Pc lent +rapport

patracem -  
 Utilisateur anonyme -
Bonjour,mon pc est lent .je recherche de l'aide apparemment je serais infecté par quelques virus.

ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:04:31, on 02/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\keyhook.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Orange\Launcher\Launcher.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Shareaza\Shareaza.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\HELPAN~1\Presario\XPHWWRF4\plugin\bin\pchbutton.exe
C:\documents and settings\compaq_propriétaire\local settings\application data\flsjahoe.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Orange\Deskboard\deskboard.exe
C:\Program Files\Orange\connectivity\connectivitymanager.exe
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=presario&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searcheo.fr/france
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60264
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60264
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60264
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60264
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://support.norton.com/sp/fr/fr/home/current/solutions/v58540272?abproduct=LU&abversion=1.90&build=Symantec&ced=true&entsrc=CED_pubweb&error=1814&module=LU&src=_mi
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer fourni par Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - (no file)
R3 - URLSearchHook: (no name) - {814C76CB-2623-43F4-AAD0-58A0E5190A20} - (no file)
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44CF-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Shareaza\Plugins\RazaWebHook.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Secured eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Program Files\Need2Find\bar\2.bin\ND2FNBAR.DLL (file missing)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: (no name) - {DB35C569-5624-4CFC-8043-E5139F55A073} - C:\PROGRA~1\Crawler\Shared\CShared.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Secured eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [sysfbtray] C:\windows\freddy46.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [EPSON Stylus DX4200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE /P26 "EPSON Stylus DX4200 Series" /O6 "USB001" /M "Stylus DX4200"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Compaq_Propriétaire] C:\Documents and Settings\Compaq_Propriétaire\Compaq_Propriétaire.exe /i
O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HELPAN~1\Presario\XPHWWRF4\plugin\bin\pchbutton.exe
O4 - HKCU\..\Run: [flsjahoe] "c:\documents and settings\compaq_propriétaire\local settings\application data\flsjahoe.exe" flsjahoe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRxdm674YYFR
O8 - Extra context menu item: ajouter cette page à vos favoris Orange - C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\cce660.html
O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Shareaza\Plugins\RazaWebHook.dll/3000
O8 - Extra context menu item: traduire la page - C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\cce65E.html
O8 - Extra context menu item: traduire le texte sélectionné - C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\cce65F.html
O9 - Extra button: Crawler Screensaver - {CDAFD956-97BE-443D-8EF7-F4F094EB5766} - C:\Program Files\Crawler\SSaver\CSSaver.exe
O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: https://www.orange.fr/portail
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/PopularScreenSaversInitialSetup1.0.1.1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?e=1232621260938&h=23adf2255bb2954a1a4d17d5efb6f691/&filename=jinstall-6u11-windows-i586-jc.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game01.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Update Service (gupdate1c9726b9996aa68) (gupdate1c9726b9996aa68) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O24 - Desktop Component 0: (no name) - http://www.couriramorlaix.com/courir%20a%20morlaix/fichier_photo-videos/diaporamas/st-martin2007_15km/medium/0012.jpg
O24 - Desktop Component 1: (no name) - https://www.marmiton.org/App_Themes/Recettes/img/recettes/recette_titre.gif2
A voir également:

47 réponses

patracem
 
je ne que cela qui s'affiche apres le scan
0
Utilisateur anonyme
 
Vérifie dans la source de ton DD (disque local C:\\)
0
patracem
 
List'em by g3n-h@ckm@n 1.1.0.0

Thx to Chiquitine29.....

User : Compaq_Propriétaire () # RACHEL
Update on 02/12/2009 by g3n-h@ckm@n ::::: 23:00
Start at: 15:41:55 | 03/12/2009
Contact : g3n-h@ckm@n sur CCM

AMD Sempron(tm) 3000+
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : avast! antivirus 4.8.1335 [VPS 091203-1] 4.8.1335 [ Enabled | Updated ]
FW : G DATA Personal Firewall[ (!) Disabled ]1.0

A:\ -> Lecteur de disquettes 3 ½ pouces
C:\ -> Disque fixe local | 144,64 Go (92,8 Go free) [PRESARIO] | NTFS
D:\ -> Disque fixe local | 4,4 Go (1,19 Go free) [PRESARIO_RP] | FAT32
E:\ -> Disque CD-ROM

