Pc ralenti anormalement

Résolu
Alex Mumu Messages postés 16 Statut Membre -  
 Utilisateur anonyme -
Bonjour, depuis un petit moment, mon pc rame beaucoup et surtout au démarrage, j'aurai besoin de votre aide pour y remedier.
Antivirus : avira antivir gratuit 2009
Pare feu : outpost firewall 2009
Aussi Spybot.
CCleaner
Advanced system care

J'ai déjà fais un nettoyage de disque, défragmentation, erreur de registre avec CCleaner et fait un recherche d'espions avec spybot et outpost ainsi qu'un scan avec antivir.

Merci d'avance de votre réponse. Alex Mumu

(ps : je m'y connai pas beaucoup)
Configuration: Windows XP Internet Explorer 8.0

24 réponses

  • 1
  • 2
  1. Utilisateur anonyme
     
    Bonjour
    Fais un scan HijackThis : : http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
    Avant de lancer HijackThis, renomme-le !
    Pour cela, suis le chemin ci-dessous, jusqu' au fichier en gras :

    C:\Program files\Trend Micro\HijackThis\HijackThis.exe

    Clique droit dessus et choisis "renommer" : tape moulin.exe et valide.
    Puis, clique droit sur "moulin.exe" et choisis Envoyer vers -> Bureau (créer un raccourci).
    Reviens sur le bureau et clique sur le nouvel icône pour le lancer.
    *. Accepte la license en cliquant sur le bouton "I Accept"
    *. Choisis l'option "Do a system scan and save a log file"
    *. Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
    *. Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport
    *. Colle le rapport que tu viens de copier sur ce forum
    *. Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement
    Tutoriaux
    0
  2. Alex Mumu Messages postés 16 Statut Membre
     
    Voilà le rapport :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:34:50, on 05/05/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\Program Files\RocketDock\RocketDock.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\moulin.exe.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trooner.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/fuji/defaults/su/*https://fr.yahoo.com/?p=us
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKLM\..\Run: [OutpostMonitor] C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice
    O4 - HKLM\..\Run: [OutpostFeedBack] "C:\Program Files\Agnitum\Outpost Firewall Pro\feedback.exe" /dump:os_startup
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra button: Réglage rapide de Outpost Firewall Pro - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall Pro\ie_bar.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - D:\CDS300\__CDS2.dll (file missing)
    O20 - AppInit_DLLs: c:\progra~1\agnitum\outpos~1\wl_hook.dll
    O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe
    O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
    O24 - Desktop Component 0: (no name) - https://securepics.ebaystatic.com/aw/pics/fr/logos/logoEbay_150x40.gif
    0
  3. jokary77 Messages postés 158 Statut Membre 13
     
    bonjour,

    je vous conseille de faire un scan gratuit avec ce logiciel : https://www.pcmatic.com/optimize/default.asp
    et de voir tous vos problemes.
    le scan est gratuit mais il vous faudra par la suite débourser une vingtaine d'euros pour résoudres vos problemes.
    0
  4. chimay8 Messages postés 7947 Statut Contributeur sécurité 60
     
    il vous faudra par la suite débourser une vingtaine d'euros

    et ici ces gratuit...
    0
    1. jokary77 Messages postés 158 Statut Membre 13
       
      bonjour,

      sauf qu'il faut bien se rendre a l'évidence....
      certains logiciels sont là pour résoudrent les problemes, sinon ca ne servirait a rien d'avoir un d'antivirus , pare feu ou autre .....

      personne n'est parfait
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. chimay8 Messages postés 7947 Statut Contributeur sécurité 60
     
    des soft pour optimiser y en a des dizaines
    ta envie de payer?fais le
    mais ne pousse pas les autres à l'achat
    0
    1. jokary77 Messages postés 158 Statut Membre 13
       
      je pousse personne a l'achat, je lui ai dit que le scan etait gratuit.....je ne pense pas lui avoir demandé d'acheter le logiciel
      0
  7. Alex Mumu Messages postés 16 Statut Membre
     
    20 euros pour réparer des problèmes? C'est cher quand même. Tout mes logiciels sont gratuit et je ne compte pas payer pour ça, deplus, ratuit ne veut pas dire inéficace. J'ai posté mon analyse Hijack Plus haut dans les réponses.

    Merci de vos réponses. Alex Mumu
    0
  8. Alex Mumu Messages postés 16 Statut Membre
     
    Quelqu'un pourrait interpreter mon rapport Hijack Svp?

    Merci.
    0
  9. Utilisateur anonyme
     
    Bonjour

    J t'avais envoyé un message mais apparemment il n'était pas passé.Donc fait ce qui suit.

    • Télécharge : http://images.malwareremoval.com/random/RSIT.exe

    /!\ Important (Sous Vista) /!\

    Vous devez exécuter RSIT avec les droits d'administrateur, pour cela Clique droit sur RSIT et "Lancer en tant qu'administrateur"
    • Double clique sur RSIT.exe pour lancer l'outil.
    • Clique sur 'Continue' à l'écran Disclaimer.
    • Si l'outil Hijackthis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
    • Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports.
    ( C:\RSIT\log.txt et C:\RSIT\info.txt )
    • CTRL A pour sélectionner tout, CTRL C pour copier et puis CTRL V pour coller
    • tuto: : https://www.androidworld.fr/
    0
  10. Alex Mumu Messages postés 16 Statut Membre
     
    Voici les deux rapports:

    log:

    Logfile of random's system information tool 1.06 (written by random/random)
    Run by paul at 2009-05-07 17:50:18
    Microsoft Windows XP Édition familiale Service Pack 3
    System drive C: has 175 GB (92%) free of 191 GB
    Total RAM: 511 MB (4% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:51:26, on 07/05/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MPKLSX6M\RSIT[1].exe
    C:\Program Files\trend micro\paul.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trooner.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/fuji/defaults/su/*https://fr.yahoo.com/?p=us
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKLM\..\Run: [OutpostMonitor] C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra button: Réglage rapide de Outpost Firewall Pro - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall Pro\ie_bar.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - D:\CDS300\__CDS2.dll (file missing)
    O20 - AppInit_DLLs: c:\progra~1\agnitum\outpos~1\wl_hook.dll
    O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe
    O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
    O24 - Desktop Component 0: (no name) - https://securepics.ebaystatic.com/aw/pics/fr/logos/logoEbay_150x40.gif
    0
  11. Utilisateur anonyme
     
    Télécharger OTMoveIt3 via un clic droit sur le lien ci-dessous:
    http://oldtimer.geekstogo.com/OTMoveIt3.exe

    * Copier ce texte en gras
    :driver
    pnicml

    :Files
    C:\WINDOWS\Matrix Code.exe
    C:\WINDOWS\mickey32.dll
    C:\DOCUME~1\paul\LOCALS~1\Temp\pnicml.sys

    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]


