessitant la collecte de données supplémentaires à des fins de diagnostic). Le code d’erreur était : 8014FFF9.
          Record Number: 25960
          Source Name: WerSvc
          Time Written: 20090407120818.000000-000
          Event Type: Erreur
          User:

          Computer Name: Bumbo
          Event Code: 1530
          Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

          DÉTAIL -
          1 user registry handles leaked from \Registry\User\S-1-5-21-3289955591-151054794-2508720594-1000_Classes:
          Process 1988 (\Device\HarddiskVolume3\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3289955591-151054794-2508720594-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache

          Record Number: 25973
          Source Name: Microsoft-Windows-User Profiles Service
          Time Written: 20090407153430.000000-000
          Event Type: Avertissement
          User: AUTORITE NT\SYSTEM

          Computer Name: Bumbo
          Event Code: 5007
          Message: Impossible d’analyser le fichier cible de la plateforme de signalement de problèmes Windows (fichier DLL contenant la liste des problèmes de l’ordinateur et nécessitant la collecte de données supplémentaires à des fins de diagnostic). Le code d’erreur était : 8014FFF9.
          Record Number: 25999
          Source Name: WerSvc
          Time Written: 20090407170852.000000-000
          Event Type: Erreur
          User:

          =====Security event log=====

          Computer Name: Bumbo
          Event Code: 4616
          Message: L’heure du système a été modifiée.

          Sujet :
          ID de sécurité : S-1-5-19
          Nom du compte : SERVICE LOCAL
          Domaine du compte : AUTORITE NT
          ID d’ouverture de session : 0x3e5

          Informations sur le processus :
          ID du processus : 0x55c
          Nom : C:\Windows\System32\svchost.exe

          Heure précédente : 15:29:49 20/12/2008
          Nouvelle heure : 15:29:49 20/12/2008

          Cet événement est généré lorsque l’heure du système est modifiée. Le changement régulier de l’heure du système est une opération normale de la part du service de temps Windows qui s’exécute avec des privilèges système. Mais, d’autres modifications de l’heure du système peuvent indiquer des tentatives de falsification de l’ordinateur.
          Record Number: 23356
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20081220142949.039000-000
          Event Type: Succès de l'audit
          User:

          Computer Name: Bumbo
          Event Code: 4647
          Message: Fermeture de session initiée par l’utilisateur :

          Sujet :
          ID de sécurité : S-1-5-21-3289955591-151054794-2508720594-1000
          Nom du compte : Fred
          Domaine du compte : Bumbo
          ID d’ouverture de session : 0x23b41

          Cet événement est généré lorsqu’une fermeture de session est initiée, mais que le nombre de références du jeton n’étant pas zéro, la session ouverte ne peut pas être supprimée. Aucune autre activité initiée par l’utilisateur ne peut se produire. Cet événement peut être interprété comme un événement de fermeture de session.
          Record Number: 23357
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20081220155220.810800-000
          Event Type: Succès de l'audit
          User:

          Computer Name: Bumbo
          Event Code: 1100
          Message: Le service d’enregistrement des événements a été arrêté.
          Record Number: 23358
          Source Name: Microsoft-Windows-Eventlog
          Time Written: 20081220155226.754400-000
          Event Type: Succès de l'audit
          User:

          Computer Name: Bumbo
          Event Code: 4634
          Message: Fermeture de session d’un compte.

          Sujet :
          ID de sécurité : S-1-5-7
          Nom du compte : ANONYMOUS LOGON
          Domaine du compte : AUTORITE NT
          ID du compte : 0x2515a

          Type d’ouverture de session : 3

          Cet événement est généré lorsqu’une session ouverte est supprimée. Il peut être associé à un événement d’ouverture de session en utilisant la valeur ID d’ouverture de session. Les ID d’ouverture de session ne sont uniques qu’entre les redémarrages sur un même ordinateur.
          Record Number: 23359
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20081220155228.720000-000
          Event Type: Succès de l'audit
          User:

          Computer Name: Bumbo
          Event Code: 4616
          Message: L’heure du système a été modifiée.