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

C:\WINDOWS\System32\smss.exe 596
C:\WINDOWS\system32\csrss.exe 660
C:\WINDOWS\system32\winlogon.exe 684
C:\WINDOWS\system32\services.exe 732
C:\WINDOWS\system32\lsass.exe 744
C:\WINDOWS\system32\svchost.exe 904
C:\WINDOWS\system32\svchost.exe 984
C:\WINDOWS\System32\svchost.exe 1080
C:\WINDOWS\system32\svchost.exe 1140
C:\WINDOWS\system32\svchost.exe 1212
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 1544
C:\WINDOWS\Explorer.EXE 1552
C:\Program Files\Alwil Software\Avast4\ashServ.exe 1600
C:\WINDOWS\system32\spoolsv.exe 1892
C:\WINDOWS\system32\svchost.exe 1956
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe 2016
C:\WINDOWS\system32\svchost.exe 300
C:\Program Files\Java\jre6\bin\jqs.exe 424
C:\WINDOWS\System32\svchost.exe 568
C:\WINDOWS\system32\nvsvc32.exe 1020
C:\WINDOWS\System32\svchost.exe 1044
C:\WINDOWS\system32\svchost.exe 1204
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe 2648
C:\Program Files\Orange\Systray\SystrayApp.exe 2656
C:\Program Files\Java\jre6\bin\jusched.exe 2664
C:\WINDOWS\system32\keyhook.exe 2672
C:\HP\KBD\KBD.EXE 2740
C:\Program Files\iTunes\iTunesHelper.exe 2748
C:\windows\system\hpsysdrv.exe 2756
C:\WINDOWS\ALCXMNTR.EXE 2788
C:\WINDOWS\AGRSMMSG.exe 2796
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe 2808
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe 2880
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe 2896
C:\Program Files\Orange\Launcher\Launcher.exe 3080
C:\WINDOWS\system32\ctfmon.exe 3148
C:\Program Files\Shareaza\Shareaza.exe 3168
C:\Program Files\Messenger\msmsgs.exe 3180
C:\PROGRA~1\HELPAN~1\Presario\XPHWWRF4\plugin\bin\pchbutton.exe 3188
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe 3216
C:\WINDOWS\system32\wuauclt.exe 3328
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 3596
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 3828
C:\Program Files\iPod\bin\iPodService.exe 224
C:\WINDOWS\System32\alg.exe 1288
C:\WINDOWS\System32\svchost.exe 2488
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe 3312
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe 1688
C:\Program Files\Orange\Deskboard\deskboard.exe 3488
C:\Program Files\Orange\connectivity\connectivitymanager.exe 2456
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe 316
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe 264
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe 3896
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe 3908
C:\WINDOWS\system32\wbem\wmiprvse.exe 628
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe 2564
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe 3336
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe 1500
C:\Documents and Settings\Compaq_Propriétaire\Mes documents\Downloads\List_Killem\List_Kill'em.exe 3068
C:\WINDOWS\system32\cmd.exe 2476
C:\WINDOWS\system32\wbem\wmiprvse.exe 1324
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temp\665.tmp\pv.exe 2308

======================
Keys "Run"
======================

! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
WOOKIT REG_SZ C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
Shareaza REG_SZ "C:\Program Files\Shareaza\Shareaza.exe" -tray
msnmsgr REG_SZ "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
MSMSGS REG_SZ "C:\Program Files\Messenger\msmsgs.exe" /background
Compaq_Propriétaire REG_SZ C:\Documents and Settings\Compaq_Propriétaire\Compaq_Propriétaire.exe /i
Acme.PCHButton REG_SZ C:\PROGRA~1\HELPAN~1\Presario\XPHWWRF4\plugin\bin\pchbutton.exe

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
VTTimer REG_SZ VTTimer.exe
SystrayORAHSS REG_SZ "C:\Program Files\Orange\Systray\SystrayApp.exe"
SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
SiS Windows KeyHook REG_SZ C:\WINDOWS\system32\keyhook.exe
Recguard REG_SZ C:\WINDOWS\SMINST\RECGUARD.EXE
PS2 REG_SZ C:\WINDOWS\system32\ps2.exe
ORAHSSSessionManager REG_SZ C:\Program Files\Orange\SessionManager\SessionManager.exe
nwiz REG_SZ nwiz.exe /installquiet /keeploaded /nodetect
NvCplDaemon REG_SZ RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
KBD REG_SZ C:\HP\KBD\KBD.EXE
iTunesHelper REG_SZ "C:\Program Files\iTunes\iTunesHelper.exe"
hpsysdrv REG_SZ c:\windows\system\hpsysdrv.exe
EPSON Stylus DX4200 Series REG_SZ C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE /P26 "EPSON Stylus DX4200 Series" /O6 "USB001" /M "Stylus DX4200"
AlcxMonitor REG_SZ ALCXMNTR.EXE
AGRSMMSG REG_SZ AGRSMMSG.exe
Adobe Photo Downloader REG_SZ "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
HP Software Update REG_SZ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
hpqSRMon REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Adobe ARM REG_SZ "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
Malwarebytes Anti-Malware (reboot) REG_SZ "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents
=====================
Other Keys
=====================