    * Double-clic sur OTMoveIt.exe

    * Dans le cadre de Gauche « Paste Instructions for Items to be Moved » ==> clic-droit ==> coller
    * Clic « MoveIt! »
    * si redémarrage demandé==> Clic : « YES »
    * Un rapport dans ==> C:\_OTMoveIt\MovedFiles\date du jour à copier/coller dans la réponse (format du type => mmjjaaaa_hhmmss.log)
    0
  12. Alex Mumu Messages postés 16 Statut Membre
     
    Merci de répondre aussi vite nanard Voici le rapport qui s'est ouvert au redémarrage :

    Error: Unable to interpret <:driver > in the current context!
    Error: Unable to interpret <pnicml > in the current context!
    ========== FILES ==========
    C:\WINDOWS\Matrix Code.exe moved successfully.
    DllUnregisterServer procedure not found in C:\WINDOWS\mickey32.dll
    C:\WINDOWS\mickey32.dll NOT unregistered.
    C:\WINDOWS\mickey32.dll moved successfully.
    File/Folder C:\DOCUME~1\paul\LOCALS~1\Temp\pnicml.sys not found.
    ========== COMMANDS ==========
    File delete failed. C:\DOCUME~1\paul\LOCALS~1\Temp\flaA.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\paul\LOCALS~1\Temp\flaB.tmp scheduled to be deleted on reboot.
    User's Temp folder emptied.
    User's Internet Explorer cache folder emptied.
    File delete failed. C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MPKLSX6M\1611312[1].mp4 scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MPKLSX6M\affich-12314404-pc-ralenti-anormalement[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MPKLSX6M\Dragon-ball-GT-54-vf[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MPKLSX6M\favicon[1].ico scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MPKLSX6M\favicon[2].ico scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\LNUWQ10Z\dellecomicon[1].ico scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\2X2B219A\OTMoveIt3[1].exe scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    User's Temporary Internet Files folder emptied.
    Local Service Temp folder emptied.
    Local Service Temporary Internet Files folder emptied.
    Network Service Temp folder emptied.
    Network Service Temporary Internet Files folder emptied.
    File delete failed. C:\WINDOWS\temp\logishrd\LVPrcInj01.dll scheduled to be deleted on reboot.
    Windows Temp folder emptied.
    Java cache emptied.
    Temp folders emptied.
    Explorer started successfully

    OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05072009_200929

    Files moved on Reboot...
    File C:\DOCUME~1\paul\LOCALS~1\Temp\flaA.tmp not found!
    File C:\DOCUME~1\paul\LOCALS~1\Temp\flaB.tmp not found!
    C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MPKLSX6M\1611312[1].mp4 moved successfully.
    C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MPKLSX6M\affich-12314404-pc-ralenti-anormalement[1].htm moved successfully.
    C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MPKLSX6M\Dragon-ball-GT-54-vf[1].htm moved successfully.
    C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MPKLSX6M\favicon[1].ico moved successfully.
    C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MPKLSX6M\favicon[2].ico moved successfully.
    C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\LNUWQ10Z\dellecomicon[1].ico moved successfully.
    C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\2X2B219A\OTMoveIt3[1].exe moved successfully.
    DllUnregisterServer procedure not found in C:\WINDOWS\temp\logishrd\LVPrcInj01.dll
    C:\WINDOWS\temp\logishrd\LVPrcInj01.dll NOT unregistered.
    File move failed. C:\WINDOWS\temp\logishrd\LVPrcInj01.dll scheduled to be moved on reboot.

    Tu me fai faire plein de test mais je ne sais pas à quoi ça sert concretement?
    Merci.
    0
  13. Utilisateur anonyme
     
    Ce ne sont pas des tests .ces programmes suppriment les infections.
    Post un nouveau rapport rsit.
    0
  14. Alex Mumu Messages postés 16 Statut Membre
     
    Un seul rapport s'est affiché :

    log :

    Logfile of random's system information tool 1.06 (written by random/random)
    Run by paul at 2009-05-08 09:00:48
    Microsoft Windows XP Édition familiale Service Pack 3
    System drive C: has 175 GB (92%) free of 191 GB
    Total RAM: 511 MB (24% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 09:01:06, on 08/05/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6Q4BV8ZO\RSIT[1].exe
    C:\Program Files\trend micro\paul.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trooner.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/fuji/defaults/su/*https://fr.yahoo.com/?p=us
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKLM\..\Run: [OutpostMonitor] C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra button: Réglage rapide de Outpost Firewall Pro - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall Pro\ie_bar.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - D:\CDS300\__CDS2.dll (file missing)
    O20 - AppInit_DLLs: c:\progra~1\agnitum\outpos~1\wl_hook.dll
    O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe
    O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
    O24 - Desktop Component 0: (no name) - https://securepics.ebaystatic.com/aw/pics/fr/logos/logoEbay_150x40.gif
    0
  15. Utilisateur anonyme
     
    /!\ A l'attention de ceux qui passent sur ce sujet /!\
    Le logiciel qui suit n'est pas à utiliser à la légère et peut faire des dégâts s'il est mal utilisé ! Ne le faites que si un helpeur du forum qui connait bien cet outil vous l'a recommandé.

    /!\ Désactive tous tes logiciels de protection /!\

    • Télécharge ComboFix (de sUBs) sur ton Bureau.http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    • Double-clique sur ComboFix.exe afin de le lancer.
    • Il va te demander d'installer la console de récupération : accepte.
    • Ne touche à rien pendant le scan.
    • Lorsque la recherche sera terminée, un rapport apparaîtra. Poste ce rapport (C:\Combofix.txt) dans ta prochaine réponse.

    Tutoriel officiel de Combofix : https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
    0
  16. Alex Mumu Messages postés 16 Statut Membre
     
    c'est dangereux??
    0
  17. Utilisateur anonyme
     
    Le message d'alerte est pour ceux qui veulent l'utiliser seul.Accompagné d'un helpeur aucun risque.
    0
  18. Alex Mumu Messages postés 16 Statut Membre
     
    ComboFix 09-05-07.A0 - paul 08/05/2009 13:53.1 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.511.220 [GMT 2:00]
    Lancé depuis: c:\documents and settings\paul\Bureau\ComboFix.exe
    AV: AntiVir Desktop *On-access scanning disabled* (Updated)
    FW: Outpost Firewall Pro *disabled*
    * Un nouveau point de restauration a été créé
    .

    ((((((((((((((((((((((((((((( Fichiers créés du 2009-04-08 au 2009-05-08 ))))))))))))))))))))))))))))))))))))
    .