          Sujet :
          ID de sécurité : S-1-5-19
          Nom du compte : SERVICE LOCAL
          Domaine du compte : AUTORITE NT
          ID d’ouverture de session : 0x3e5

          Informations sur le processus :
          ID du processus : 0x55c
          Nom : C:\Windows\System32\svchost.exe

          Heure précédente : 16:52:30 20/12/2008
          Nouvelle heure : 16:52:30 20/12/2008

          Cet événement est généré lorsque l’heure du système est modifiée. Le changement régulier de l’heure du système est une opération normale de la part du service de temps Windows qui s’exécute avec des privilèges système. Mais, d’autres modifications de l’heure du système peuvent indiquer des tentatives de falsification de l’ordinateur.
          Record Number: 23360
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20081220155230.467000-000
          Event Type: Succès de l'audit
          User:

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\bin;C:\Program Files\Common Files\Autodesk Shared\;C:\Program Files\Autodesk\backburner\;C:\Program Files\QuickTime\QTSystem\
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
          "PROCESSOR_ARCHITECTURE"=x86
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP
          "USERNAME"=SYSTEM
          "windir"=%SystemRoot%
          "PROCESSOR_LEVEL"=6
          "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 10, GenuineIntel
          "PROCESSOR_REVISION"=0f0a
          "NUMBER_OF_PROCESSORS"=2
          "configsetroot"=%SystemRoot%\ConfigSetRoot
          "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip
          "QTJAVA"=C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip

          -----------------EOF-----------------
          0
        2. @alfredaPar ailleurs j'ai bien désinstallé les antivirus pour remettre AVG free (celui que j'avais avant).
          Voici le log.txt maintenant:

          Logfile of random's system information tool 1.06 (written by random/random)
          Run by Fred at 2009-04-08 10:07:39
          Microsoft® Windows Vista™ Édition Familiale Premium
          System drive C: has 43 GB (56%) free of 76 GB
          Total RAM: 2047 MB (53% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 10:07:44, on 08/04/2009
          Platform: Windows Vista (WinNT 6.00.1904)
          MSIE: Internet Explorer v7.00 (7.00.6000.16809)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
          C:\Windows\system32\taskeng.exe
          C:\Program Files\ASUS\ASUS Live Update\ALU.exe
          C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
          C:\Windows\System32\rundll32.exe
          C:\Program Files\Nero\Nero 7\InCD\InCD.exe
          C:\Windows\RtHDVCpl.exe
          C:\Windows\System32\rundll32.exe
          C:\Program Files\ASUS\ATK Media\DMedia.exe
          C:\Program Files\Intel\Intel Matrix Storage Manager\IAANOTIF.EXE
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\PowerForPhone\PowerForPhone.exe
          C:\Windows\ASScrPro.exe
          C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
          C:\Program Files\AVG\AVG8\avgtray.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\PDFCreator\PDFCreator.exe
          C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
          C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
          C:\Windows\ehome\ehmsas.exe
          C:\Program Files\Infineon\Security Platform Software\PSDrt.exe
          C:\Program Files\Infineon\Security Platform Software\SpTna.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
          C:\Windows\system32\wbem\unsecapp.exe
          C:\Windows\system32\rundll32.exe
          C:\Windows\system32\wuauclt.exe
          C:\Users\Fred\Desktop\launch.exe
          C:\Users\Fred\AppData\Local\Temp\RarSFX0\_start.exe
          C:\Users\Fred\AppData\Local\Temp\RarSFX0\setup.exe
          C:\Windows\system32\conime.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Users\Fred\Desktop\RSIT.exe
          C:\Program Files\Trend Micro\HijackThis\Fred.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.asus.com/fr/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
          O1 - Hosts: ::1 localhost
          O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
          O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
          O2 - BHO: ASUS Security Protect Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll
          O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
          O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
          O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [Skytel] Skytel.exe
          O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
          O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
          O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone.exe
          O4 - HKLM\..\Run: [IFXSPMGT] C:\Windows\system32\ifxspmgt.exe /NotifyLogon
          O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
          O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
          O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll,RegisterModule
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O4 - Global Startup: PDFCreator.lnk = C:\Program Files\PDFCreator\PDFCreator.exe
          O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
          O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
          O13 - Gopher Prefix:
          O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
          O20 - AppInit_DLLs: APSHook.dll,avgrsstx.dll
          O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
          O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
          O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
          O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
          O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
          O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Windows\system32\ifxspmgt.exe
          O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Windows\system32\ifxtcs.exe
          O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
          O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
          O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Windows\system32\IfxPsdSv.exe
          O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
          O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
          O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe
          0
      3. Contributeur sécurité
        ok tu as une infection par clé usb, disque dur externe ...