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System
dontdisplaylastusername REG_DWORD 0x0
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
shutdownwithoutlogon REG_DWORD 0x1
undockwithoutlogon REG_DWORD 0x1
===============

===============
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
===============
BHO :
======

========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

Ndisuio : 0x3
EapHost : 0x3
SharedAccess : 0x2
wuauserv : 0x2
=========

=========================
Environnement variables :
=========================

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Compaq_Propri‚taire\Application Data
choix=1
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Fichiers communs
COMPUTERNAME=RACHEL
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Compaq_Propri‚taire
LOGONSERVER=\\RACHEL
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;c:\Python22;C:\Program Files\PC-Doctor for Windows\services
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0a00
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp
USERDOMAIN=RACHEL
USERNAME=Compaq_Propri‚taire
USERPROFILE=C:\Documents and Settings\Compaq_Propri‚taire
windir=C:\WINDOWS

¤¤¤¤¤¤¤¤¤¤ Files/folders :

C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
C:\Program Files\Crawler
C:\Program Files\GamesBar
C:\Program Files\KaZaA
C:\Program Files\Need2Find
C:\WINDOWS\iun6002.exe
C:\WINDOWS\System32\cagzht_navup.dat
C:\WINDOWS\System32\ACTSKN43.ocx
C:\WINDOWS\System32\drivers\etc\hosts.msn
C:\WINDOWS\system32\drivers\Sonyhcp.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\ps2.bat
C:\WINDOWS\System32\SET182.tmp
C:\WINDOWS\System32\SET187.tmp
C:\WINDOWS\System32\SET18E.tmp
C:\WINDOWS\System32\SET197.tmp
C:\WINDOWS\System32\SET199.tmp
C:\WINDOWS\System32\SET19C.tmp
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\hpzmsi01.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\hpzscr01.EXE
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\hpzswp01.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\installation.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\PxCpyA64.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\PxCpyI64.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\pxhpinst.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\PxInsA64.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\PxInsI64.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\pxsetup.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\setup_wm.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is1.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is2.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is22B.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is233.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is234.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is235.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is238.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is239.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is3.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is4.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is41A.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is41C.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is41D.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is41E.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is420.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is421.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is422.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is424.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is437.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is438.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is43B.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is459.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is45A.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is4AB.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is4AC.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is5.exe

¤¤¤¤¤¤¤¤¤¤ Keys :

HKU\S-1-5-21-1499807320-3828894901-3313630303-1007\Software\Microsoft\Windows\CurrentVersion\Run "avgsys"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "3wPlayer Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "4 ROAD"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "63651021"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "a00f118337.exe"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "adobe_reader"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "acxzup"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "antihost"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "AV"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "ARMY SECT"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "backup windows 2009"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Bags regs"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "BitDownload Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "BitGrabber Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "BitRoll Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "book ante"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "bwebu"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "calc"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "COPY DEBUG"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "DivoPlayer Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "GalaPlayer"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Get-Torrent Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "GreatLog"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Internet Today Task"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "mobiswing"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "mset"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "NT Printing Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "ocqcqii"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "OkayLicense"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "outil système"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "part mags"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Peak Meal"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "photo_id"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Salestart"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "secure32"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "secure64"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "sizedrv"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "style cool 2 city"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "system tool"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "That dent five else"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Tok-Cirrhatus"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "tok-cirrhatus-2289"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Torrent101 Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "TorrentQ Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "TorrentSoftware Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "VideoBarApp"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "vmmonitor"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WhenUSave"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Upgrate Utility"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "winusr"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WinZix Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Yjafosi8kdf98winmdkmnkmfnwe"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "®Update"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ".NET Application Debugger 32"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ".nvsvc"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ".nvsvcb"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_mzu_stonedrv2"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_mzu_stonedrv4"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_mzu_stonedrv5"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_mzu_stonedrv6"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_mzu_stonedrv7"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_Windows"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "0mcamcap"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "12CFG214-K641-11SF-N33P"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "12CFG214-K641-12SF-N85P"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "2chkdsk"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "3cfe250a"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "64 inter flaw hold"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Acrobat Read"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "ActiveScan Antivirus"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "adir"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "adobe_reader"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "AdobeReaderPro"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Ads checker"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Advanced DHTML Enable"
0
Utilisateur anonyme
 
▶ Relance List&Kill'em comme tu as fait pour l'option 1 (soit en clic droit pour vista),

mais cette fois-ci :

▶ choisis l'option 2 = Mode Destruction

laisse travailler l'outil.

en fin de scan un rapport s'ouvre , ferme-le puis redemarre

▶ colle le contenu dans ta reponse
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
patracem
 
voisi le compte rendu
List'em by g3n-h@ckm@n 1.1.0.0

Thx to Chiquitine29.....