    2009-05-07 18:09 . 2009-05-07 18:09 -------- d-----w C:\_OTMoveIt
    2009-05-07 15:50 . 2009-05-07 15:51 -------- d-----w C:\rsit
    2009-05-06 10:23 . 2009-05-06 10:24 -------- d--h--w c:\documents and settings\All Users\Application Data\{148D8B8A-8F96-4822-81EC-D510B626B7D5}
    2009-05-06 09:17 . 2009-05-06 09:17 -------- d-----w c:\documents and settings\paul\Application Data\ATI
    2009-05-06 09:17 . 2009-05-06 09:17 -------- d-----w c:\documents and settings\paul\Local Settings\Application Data\ATI
    2009-05-06 09:09 . 2006-05-03 09:57 520192 ------w c:\windows\system32\ati2sgag.exe
    2009-05-06 09:03 . 2009-05-06 10:25 -------- d-----w c:\documents and settings\All Users\Application Data\DriverScanner
    2009-05-05 09:15 . 2009-05-08 07:00 -------- d-----w c:\program files\Trend Micro
    2009-05-05 07:47 . 2009-05-05 07:47 -------- d-----w c:\program files\Windows Live SkyDrive
    2009-05-05 07:46 . 2009-05-05 07:47 -------- d-----w c:\program files\Windows Live
    2009-05-01 06:26 . 2009-05-01 06:26 -------- d-----w c:\program files\Tracker Software
    2009-04-30 07:01 . 2009-04-06 09:37 704384 ----a-w c:\windows\system32\drivers\SandBox.sys
    2009-04-30 07:01 . 2009-02-10 14:15 257432 ----a-w c:\windows\system32\drivers\afwcore.sys
    2009-04-30 06:59 . 2009-02-18 15:30 31128 ----a-w c:\windows\system32\drivers\afw.sys
    2009-04-30 06:59 . 2009-05-08 06:57 -------- d-----w c:\windows\system32\Filt
    2009-04-30 06:59 . 2009-04-30 06:59 -------- d-----w c:\program files\Agnitum
    2009-04-30 06:58 . 2009-04-30 06:58 -------- d-----w c:\documents and settings\All Users\Application Data\Agnitum
    2009-04-30 06:27 . 2009-05-06 09:03 -------- d-----w c:\documents and settings\paul\Application Data\Uniblue
    2009-04-29 18:40 . 2009-04-29 18:40 -------- d-sh--w c:\documents and settings\Default User\IETldCache
    2009-04-29 10:10 . 2009-04-29 10:10 -------- d-----w c:\documents and settings\NetworkService\Menu Démarrer
    2009-04-29 10:09 . 2009-03-24 14:07 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
    2009-04-29 10:09 . 2009-04-29 10:09 -------- d-----w c:\documents and settings\All Users\Application Data\Avira
    2009-04-29 10:09 . 2009-04-29 10:09 -------- d-----w c:\program files\Avira
    2009-04-27 15:14 . 2009-04-27 15:14 65541 ----a-w c:\windows\BricoPackUninst.cmd
    2009-04-27 15:10 . 2009-04-27 15:14 6112 ----a-w c:\windows\BricoPackFoldersDelete.cmd
    2009-04-26 19:57 . 2009-05-06 09:10 -------- d-----w c:\program files\ATI Technologies
    2009-04-26 19:56 . 2001-09-19 11:28 9728 ----a-w c:\windows\system32\drivers\viausb1.sys
    2009-04-26 19:55 . 2009-04-26 19:55 -------- d-----w C:\ATI
    2009-04-26 19:53 . 2001-09-23 23:10 306688 ----a-w c:\windows\IsUninst.exe
    2009-04-26 19:53 . 2009-04-26 19:53 -------- d-----w c:\documents and settings\paul\WINDOWS
    2009-04-26 19:33 . 2009-04-26 19:58 -------- d-----w c:\documents and settings\paul\Application Data\IObit
    2009-04-26 19:33 . 2009-04-26 19:33 -------- d-----w c:\program files\IObit
    2009-04-26 07:41 . 2009-04-26 07:41 -------- d-----w c:\program files\FreshDevices
    2009-04-25 17:50 . 2009-05-06 18:32 -------- d-----w c:\documents and settings\All Users\Application Data\WinZip
    2009-04-23 17:32 . 2009-04-23 17:32 232784 ----a-w c:\windows\Matrix Code.scr
    2009-04-23 17:16 . 2009-05-03 16:15 -------- d-----w c:\program files\Spybot - Search & Destroy
    2009-04-20 11:05 . 2009-04-20 11:05 -------- d-----w c:\windows\Sun
    2009-04-18 11:01 . 2009-05-08 06:49 -------- d-----w c:\documents and settings\paul\Tracing
    2009-04-16 07:23 . 2009-04-16 07:23 -------- d-----w c:\program files\Fichiers communs\Ulead
    2009-04-16 07:22 . 2009-04-16 07:22 -------- d-----w c:\documents and settings\All Users\Application Data\InstallShield
    2009-04-16 07:17 . 2009-04-16 07:17 -------- d-----w c:\windows\Logs
    2009-04-15 16:47 . 2009-04-15 16:47 80860 ---ha-w c:\windows\system32\mlfcache.dat
    2009-04-15 15:00 . 2009-04-15 15:00 -------- d-----w c:\program files\Windows Media Connect 2
    2009-04-15 08:36 . 2009-02-09 11:23 111104 ------w c:\windows\system32\dllcache\services.exe
    2009-04-15 08:36 . 2009-02-09 10:53 401408 ------w c:\windows\system32\dllcache\rpcss.dll
    2009-04-15 08:36 . 2009-02-09 10:53 473600 ------w c:\windows\system32\dllcache\fastprox.dll
    2009-04-15 08:36 . 2009-02-09 10:53 685568 ------w c:\windows\system32\dllcache\advapi32.dll
    2009-04-15 08:36 . 2009-02-09 10:53 735744 ------w c:\windows\system32\dllcache\lsasrv.dll
    2009-04-15 08:36 . 2009-02-09 10:53 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
    2009-04-15 08:36 . 2009-02-09 10:53 739840 ------w c:\windows\system32\dllcache\ntdll.dll
    2009-04-15 08:34 . 2008-12-16 12:31 354304 ------w c:\windows\system32\dllcache\winhttp.dll
    2009-04-14 01:02 . 2009-04-16 08:30 101392 ----a-w c:\windows\system32\GDIPFONTCACHEV1.DAT
    2009-04-13 16:49 . 2004-08-05 12:00 185344 ----a-w c:\windows\system32\dllcache\thawbrkr.dll
    2009-04-13 16:49 . 2004-08-05 12:00 185344 ----a-w c:\windows\system32\Thawbrkr.dll
    2009-04-13 16:49 . 2004-08-05 12:00 10752 ----a-w c:\windows\system32\dllcache\c_iscii.dll
    2009-04-13 16:49 . 2004-08-05 12:00 10752 ----a-w c:\windows\system32\c_iscii.dll
    2009-04-13 16:49 . 2004-08-05 12:00 5632 ----a-w c:\windows\system32\dllcache\kbdusa.dll
    2009-04-13 16:49 . 2004-08-05 12:00 5632 ----a-w c:\windows\system32\kbdusa.dll
    2009-04-13 16:49 . 2004-08-05 12:00 6144 ----a-w c:\windows\system32\dllcache\ftlx041e.dll
    2009-04-13 16:49 . 2004-08-05 12:00 6144 ----a-w c:\windows\system32\ftlx041e.dll
    2009-04-12 16:33 . 2009-04-12 16:33 -------- d-----w c:\documents and settings\paul\Application Data\AVS4YOU
    2009-04-12 16:31 . 2009-04-12 16:44 -------- d-----w c:\program files\Fichiers communs\AVSMedia
    2009-04-12 16:30 . 2009-04-16 06:53 -------- d-----w c:\windows\system32\drivers\umdf
    2009-04-12 16:28 . 2009-01-28 18:49 974848 ----a-w c:\windows\system32\mfc70.dll
    2009-04-10 15:28 . 2009-04-10 15:28 -------- d-----w c:\program files\Fichiers communs\DivX Shared
    2009-04-10 15:28 . 2009-04-10 15:29 -------- d-----w c:\program files\DivX