        Telecharge et install UsbFixTelecharge et install UsbFix de C_XX & Chiquitine29

        Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

        # Double clic sur le raccourci UsbFix présent sur ton bureau .

        # Choisi l option 1 ( Recherche )

        # Laisse travailler l outil.

        # Ensuite post le rapport UsbFix.txt qui apparaitra.

        # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

        ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

        # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

        0
        1. J'ai fait tout ça mais quand je choisis l'option 1, une liste apparaît avec "accès refusé " répété plusieurs fois.
          Et mon antivirus me donne une menace détectée: Usbfix.exe.
          J'ai cliqué sur ignorer. Mais du coup, le processus ne s'enclenche pas et si je repète l'opération ça me refait la même chose. Bref, Usbfix ne veut pas démarrer.
          Comment faire? MErci
          0
        2. @alfredaPlus exactement le fichier détecté par AVG est windows/systeme32/cdm.exe

          Est ce le virus ou un composant de Usbfix à autoriser?
          0
        3. Contributeur sécurité
          @alfredaautorise si c'est suite a usbfix
          0
      4. Contributeur sécurité
        désactive ton antivirus avant de télécharger usbfix : donc desactive l'antivirus puis télécharge a nouveau usbfix puis lance le

        si cela ne marche pas alors:

        télécharge combofix (par sUBs) ici :

        http://download.bleepingcomputer.com/sUBs/ComboFix.exe

        et enregistre le sur le bureau.

        déconnecte toi d'internet et ferme toutes tes applications.

        désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

        double-clique sur combofix.exe et suis les instructions

        à la fin, il va produire un rapport C:\ComboFix.txt

        réactive ton parefeu, ton antivirus, la garde de ton antispyware

        copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

        Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

        Tu as un tutoriel complet ici :

        https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
        0
        1. Pour tout dire, je n'ai réussi ni Usb fix en réessayant, ni Combo Fix qui a fait planter mon ordi quand j'ai fait exécuter de dossier...
          Bref, j'ai entamé une analyse tout simple AVG sur mon disque dur externe et il est infecté par un virus nommé Worm Rjump. Est ce ce que tu avais détecté dans les derniers .txt? Puis je le résoudre juste avec AVG? ou faut il un autre logiciel? merci
          0
        2. @alfreda"Nom de l'objet";"G:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP108\A0012461.exe"

          "Nom de l'objet";"G:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP108\A0012484.exe"

          "Nom de l'objet";"G:\System Volume Information\_restore{7F7372F2-0998-4664-876E-A5B56A790057}\RP27\A0004482.exe"

          Ce sont les 3 virus détectés sur mon Disque dur externe par AVG et mis en quarantaine.
          Ces virus peuvent ils expliquer les ralentissements de mon ordi (alors que le disque n'était pas pluggé)? Dois je continuer à chercher? Comment savoir si ce virus ne s'est pas répandu dans l'ordi (j'avoue que j'y connais vraiment rien à tout ça)

          Merci pour vos lumières sur ce point encore :)
          0
        3. Contributeur sécurité
          @alfredaBref, j'ai entamé une analyse tout simple AVG sur mon disque dur externe et il est infecté par un virus nommé Worm Rjump. Est ce ce que tu avais détecté dans les derniers .txt? Puis je le résoudre juste avec AVG? ou faut il un autre logiciel? merci

          oui je sais et avg ne suffit pas c'est pourquoi je te demande USBFIX ou COMBOFIX qui vont l'éradiquer (branche le disque externe bien sur)
          0
      5. Yop,
        msconfig est ton ami !!
        Démarrer, Executer, "msconfig", Entrée, onglet démarrage, décoche toutes les cases sauf antivirus.
        Reboot et tu auras normalement une nette amélioration : plus de processus inutile !!!!
        Un petit coup de ccleaner et voilà un ordi quasi-neuf.
        Si certains fichiers reviennent se cocher sur msconfig, ce sont surement des trojans, virus ... donne leur noms et si besoin supprime les en mode sans échec.
        (Arrêtez avec vos rapports HijackThis, personne ne les lit xD)
        -1