User : Compaq_Propriétaire () # RACHEL
Update on 02/12/2009 by g3n-h@ckm@n ::::: 23:00
Start at: 15:41:55 | 03/12/2009
Contact : g3n-h@ckm@n sur CCM

AMD Sempron(tm) 3000+
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : avast! antivirus 4.8.1335 [VPS 091203-1] 4.8.1335 [ Enabled | Updated ]
FW : G DATA Personal Firewall[ (!) Disabled ]1.0

A:\ -> Lecteur de disquettes 3 ½ pouces
C:\ -> Disque fixe local | 144,64 Go (92,8 Go free) [PRESARIO] | NTFS
D:\ -> Disque fixe local | 4,4 Go (1,19 Go free) [PRESARIO_RP] | FAT32
E:\ -> Disque CD-ROM

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

C:\WINDOWS\System32\smss.exe 596
C:\WINDOWS\system32\csrss.exe 660
C:\WINDOWS\system32\winlogon.exe 684
C:\WINDOWS\system32\services.exe 732
C:\WINDOWS\system32\lsass.exe 744
C:\WINDOWS\system32\svchost.exe 904
C:\WINDOWS\system32\svchost.exe 984
C:\WINDOWS\System32\svchost.exe 1080
C:\WINDOWS\system32\svchost.exe 1140
C:\WINDOWS\system32\svchost.exe 1212
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 1544
C:\WINDOWS\Explorer.EXE 1552
C:\Program Files\Alwil Software\Avast4\ashServ.exe 1600
C:\WINDOWS\system32\spoolsv.exe 1892
C:\WINDOWS\system32\svchost.exe 1956
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe 2016
C:\WINDOWS\system32\svchost.exe 300
C:\Program Files\Java\jre6\bin\jqs.exe 424
C:\WINDOWS\System32\svchost.exe 568
C:\WINDOWS\system32\nvsvc32.exe 1020
C:\WINDOWS\System32\svchost.exe 1044
C:\WINDOWS\system32\svchost.exe 1204
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe 2648
C:\Program Files\Orange\Systray\SystrayApp.exe 2656
C:\Program Files\Java\jre6\bin\jusched.exe 2664
C:\WINDOWS\system32\keyhook.exe 2672
C:\HP\KBD\KBD.EXE 2740
C:\Program Files\iTunes\iTunesHelper.exe 2748
C:\windows\system\hpsysdrv.exe 2756
C:\WINDOWS\ALCXMNTR.EXE 2788
C:\WINDOWS\AGRSMMSG.exe 2796
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe 2808
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe 2880
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe 2896
C:\Program Files\Orange\Launcher\Launcher.exe 3080
C:\WINDOWS\system32\ctfmon.exe 3148
C:\Program Files\Shareaza\Shareaza.exe 3168
C:\Program Files\Messenger\msmsgs.exe 3180
C:\PROGRA~1\HELPAN~1\Presario\XPHWWRF4\plugin\bin\pchbutton.exe 3188
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe 3216
C:\WINDOWS\system32\wuauclt.exe 3328
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 3596
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 3828
C:\Program Files\iPod\bin\iPodService.exe 224
C:\WINDOWS\System32\alg.exe 1288
C:\WINDOWS\System32\svchost.exe 2488
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe 3312
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe 1688
C:\Program Files\Orange\Deskboard\deskboard.exe 3488
C:\Program Files\Orange\connectivity\connectivitymanager.exe 2456
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe 316
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe 264
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe 3896
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe 3908
C:\WINDOWS\system32\wbem\wmiprvse.exe 628
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe 2564
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe 3336
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe 1500
C:\Documents and Settings\Compaq_Propriétaire\Mes documents\Downloads\List_Killem\List_Kill'em.exe 3068
C:\WINDOWS\system32\cmd.exe 2476
C:\WINDOWS\system32\wbem\wmiprvse.exe 1324
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temp\665.tmp\pv.exe 2308