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-05-08 11:56 . 2009-03-19 18:19 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
    2009-05-08 11:56 . 2009-03-19 18:18 0 ----a-w c:\windows\system32\drivers\logiflt.iad
    2009-05-06 22:43 . 2009-03-22 15:03 -------- d-----w c:\program files\CCleaner
    2009-05-06 09:20 . 2005-01-23 13:41 86274 ----a-w c:\windows\system32\perfc00C.dat
    2009-05-06 09:20 . 2005-01-23 13:41 514630 ----a-w c:\windows\system32\perfh00C.dat
    2009-05-06 09:08 . 2004-03-20 09:17 -------- d--h--w c:\program files\InstallShield Installation Information
    2009-04-29 14:20 . 2004-03-20 09:15 -------- d-----w c:\program files\Fichiers communs\Adobe
    2009-04-29 14:16 . 2009-03-31 09:50 -------- d-----w c:\program files\NOS
    2009-04-29 05:42 . 2005-09-11 09:15 -------- d-----w c:\program files\Guitar Pro 4
    2009-04-27 15:14 . 2005-01-23 13:41 219648 ----a-w c:\windows\system32\uxtheme.dll
    2009-04-26 19:47 . 2005-04-13 11:58 -------- d-----w c:\program files\Raccourcis de programmes
    2009-04-24 19:44 . 2004-03-20 09:20 -------- d-----w c:\program files\Fichiers communs\Ahead
    2009-04-24 19:44 . 2004-03-20 09:19 -------- d-----w c:\program files\Ahead
    2009-04-17 14:52 . 2007-01-04 06:18 -------- d-----w c:\program files\Creative
    2009-04-16 07:21 . 2004-03-20 09:17 -------- d-----w c:\program files\Fichiers communs\InstallShield
    2009-04-15 16:49 . 2007-01-04 06:13 -------- d-----w c:\program files\Samsung
    2009-04-15 14:37 . 2007-05-17 13:20 -------- d--h--w c:\program files\Creative Installation Information
    2009-04-15 09:05 . 2008-10-22 05:09 -------- d-----w c:\program files\Java
    2009-04-14 01:02 . 2005-04-13 11:59 8224 ----a-w c:\documents and settings\paul\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-04-11 22:19 . 2009-03-25 10:53 -------- d-----w c:\program files\QuickTime
    2009-04-08 11:50 . 2009-04-08 11:50 -------- d-----w c:\program files\MSECache
    2009-04-03 09:07 . 2008-10-30 15:15 -------- d-----w c:\program files\7-Zip
    2009-03-20 11:13 . 2008-10-21 10:19 -------- d-----w c:\program files\MSBuild
    2009-03-20 11:13 . 2009-03-20 11:13 -------- d-----w c:\program files\Reference Assemblies
    2009-03-20 11:01 . 2009-03-20 11:01 -------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
    2009-03-19 19:45 . 2009-03-19 18:13 -------- d-----w c:\program files\Fichiers communs\LogiShrd
    2009-03-19 19:43 . 2008-12-20 17:24 -------- d-----w c:\program files\Logitech
    2009-03-19 16:07 . 2004-03-20 08:57 76507 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
    2009-03-19 13:38 . 2009-03-19 13:38 -------- d-----w c:\program files\Fichiers communs\xing shared
    2009-03-19 13:38 . 2009-01-27 22:08 -------- d-----w c:\program files\Fichiers communs\Real
    2009-03-19 13:37 . 2003-03-18 21:14 499712 ----a-w c:\windows\system32\msvcp71.dll
    2009-03-19 13:37 . 2003-02-21 03:42 348160 ----a-w c:\windows\system32\msvcr71.dll
    2009-03-19 11:23 . 2009-03-19 11:23 -------- d-----w c:\program files\WinPcap
    2009-03-19 11:23 . 2009-03-19 11:23 -------- d-----w c:\program files\D-Link
    2009-03-19 08:30 . 2009-03-19 07:08 -------- d-----w c:\program files\Microsoft Silverlight
    2009-03-19 07:08 . 2009-03-19 07:01 -------- d-----w c:\program files\Microsoft
    2009-03-19 06:45 . 2009-03-19 06:45 -------- d-----w c:\program files\Fichiers communs\Windows Live
    2009-03-18 16:13 . 2009-03-18 16:13 21361 ----a-w c:\windows\system32\drivers\AegisP.sys
    2009-03-16 12:18 . 2009-04-16 07:19 69448 ----a-w c:\windows\system32\XAPOFX1_3.dll
    2009-03-16 12:18 . 2009-04-16 07:19 517448 ----a-w c:\windows\system32\XAudio2_4.dll
    2009-03-16 12:18 . 2009-04-16 07:19 235352 ----a-w c:\windows\system32\xactengine3_4.dll
    2009-03-16 12:18 . 2009-04-16 07:19 22360 ----a-w c:\windows\system32\X3DAudio1_6.dll
    2009-03-09 13:27 . 2009-04-16 07:19 453456 ----a-w c:\windows\system32\d3dx10_41.dll
    2009-03-09 13:27 . 2009-04-16 07:19 1846632 ----a-w c:\windows\system32\D3DCompiler_41.dll
    2009-03-09 13:27 . 2009-04-16 07:19 4178264 ----a-w c:\windows\system32\D3DX9_41.dll
    2009-03-09 03:19 . 2009-03-19 07:15 410984 ----a-w c:\windows\system32\deploytk.dll
    2009-03-08 03:34 . 2005-01-23 13:41 914944 ----a-w c:\windows\system32\wininet.dll
    2009-03-08 03:34 . 2005-01-23 13:40 43008 ----a-w c:\windows\system32\licmgr10.dll
    2009-03-08 03:33 . 2005-01-23 13:40 18944 ----a-w c:\windows\system32\corpol.dll
    2009-03-08 03:33 . 2005-01-23 13:41 420352 ----a-w c:\windows\system32\vbscript.dll
    2009-03-08 03:32 . 2005-01-23 13:40 72704 ----a-w c:\windows\system32\admparse.dll
    2009-03-08 03:32 . 2005-01-23 13:40 71680 ----a-w c:\windows\system32\iesetup.dll
    2009-03-08 03:31 . 2005-01-23 13:40 34816 ----a-w c:\windows\system32\imgutil.dll
    2009-03-08 03:31 . 2005-01-23 13:40 48128 ----a-w c:\windows\system32\mshtmler.dll
    2009-03-08 03:31 . 2005-01-23 13:40 45568 ----a-w c:\windows\system32\mshta.exe
    2009-03-08 03:22 . 2005-01-23 13:40 156160 ----a-w c:\windows\system32\msls31.dll
    2009-03-06 14:20 . 2005-01-23 13:40 286720 ----a-w c:\windows\system32\pdh.dll
    2009-02-10 17:06 . 2004-08-04 00:48 2068096 ----a-w c:\windows\system32\ntkrnlpa.exe
    2009-02-09 14:05 . 2005-01-23 13:41 1846912 ----a-w c:\windows\system32\win32k.sys
    2009-02-09 11:24 . 2005-01-23 13:40 2191104 ----a-w c:\windows\system32\ntoskrnl.exe
    2009-02-09 11:23 . 2005-01-23 13:40 111104 ----a-w c:\windows\system32\services.exe
    2009-02-09 10:53 . 2005-01-23 13:40 735744 ----a-w c:\windows\system32\lsasrv.dll
    2009-02-09 10:53 . 2005-01-23 13:40 401408 ----a-w c:\windows\system32\rpcss.dll
    2009-02-09 10:53 . 2005-01-23 13:40 739840 ----a-w c:\windows\system32\ntdll.dll
    2009-02-09 10:53 . 2005-01-23 13:40 685568 ----a-w c:\windows\system32\advapi32.dll
    2006-07-23 18:40 . 2006-07-23 18:40 1753407 ----a-w c:\program files\Fichiers communs\20060414_plan_tram.pdf
    2006-06-03 10:40 . 2006-06-03 10:40 11159 ----a-w c:\program files\Fichiers communs\coderoute.htm
    2006-04-16 06:32 . 2006-04-16 06:31 4752968 ----a-w c:\program files\MsgPlus-363.exe
    2006-04-05 17:16 . 2006-04-05 17:16 506758 ----a-w c:\program files\Fichiers communs\seins_pendouilleurs.zip
    2006-04-05 17:16 . 2006-04-04 16:16 538778 ----a-w c:\program files\Fichiers communs\seins_pendouilleurs.mpeg
    2006-04-04 17:57 . 2006-04-04 17:57 2071623 ----a-w c:\program files\Fichiers communs\capotesviepratique.wmv
    2006-04-04 17:06 . 2006-04-04 17:06 1039674 ----a-w c:\program files\Fichiers communs\iliketomoveit.wmv
    2006-04-03 18:39 . 2006-04-03 18:39 805027 ----a-w c:\program files\Fichiers communs\lullig.asx
    2006-04-03 15:51 . 2006-04-03 15:51 1467579 ----a-w c:\program files\Fichiers communs\ameriquest_fly.wmv
    2006-04-01 09:32 . 2006-04-01 09:32 16259 ----a-w c:\program files\factureFEL
    2006-02-25 11:41 . 2006-02-11 07:14 278528 ----a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
    2006-02-11 07:57 . 2006-02-11 07:57 4752968 ----a-w c:\program files\MsgPlus-361.exe
    2006-02-11 07:45 . 2006-02-11 07:43 9393352 ----a-w c:\program files\Install_MSN_Messenger.EXE
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
    "OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-15 1229640]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoSMBalloonTip"= 0 (0x0)

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
    "wave"= serwvdrv.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=""

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger.lnk
    backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech SetPoint.lnk]
    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech SetPoint.lnk
    backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "Creative Service for CDROM Access"=2 (0x2)
    "UPS"=3 (0x3)
    "JavaQuickStarterService"=3 (0x3)
    "VSS"=3 (0x3)
    "helpsvc"=3 (0x3)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
    "c:\\WINDOWS\\system32\\mmc.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

    R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [30/04/2009 09:01 704384]
    R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [29/04/2009 12:09 108289]
    R2 LxrSII1d;Secure II Driver;c:\windows\system32\drivers\LxrSII1d.sys [05/12/2008 15:31 72672]
    R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [30/04/2009 08:59 31128]
    R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [30/04/2009 09:01 257432]
    S2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [30/04/2009 08:59 1267528]
    S3 ASWFilt;ASWFilt;c:\windows\system32\Filt\ASWFilt.dll [30/04/2009 09:01 33888]
    S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\drivers\netr28u.sys [18/03/2009 17:46 552448]
    S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [25/01/2007 19:31 42000]
    S3 pnicml;pnicml;\??\c:\docume~1\paul\LOCALS~1\Temp\pnicml.sys --> c:\docume~1\paul\LOCALS~1\Temp\pnicml.sys [?]
    S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\DRIVERS\rt2870.sys --> c:\windows\system32\DRIVERS\rt2870.sys [?]
    S3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\sis163u.sys --> c:\windows\system32\DRIVERS\sis163u.sys [?]
    S3 viafilter;VIA USB Filter;c:\windows\system32\drivers\viausb1.sys [26/04/2009 21:56 9728]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
    \Shell\AutoRun\command - E:\LaunchU3.exe -a
    .
    Contenu du dossier 'Tâches planifiées'

    2009-04-27 c:\windows\Tasks\User_Feed_Synchronization-{887CF9D9-420B-4A97-AEA3-681475F6B52F}.job
    - c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
    .
    - - - - ORPHELINS SUPPRIMES - - - -

    Toolbar-Locked - (no file)

    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.google.com/
    mStart Page = hxxp://www.trooner.com/
    uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/fuji/defaults/su/*https://fr.yahoo.com/?p=us
    Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    Handler: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} -
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-05-08 14:00
    Windows 5.1.2600 Service Pack 3 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************
    .
    --------------------- DLLs chargées dans les processus actifs ---------------------

    - - - - - - - > 'winlogon.exe'(1260)
    c:\windows\system32\Ati2evxx.dll

    - - - - - - - > 'explorer.exe'(2904)
    c:\windows\TEMP\logishrd\LVPrcInj01.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\eappprxy.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Autres processus actifs ------------------------
    .
    c:\windows\system32\ati2evxx.exe
    c:\program files\Avira\AntiVir Desktop\avguard.exe
    c:\program files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    c:\windows\system32\MsPMSPSv.exe
    c:\windows\system32\ati2evxx.exe
    .
    **************************************************************************
    .
    Heure de fin: 2009-05-08 14:04 - La machine a redémarré
    ComboFix-quarantined-files.txt 2009-05-08 12:04

    Avant-CF: 180 192 129 024 octets libres
    Après-CF: 180 109 725 696 octets libres

    WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

    273 --- E O F --- 2009-04-29 18:42

    Verdict cher nanard lol
    0
  19. Alex Mumu Messages postés 16 Statut Membre
     
    En regardant le rapport jai trouvé des fichiers louches lol. Ce pc appartenait à mon frère avant beurk.
    0
  20. Alex Mumu Messages postés 16 Statut Membre
     
    dsl mauvaise manip
    0
  21. Utilisateur anonyme
     
    /!\ ATTENTION /!\ Le script qui suit a été écrit spécialement pour Alex Mumu, il n'est pas transposable sur un autre ordinateur !