======================
Keys "Run"
======================

! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
WOOKIT REG_SZ C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
Shareaza REG_SZ "C:\Program Files\Shareaza\Shareaza.exe" -tray
msnmsgr REG_SZ "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
MSMSGS REG_SZ "C:\Program Files\Messenger\msmsgs.exe" /background
Compaq_Propriétaire REG_SZ C:\Documents and Settings\Compaq_Propriétaire\Compaq_Propriétaire.exe /i
Acme.PCHButton REG_SZ C:\PROGRA~1\HELPAN~1\Presario\XPHWWRF4\plugin\bin\pchbutton.exe

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
VTTimer REG_SZ VTTimer.exe
SystrayORAHSS REG_SZ "C:\Program Files\Orange\Systray\SystrayApp.exe"
SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
SiS Windows KeyHook REG_SZ C:\WINDOWS\system32\keyhook.exe
Recguard REG_SZ C:\WINDOWS\SMINST\RECGUARD.EXE
PS2 REG_SZ C:\WINDOWS\system32\ps2.exe
ORAHSSSessionManager REG_SZ C:\Program Files\Orange\SessionManager\SessionManager.exe
nwiz REG_SZ nwiz.exe /installquiet /keeploaded /nodetect
NvCplDaemon REG_SZ RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
KBD REG_SZ C:\HP\KBD\KBD.EXE
iTunesHelper REG_SZ "C:\Program Files\iTunes\iTunesHelper.exe"
hpsysdrv REG_SZ c:\windows\system\hpsysdrv.exe
EPSON Stylus DX4200 Series REG_SZ C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE /P26 "EPSON Stylus DX4200 Series" /O6 "USB001" /M "Stylus DX4200"
AlcxMonitor REG_SZ ALCXMNTR.EXE
AGRSMMSG REG_SZ AGRSMMSG.exe
Adobe Photo Downloader REG_SZ "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
HP Software Update REG_SZ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
hpqSRMon REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Adobe ARM REG_SZ "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
Malwarebytes Anti-Malware (reboot) REG_SZ "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents
=====================
Other Keys
=====================

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System
dontdisplaylastusername REG_DWORD 0x0
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
shutdownwithoutlogon REG_DWORD 0x1
undockwithoutlogon REG_DWORD 0x1
===============

===============
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
===============
BHO :
======

========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

Ndisuio : 0x3
EapHost : 0x3
SharedAccess : 0x2
wuauserv : 0x2
=========

=========================
Environnement variables :
=========================

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Compaq_Propri‚taire\Application Data
choix=1
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Fichiers communs
COMPUTERNAME=RACHEL
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Compaq_Propri‚taire
LOGONSERVER=\\RACHEL
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;c:\Python22;C:\Program Files\PC-Doctor for Windows\services
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0a00
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp
USERDOMAIN=RACHEL
USERNAME=Compaq_Propri‚taire
USERPROFILE=C:\Documents and Settings\Compaq_Propri‚taire
windir=C:\WINDOWS

¤¤¤¤¤¤¤¤¤¤ Files/folders :

C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
C:\Program Files\Crawler
C:\Program Files\GamesBar
C:\Program Files\KaZaA
C:\Program Files\Need2Find
C:\WINDOWS\iun6002.exe
C:\WINDOWS\System32\cagzht_navup.dat
C:\WINDOWS\System32\ACTSKN43.ocx
C:\WINDOWS\System32\drivers\etc\hosts.msn
C:\WINDOWS\system32\drivers\Sonyhcp.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\ps2.bat
C:\WINDOWS\System32\SET182.tmp
C:\WINDOWS\System32\SET187.tmp
C:\WINDOWS\System32\SET18E.tmp
C:\WINDOWS\System32\SET197.tmp
C:\WINDOWS\System32\SET199.tmp
C:\WINDOWS\System32\SET19C.tmp
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\hpzmsi01.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\hpzscr01.EXE
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\hpzswp01.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\installation.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\PxCpyA64.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\PxCpyI64.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\pxhpinst.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\PxInsA64.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\PxInsI64.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\pxsetup.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\setup_wm.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is1.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is2.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is22B.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is233.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is234.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is235.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is238.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is239.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is3.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is4.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is41A.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is41C.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is41D.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is41E.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is420.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is421.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is422.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is424.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is437.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is438.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is43B.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is459.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is45A.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is4AB.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is4AC.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is5.exe

¤¤¤¤¤¤¤¤¤¤ Keys :