    • Télécharge ce dossier Alex Mumu.zip
    • Fais un clic-droit dessus --> Extraire tout --> choisis le Bureau comme destination
    • Un autre dossier va apparaitre, prends le fichier CFScript.txt qui se trouve à l'intérieur et place le sur le Bureau.

    • Désactive tes logiciels de protection
    • Fais un glisser/déposer de ce fichier CFScript.txt sur le fichier Combofix.exe

    • Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
    • Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
    • Si le fichier ne s'ouvre pas, il se trouve ici → C:\ComboFix.txt

    0
    1. Alex Mumu Messages postés 16 Statut Membre
       
      ComboFix 09-05-07.A01 - paul 08/05/2009 16:36.2 - NTFSx86
      Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.511.280 [GMT 2:00]
      Lancé depuis: c:\documents and settings\paul\Bureau\ComboFix.exe
      Commutateurs utilisés :: c:\documents and settings\paul\Bureau\CFScript.txt
      AV: AntiVir Desktop *On-access scanning disabled* (Updated)
      FW: Outpost Firewall Pro *disabled*

      FILE ::
      c:\docume~1\jenny\LOCALS~1\Temp\pnicml.sys
      .

      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .

      .
      ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      -------\Legacy_PNICML
      -------\Service_pnicml


      ((((((((((((((((((((((((((((( Fichiers créés du 2009-04-08 au 2009-05-08 ))))))))))))))))))))))))))))))))))))
      .

      2009-05-06 10:23 . 2009-05-06 10:24 -------- d--h--w c:\documents and settings\All Users\Application Data\{148D8B8A-8F96-4822-81EC-D510B626B7D5}
      2009-05-06 09:17 . 2009-05-06 09:17 -------- d-----w c:\documents and settings\paul\Application Data\ATI
      2009-05-06 09:17 . 2009-05-06 09:17 -------- d-----w c:\documents and settings\paul\Local Settings\Application Data\ATI
      2009-05-06 09:09 . 2006-05-03 09:57 520192 ------w c:\windows\system32\ati2sgag.exe
      2009-05-06 09:03 . 2009-05-06 10:25 -------- d-----w c:\documents and settings\All Users\Application Data\DriverScanner
      2009-05-05 07:47 . 2009-05-05 07:47 -------- d-----w c:\program files\Windows Live SkyDrive
      2009-05-05 07:46 . 2009-05-05 07:47 -------- d-----w c:\program files\Windows Live
      2009-05-01 06:26 . 2009-05-01 06:26 -------- d-----w c:\program files\Tracker Software
      2009-04-30 07:01 . 2009-04-06 09:37 704384 ----a-w c:\windows\system32\drivers\SandBox.sys
      2009-04-30 07:01 . 2009-02-10 14:15 257432 ----a-w c:\windows\system32\drivers\afwcore.sys
      2009-04-30 06:59 . 2009-02-18 15:30 31128 ----a-w c:\windows\system32\drivers\afw.sys
      2009-04-30 06:59 . 2009-05-08 06:57 -------- d-----w c:\windows\system32\Filt
      2009-04-30 06:59 . 2009-04-30 06:59 -------- d-----w c:\program files\Agnitum
      2009-04-30 06:58 . 2009-04-30 06:58 -------- d-----w c:\documents and settings\All Users\Application Data\Agnitum
      2009-04-30 06:27 . 2009-05-06 09:03 -------- d-----w c:\documents and settings\paul\Application Data\Uniblue
      2009-04-29 18:40 . 2009-04-29 18:40 -------- d-sh--w c:\documents and settings\Default User\IETldCache
      2009-04-29 10:10 . 2009-04-29 10:10 -------- d-----w c:\documents and settings\NetworkService\Menu Démarrer
      2009-04-29 10:09 . 2009-03-24 14:07 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
      2009-04-29 10:09 . 2009-04-29 10:09 -------- d-----w c:\documents and settings\All Users\Application Data\Avira
      2009-04-29 10:09 . 2009-04-29 10:09 -------- d-----w c:\program files\Avira
      2009-04-27 15:14 . 2009-04-27 15:14 65541 ----a-w c:\windows\BricoPackUninst.cmd
      2009-04-27 15:10 . 2009-04-27 15:14 6112 ----a-w c:\windows\BricoPackFoldersDelete.cmd
      2009-04-26 19:57 . 2009-05-06 09:10 -------- d-----w c:\program files\ATI Technologies
      2009-04-26 19:56 . 2001-09-19 11:28 9728 ----a-w c:\windows\system32\drivers\viausb1.sys
      2009-04-26 19:55 . 2009-04-26 19:55 -------- d-----w C:\ATI
      2009-04-26 19:53 . 2001-09-23 23:10 306688 ----a-w c:\windows\IsUninst.exe
      2009-04-26 19:53 . 2009-04-26 19:53 -------- d-----w c:\documents and settings\paul\WINDOWS
      2009-04-26 19:33 . 2009-04-26 19:58 -------- d-----w c:\documents and settings\paul\Application Data\IObit
      2009-04-26 07:41 . 2009-04-26 07:41 -------- d-----w c:\program files\FreshDevices
      2009-04-25 17:50 . 2009-05-06 18:32 -------- d-----w c:\documents and settings\All Users\Application Data\WinZip
      2009-04-23 17:32 . 2009-04-23 17:32 232784 ----a-w c:\windows\Matrix Code.scr
      2009-04-23 17:16 . 2009-05-03 16:15 -------- d-----w c:\program files\Spybot - Search & Destroy
      2009-04-20 11:05 . 2009-04-20 11:05 -------- d-----w c:\windows\Sun
      2009-04-18 11:01 . 2009-05-08 14:27 -------- d-----w c:\documents and settings\paul\Tracing
      2009-04-16 07:23 . 2009-04-16 07:23 -------- d-----w c:\program files\Fichiers communs\Ulead
      2009-04-16 07:22 . 2009-04-16 07:22 -------- d-----w c:\documents and settings\All Users\Application Data\InstallShield
      2009-04-16 07:17 . 2009-04-16 07:17 -------- d-----w c:\windows\Logs
      2009-04-15 16:47 . 2009-04-15 16:47 80860 ---ha-w c:\windows\system32\mlfcache.dat
      2009-04-15 15:00 . 2009-04-15 15:00 -------- d-----w c:\program files\Windows Media Connect 2
      2009-04-15 08:36 . 2009-02-09 11:23 111104 ------w c:\windows\system32\dllcache\services.exe
      2009-04-15 08:36 . 2009-02-09 10:53 401408 ------w c:\windows\system32\dllcache\rpcss.dll
      2009-04-15 08:36 . 2009-02-09 10:53 473600 ------w c:\windows\system32\dllcache\fastprox.dll
      2009-04-15 08:36 . 2009-02-09 10:53 685568 ------w c:\windows\system32\dllcache\advapi32.dll
      2009-04-15 08:36 . 2009-02-09 10:53 735744 ------w c:\windows\system32\dllcache\lsasrv.dll
      2009-04-15 08:36 . 2009-02-09 10:53 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
      2009-04-15 08:36 . 2009-02-09 10:53 739840 ------w c:\windows\system32\dllcache\ntdll.dll
      2009-04-15 08:34 . 2008-12-16 12:31 354304 ------w c:\windows\system32\dllcache\winhttp.dll
      2009-04-14 01:02 . 2009-04-16 08:30 101392 ----a-w c:\windows\system32\GDIPFONTCACHEV1.DAT
      2009-04-13 16:49 . 2004-08-05 12:00 185344 ----a-w c:\windows\system32\dllcache\thawbrkr.dll
      2009-04-13 16:49 . 2004-08-05 12:00 185344 ----a-w c:\windows\system32\Thawbrkr.dll
      2009-04-13 16:49 . 2004-08-05 12:00 10752 ----a-w c:\windows\system32\dllcache\c_iscii.dll
      2009-04-13 16:49 . 2004-08-05 12:00 10752 ----a-w c:\windows\system32\c_iscii.dll
      2009-04-13 16:49 . 2004-08-05 12:00 5632 ----a-w c:\windows\system32\dllcache\kbdusa.dll
      2009-04-13 16:49 . 2004-08-05 12:00 5632 ----a-w c:\windows\system32\kbdusa.dll
      2009-04-13 16:49 . 2004-08-05 12:00 6144 ----a-w c:\windows\system32\dllcache\ftlx041e.dll
      2009-04-13 16:49 . 2004-08-05 12:00 6144 ----a-w c:\windows\system32\ftlx041e.dll
      2009-04-12 16:33 . 2009-04-12 16:33 -------- d-----w c:\documents and settings\paul\Application Data\AVS4YOU
      2009-04-12 16:31 . 2009-04-12 16:44 -------- d-----w c:\program files\Fichiers communs\AVSMedia
      2009-04-12 16:30 . 2009-04-16 06:53 -------- d-----w c:\windows\system32\drivers\umdf
      2009-04-12 16:28 . 2009-01-28 18:49 974848 ----a-w c:\windows\system32\mfc70.dll
      2009-04-10 15:28 . 2009-04-10 15:28 -------- d-----w c:\program files\Fichiers communs\DivX Shared
      2009-04-10 15:28 . 2009-04-10 15:29 -------- d-----w c:\program files\DivX

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2009-05-08 14:39 . 2009-03-19 18:19 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
      2009-05-08 14:39 . 2009-03-19 18:18 0 ----a-w c:\windows\system32\drivers\logiflt.iad
      2009-05-08 12:01 . 2005-01-23 13:41 86274 ----a-w c:\windows\system32\perfc00C.dat
      2009-05-08 12:01 . 2005-01-23 13:41 514630 ----a-w c:\windows\system32\perfh00C.dat
      2009-05-06 22:43 . 2009-03-22 15:03 -------- d-----w c:\program files\CCleaner
      2009-05-06 09:08 . 2004-03-20 09:17 -------- d--h--w c:\program files\InstallShield Installation Information
      2009-04-29 14:16 . 2009-03-31 09:50 -------- d-----w c:\program files\NOS
      2009-04-29 05:42 . 2005-09-11 09:15 -------- d-----w c:\program files\Guitar Pro 4
      2009-04-27 15:14 . 2005-01-23 13:41 219648 ----a-w c:\windows\system32\uxtheme.dll
      2009-04-26 19:47 . 2005-04-13 11:58 -------- d-----w c:\program files\Raccourcis de programmes
      2009-04-24 19:44 . 2004-03-20 09:20 -------- d-----w c:\program files\Fichiers communs\Ahead
      2009-04-24 19:44 . 2004-03-20 09:19 -------- d-----w c:\program files\Ahead
      2009-04-17 14:52 . 2007-01-04 06:18 -------- d-----w c:\program files\Creative
      2009-04-16 07:21 . 2004-03-20 09:17 -------- d-----w c:\program files\Fichiers communs\InstallShield
      2009-04-15 16:49 . 2007-01-04 06:13 -------- d-----w c:\program files\Samsung
      2009-04-15 14:37 . 2007-05-17 13:20 -------- d--h--w c:\program files\Creative Installation Information
      2009-04-15 09:05 . 2008-10-22 05:09 -------- d-----w c:\program files\Java
      2009-04-14 01:02 . 2005-04-13 11:59 8224 ----a-w c:\documents and settings\paul\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
      2009-04-11 22:19 . 2009-03-25 10:53 -------- d-----w c:\program files\QuickTime
      2009-04-08 11:50 . 2009-04-08 11:50 -------- d-----w c:\program files\MSECache
      2009-03-20 11:13 . 2008-10-21 10:19 -------- d-----w c:\program files\MSBuild
      2009-03-20 11:13 . 2009-03-20 11:13 -------- d-----w c:\program files\Reference Assemblies
      2009-03-20 11:01 . 2009-03-20 11:01 -------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
      2009-03-19 19:45 . 2009-03-19 18:13 -------- d-----w c:\program files\Fichiers communs\LogiShrd
      2009-03-19 19:43 . 2008-12-20 17:24 -------- d-----w c:\program files\Logitech
      2009-03-19 16:07 . 2004-03-20 08:57 76507 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
      2009-03-19 13:38 . 2009-03-19 13:38 -------- d-----w c:\program files\Fichiers communs\xing shared
      2009-03-19 13:38 . 2009-01-27 22:08 -------- d-----w c:\program files\Fichiers communs\Real
      2009-03-19 13:37 . 2003-03-18 21:14 499712 ----a-w c:\windows\system32\msvcp71.dll
      2009-03-19 13:37 . 2003-02-21 03:42 348160 ----a-w c:\windows\system32\msvcr71.dll
      2009-03-19 11:23 . 2009-03-19 11:23 -------- d-----w c:\program files\WinPcap
      2009-03-19 11:23 . 2009-03-19 11:23 -------- d-----w c:\program files\D-Link
      2009-03-19 08:30 . 2009-03-19 07:08 -------- d-----w c:\program files\Microsoft Silverlight
      2009-03-19 07:08 . 2009-03-19 07:01 -------- d-----w c:\program files\Microsoft
      2009-03-19 06:45 . 2009-03-19 06:45 -------- d-----w c:\program files\Fichiers communs\Windows Live
      2009-03-18 16:13 . 2009-03-18 16:13 21361 ----a-w c:\windows\system32\drivers\AegisP.sys
      2009-03-16 12:18 . 2009-04-16 07:19 69448 ----a-w c:\windows\system32\XAPOFX1_3.dll
      2009-03-16 12:18 . 2009-04-16 07:19 517448 ----a-w c:\windows\system32\XAudio2_4.dll
      2009-03-16 12:18 . 2009-04-16 07:19 235352 ----a-w c:\windows\system32\xactengine3_4.dll
      2009-03-16 12:18 . 2009-04-16 07:19 22360 ----a-w c:\windows\system32\X3DAudio1_6.dll
      2009-03-09 13:27 . 2009-04-16 07:19 453456 ----a-w c:\windows\system32\d3dx10_41.dll
      2009-03-09 13:27 . 2009-04-16 07:19 1846632 ----a-w c:\windows\system32\D3DCompiler_41.dll
      2009-03-09 13:27 . 2009-04-16 07:19 4178264 ----a-w c:\windows\system32\D3DX9_41.dll
      2009-03-09 03:19 . 2009-03-19 07:15 410984 ----a-w c:\windows\system32\deploytk.dll
      2009-03-08 03:34 . 2005-01-23 13:41 914944 ----a-w c:\windows\system32\wininet.dll
      2009-03-08 03:34 . 2005-01-23 13:40 43008 ----a-w c:\windows\system32\licmgr10.dll
      2009-03-08 03:33 . 2005-01-23 13:40 18944 ----a-w c:\windows\system32\corpol.dll
      2009-03-08 03:33 . 2005-01-23 13:41 420352 ----a-w c:\windows\system32\vbscript.dll
      2009-03-08 03:32 . 2005-01-23 13:40 72704 ----a-w c:\windows\system32\admparse.dll
      2009-03-08 03:32 . 2005-01-23 13:40 71680 ----a-w c:\windows\system32\iesetup.dll
      2009-03-08 03:31 . 2005-01-23 13:40 34816 ----a-w c:\windows\system32\imgutil.dll
      2009-03-08 03:31 . 2005-01-23 13:40 48128 ----a-w c:\windows\system32\mshtmler.dll
      2009-03-08 03:31 . 2005-01-23 13:40 45568 ----a-w c:\windows\system32\mshta.exe
      2009-03-08 03:22 . 2005-01-23 13:40 156160 ----a-w c:\windows\system32\msls31.dll
      2009-03-06 14:20 . 2005-01-23 13:40 286720 ----a-w c:\windows\system32\pdh.dll
      2009-02-10 17:06 . 2004-08-04 00:48 2068096 ----a-w c:\windows\system32\ntkrnlpa.exe
      2009-02-09 14:05 . 2005-01-23 13:41 1846912 ----a-w c:\windows\system32\win32k.sys
      2009-02-09 11:24 . 2005-01-23 13:40 2191104 ----a-w c:\windows\system32\ntoskrnl.exe
      2009-02-09 11:23 . 2005-01-23 13:40 111104 ----a-w c:\windows\system32\services.exe
      2009-02-09 10:53 . 2005-01-23 13:40 735744 ----a-w c:\windows\system32\lsasrv.dll
      2009-02-09 10:53 . 2005-01-23 13:40 401408 ----a-w c:\windows\system32\rpcss.dll
      2009-02-09 10:53 . 2005-01-23 13:40 739840 ----a-w c:\windows\system32\ntdll.dll
      2009-02-09 10:53 . 2005-01-23 13:40 685568 ----a-w c:\windows\system32\advapi32.dll
      2006-04-03 18:39 . 2006-04-03 18:39 805027 ----a-w c:\program files\Fichiers communs\lullig.asx
      2006-04-01 09:32 . 2006-04-01 09:32 16259 ----a-w c:\program files\factureFEL
      2006-02-25 11:41 . 2006-02-11 07:14 278528 ----a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
      .