HKU\S-1-5-21-1499807320-3828894901-3313630303-1007\Software\Microsoft\Windows\CurrentVersion\Run "avgsys"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "3wPlayer Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "4 ROAD"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "63651021"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "a00f118337.exe"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "adobe_reader"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "acxzup"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "antihost"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "AV"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "ARMY SECT"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "backup windows 2009"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Bags regs"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "BitDownload Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "BitGrabber Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "BitRoll Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "book ante"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "bwebu"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "calc"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "COPY DEBUG"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "DivoPlayer Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "GalaPlayer"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Get-Torrent Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "GreatLog"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Internet Today Task"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "mobiswing"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "mset"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "NT Printing Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "ocqcqii"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "OkayLicense"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "outil système"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "part mags"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Peak Meal"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "photo_id"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Salestart"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "secure32"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "secure64"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "sizedrv"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "style cool 2 city"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "system tool"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "That dent five else"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Tok-Cirrhatus"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "tok-cirrhatus-2289"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Torrent101 Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "TorrentQ Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "TorrentSoftware Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "VideoBarApp"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "vmmonitor"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WhenUSave"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Upgrate Utility"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "winusr"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WinZix Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Yjafosi8kdf98winmdkmnkmfnwe"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "®Update"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ".NET Application Debugger 32"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ".nvsvc"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ".nvsvcb"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_mzu_stonedrv2"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_mzu_stonedrv4"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_mzu_stonedrv5"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_mzu_stonedrv6"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_mzu_stonedrv7"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_Windows"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "0mcamcap"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "12CFG214-K641-11SF-N33P"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "12CFG214-K641-12SF-N85P"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "2chkdsk"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "3cfe250a"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "64 inter flaw hold"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Acrobat Read"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "ActiveScan Antivirus"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "adir"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "adobe_reader"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "AdobeReaderPro"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Ads checker"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Advanced DHTML Enable"
0
Utilisateur anonyme
 
Tu peux me refaire un RSIT ?
0
patracem
 
quoi c'est quoi un rsit
0
Utilisateur anonyme
 
Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

! Déconnecte toi et FERME TOUTES TES APPLICATIONS EN COURS !

Double-clique sur " RSIT.exe " pour le lancer .

▶ Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

▶ Devant l'option "List files/folders created ..." , tu choisis : 2 months

▶ clique ensuite sur " Continue " pour lancer l'analyse ...

▶ laisse faire le scan et ne touche pas au PC ...

Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

Important : poste un rapport, puis l'autre dans la réponse suivante
Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
0
patracem
 
List'em by g3n-h@ckm@n 1.1.0.0

Thx to Chiquitine29.....

User : Compaq_Propriétaire () # RACHEL
Update on 02/12/2009 by g3n-h@ckm@n ::::: 23:00
Start at: 15:41:55 | 03/12/2009
Contact : g3n-h@ckm@n sur CCM

AMD Sempron(tm) 3000+
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : avast! antivirus 4.8.1335 [VPS 091203-1] 4.8.1335 [ Enabled | Updated ]
FW : G DATA Personal Firewall[ (!) Disabled ]1.0

A:\ -> Lecteur de disquettes 3 ½ pouces
C:\ -> Disque fixe local | 144,64 Go (92,8 Go free) [PRESARIO] | NTFS
D:\ -> Disque fixe local | 4,4 Go (1,19 Go free) [PRESARIO_RP] | FAT32
E:\ -> Disque CD-ROM

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

C:\WINDOWS\System32\smss.exe 596
C:\WINDOWS\system32\csrss.exe 660
C:\WINDOWS\system32\winlogon.exe 684
C:\WINDOWS\system32\services.exe 732
C:\WINDOWS\system32\lsass.exe 744
C:\WINDOWS\system32\svchost.exe 904
C:\WINDOWS\system32\svchost.exe 984
C:\WINDOWS\System32\svchost.exe 1080
C:\WINDOWS\system32\svchost.exe 1140
C:\WINDOWS\system32\svchost.exe 1212
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 1544
C:\WINDOWS\Explorer.EXE 1552
C:\Program Files\Alwil Software\Avast4\ashServ.exe 1600
C:\WINDOWS\system32\spoolsv.exe 1892
C:\WINDOWS\system32\svchost.exe 1956
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe 2016
C:\WINDOWS\system32\svchost.exe 300
C:\Program Files\Java\jre6\bin\jqs.exe 424
C:\WINDOWS\System32\svchost.exe 568
C:\WINDOWS\system32\nvsvc32.exe 1020
C:\WINDOWS\System32\svchost.exe 1044
C:\WINDOWS\system32\svchost.exe 1204
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe 2648
C:\Program Files\Orange\Systray\SystrayApp.exe 2656
C:\Program Files\Java\jre6\bin\jusched.exe 2664
C:\WINDOWS\system32\keyhook.exe 2672
C:\HP\KBD\KBD.EXE 2740
C:\Program Files\iTunes\iTunesHelper.exe 2748
C:\windows\system\hpsysdrv.exe 2756
C:\WINDOWS\ALCXMNTR.EXE 2788
C:\WINDOWS\AGRSMMSG.exe 2796
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe 2808
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe 2880
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe 2896
C:\Program Files\Orange\Launcher\Launcher.exe 3080
C:\WINDOWS\system32\ctfmon.exe 3148
C:\Program Files\Shareaza\Shareaza.exe 3168
C:\Program Files\Messenger\msmsgs.exe 3180
C:\PROGRA~1\HELPAN~1\Presario\XPHWWRF4\plugin\bin\pchbutton.exe 3188
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe 3216
C:\WINDOWS\system32\wuauclt.exe 3328
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 3596
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 3828
C:\Program Files\iPod\bin\iPodService.exe 224
C:\WINDOWS\System32\alg.exe 1288
C:\WINDOWS\System32\svchost.exe 2488
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe 3312
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe 1688
C:\Program Files\Orange\Deskboard\deskboard.exe 3488
C:\Program Files\Orange\connectivity\connectivitymanager.exe 2456
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe 316
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe 264
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe 3896
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe 3908
C:\WINDOWS\system32\wbem\wmiprvse.exe 628
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe 2564
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe 3336
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe 1500
C:\Documents and Settings\Compaq_Propriétaire\Mes documents\Downloads\List_Killem\List_Kill'em.exe 3068
C:\WINDOWS\system32\cmd.exe 2476
C:\WINDOWS\system32\wbem\wmiprvse.exe 1324
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temp\665.tmp\pv.exe 2308

======================
Keys "Run"
======================

! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
WOOKIT REG_SZ C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
Shareaza REG_SZ "C:\Program Files\Shareaza\Shareaza.exe" -tray
msnmsgr REG_SZ "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
MSMSGS REG_SZ "C:\Program Files\Messenger\msmsgs.exe" /background
Compaq_Propriétaire REG_SZ C:\Documents and Settings\Compaq_Propriétaire\Compaq_Propriétaire.exe /i
Acme.PCHButton REG_SZ C:\PROGRA~1\HELPAN~1\Presario\XPHWWRF4\plugin\bin\pchbutton.exe

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
VTTimer REG_SZ VTTimer.exe
SystrayORAHSS REG_SZ "C:\Program Files\Orange\Systray\SystrayApp.exe"
SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
SiS Windows KeyHook REG_SZ C:\WINDOWS\system32\keyhook.exe
Recguard REG_SZ C:\WINDOWS\SMINST\RECGUARD.EXE
PS2 REG_SZ C:\WINDOWS\system32\ps2.exe
ORAHSSSessionManager REG_SZ C:\Program Files\Orange\SessionManager\SessionManager.exe
nwiz REG_SZ nwiz.exe /installquiet /keeploaded /nodetect
NvCplDaemon REG_SZ RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
KBD REG_SZ C:\HP\KBD\KBD.EXE
iTunesHelper REG_SZ "C:\Program Files\iTunes\iTunesHelper.exe"
hpsysdrv REG_SZ c:\windows\system\hpsysdrv.exe
EPSON Stylus DX4200 Series REG_SZ C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE /P26 "EPSON Stylus DX4200 Series" /O6 "USB001" /M "Stylus DX4200"
AlcxMonitor REG_SZ ALCXMNTR.EXE
AGRSMMSG REG_SZ AGRSMMSG.exe
Adobe Photo Downloader REG_SZ "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
HP Software Update REG_SZ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
hpqSRMon REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Adobe ARM REG_SZ "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
Malwarebytes Anti-Malware (reboot) REG_SZ "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents
=====================
Other Keys
=====================

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System
dontdisplaylastusername REG_DWORD 0x0
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
shutdownwithoutlogon REG_DWORD 0x1
undockwithoutlogon REG_DWORD 0x1
===============

===============
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
===============
BHO :
======