      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
      "OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-15 1229640]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
      "NoSMBalloonTip"= 0 (0x0)

      HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
      "wave"= serwvdrv.dll

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
      @=""

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
      path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger.lnk
      backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech SetPoint.lnk]
      path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech SetPoint.lnk
      backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
      "Creative Service for CDROM Access"=2 (0x2)
      "UPS"=3 (0x3)
      "JavaQuickStarterService"=3 (0x3)
      "VSS"=3 (0x3)
      "helpsvc"=2 (0x2)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "EnableFirewall"= 0 (0x0)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
      "c:\\WINDOWS\\system32\\mmc.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

      R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [30/04/2009 09:01 704384]
      R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [29/04/2009 12:09 108289]
      R2 LxrSII1d;Secure II Driver;c:\windows\system32\drivers\LxrSII1d.sys [05/12/2008 15:31 72672]
      R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [30/04/2009 08:59 31128]
      R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [30/04/2009 09:01 257432]
      S2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [30/04/2009 08:59 1267528]
      S3 ASWFilt;ASWFilt;c:\windows\system32\Filt\ASWFilt.dll [30/04/2009 09:01 33888]
      S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\drivers\netr28u.sys [18/03/2009 17:46 552448]
      S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [25/01/2007 19:31 42000]
      S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\DRIVERS\rt2870.sys --> c:\windows\system32\DRIVERS\rt2870.sys [?]
      S3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\sis163u.sys --> c:\windows\system32\DRIVERS\sis163u.sys [?]
      S3 viafilter;VIA USB Filter;c:\windows\system32\drivers\viausb1.sys [26/04/2009 21:56 9728]

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
      \Shell\AutoRun\command - E:\LaunchU3.exe -a
      .
      Contenu du dossier 'Tâches planifiées'

      2009-04-27 c:\windows\Tasks\User_Feed_Synchronization-{887CF9D9-420B-4A97-AEA3-681475F6B52F}.job
      - c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
      .
      .
      ------- Examen supplémentaire -------
      .
      uStart Page = hxxp://www.google.com/
      mStart Page = hxxp://www.trooner.com/
      uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/fuji/defaults/su/*https://fr.yahoo.com/?p=us
      Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
      Handler: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} -
      .

      **************************************************************************

      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2009-05-08 16:43
      Windows 5.1.2600 Service Pack 3 NTFS

      Recherche de processus cachés ...

      Recherche d'éléments en démarrage automatique cachés ...

      Recherche de fichiers cachés ...

      Scan terminé avec succès
      Fichiers cachés: 0

      **************************************************************************
      .
      --------------------- DLLs chargées dans les processus actifs ---------------------

      - - - - - - - > 'winlogon.exe'(1248)
      c:\windows\system32\Ati2evxx.dll

      - - - - - - - > 'explorer.exe'(5676)
      c:\windows\TEMP\logishrd\LVPrcInj01.dll
      c:\windows\system32\ieframe.dll
      c:\windows\system32\webcheck.dll
      c:\windows\system32\WPDShServiceObj.dll
      c:\windows\system32\eappprxy.dll
      c:\windows\system32\PortableDeviceTypes.dll
      c:\windows\system32\PortableDeviceApi.dll
      .
      ------------------------ Autres processus actifs ------------------------
      .
      c:\windows\system32\ati2evxx.exe
      c:\program files\Avira\AntiVir Desktop\avguard.exe
      c:\program files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      c:\windows\system32\MsPMSPSv.exe
      c:\windows\system32\ati2evxx.exe
      .
      **************************************************************************
      .
      Heure de fin: 2009-05-08 16:47 - La machine a redémarré
      ComboFix-quarantined-files.txt 2009-05-08 14:47

      Avant-CF: 180 124 073 984 octets libres
      Après-CF: 180 114 808 832 octets libres

      256 --- E O F --- 2009-04-29 18:42
      0
      1. Utilisateur anonyme > Alex Mumu Messages postés 16 Statut Membre
         
        Bien .Cette fois il a été supprimé.Pour vérifier post un nouveau rsit et dit moi si tu as toujours des problèmes avec ton pc.
        0
  • 1
  • 2