========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

Ndisuio : 0x3
EapHost : 0x3
SharedAccess : 0x2
wuauserv : 0x2
=========

=========================
Environnement variables :
=========================

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Compaq_Propri‚taire\Application Data
choix=1
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Fichiers communs
COMPUTERNAME=RACHEL
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Compaq_Propri‚taire
LOGONSERVER=\\RACHEL
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;c:\Python22;C:\Program Files\PC-Doctor for Windows\services
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0a00
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp
USERDOMAIN=RACHEL
USERNAME=Compaq_Propri‚taire
USERPROFILE=C:\Documents and Settings\Compaq_Propri‚taire
windir=C:\WINDOWS

¤¤¤¤¤¤¤¤¤¤ Files/folders :

C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
C:\Program Files\Crawler
C:\Program Files\GamesBar
C:\Program Files\KaZaA
C:\Program Files\Need2Find
C:\WINDOWS\iun6002.exe
C:\WINDOWS\System32\cagzht_navup.dat
C:\WINDOWS\System32\ACTSKN43.ocx
C:\WINDOWS\System32\drivers\etc\hosts.msn
C:\WINDOWS\system32\drivers\Sonyhcp.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\ps2.bat
C:\WINDOWS\System32\SET182.tmp
C:\WINDOWS\System32\SET187.tmp
C:\WINDOWS\System32\SET18E.tmp
C:\WINDOWS\System32\SET197.tmp
C:\WINDOWS\System32\SET199.tmp
C:\WINDOWS\System32\SET19C.tmp
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\hpzmsi01.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\hpzscr01.EXE
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\hpzswp01.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\installation.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\PxCpyA64.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\PxCpyI64.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\pxhpinst.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\PxInsA64.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\PxInsI64.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\pxsetup.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\setup_wm.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is1.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is2.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is22B.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is233.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is234.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is235.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is238.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is239.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is3.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is4.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is41A.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is41C.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is41D.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is41E.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is420.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is421.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is422.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is424.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is437.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is438.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is43B.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is459.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is45A.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is4AB.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is4AC.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\_is5.exe

¤¤¤¤¤¤¤¤¤¤ Keys :

HKU\S-1-5-21-1499807320-3828894901-3313630303-1007\Software\Microsoft\Windows\CurrentVersion\Run "avgsys"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "3wPlayer Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "4 ROAD"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "63651021"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "a00f118337.exe"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "adobe_reader"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "acxzup"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "antihost"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "AV"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "ARMY SECT"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "backup windows 2009"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Bags regs"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "BitDownload Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "BitGrabber Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "BitRoll Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "book ante"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "bwebu"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "calc"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "COPY DEBUG"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "DivoPlayer Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "GalaPlayer"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Get-Torrent Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "GreatLog"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Internet Today Task"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "mobiswing"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "mset"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "NT Printing Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "ocqcqii"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "OkayLicense"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "outil système"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "part mags"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Peak Meal"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "photo_id"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Salestart"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "secure32"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "secure64"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "sizedrv"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "style cool 2 city"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "system tool"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "That dent five else"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Tok-Cirrhatus"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "tok-cirrhatus-2289"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Torrent101 Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "TorrentQ Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "TorrentSoftware Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "VideoBarApp"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "vmmonitor"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WhenUSave"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Upgrate Utility"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "winusr"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WinZix Service"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Yjafosi8kdf98winmdkmnkmfnwe"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "®Update"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ".NET Application Debugger 32"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ".nvsvc"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ".nvsvcb"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_mzu_stonedrv2"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_mzu_stonedrv4"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_mzu_stonedrv5"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_mzu_stonedrv6"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_mzu_stonedrv7"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "_Windows"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "0mcamcap"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "12CFG214-K641-11SF-N33P"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "12CFG214-K641-12SF-N85P"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "2chkdsk"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "3cfe250a"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "64 inter flaw hold"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Acrobat Read"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "ActiveScan Antivirus"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "adir"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "adobe_reader"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "AdobeReaderPro"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Ads checker"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Advanced DHTML Enable"
0
Utilisateur anonyme
 
0
patracem
 
j'ai pas posté le bon truc
0
patracem
 
je n'ai que cela apres le scan
0
Utilisateur anonyme
 
0
patracem
 
ça y est c le bon

logfile of random's system information tool 1.06 (written by random/random)
Run by Compaq_Propriétaire at 2009-12-03 18:15:33
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 95 GB (64%) free of 148 GB
Total RAM: 511 MB (22% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:15:39, on 03/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\keyhook.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\Orange\Launcher\Launcher.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Shareaza\Shareaza.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\HELPAN~1\Presario\XPHWWRF4\plugin\bin\pchbutton.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Orange\Deskboard\deskboard.exe
C:\Program Files\Orange\connectivity\connectivitymanager.exe
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\spider.exe
C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Compaq_Propriétaire\Mes documents\Downloads\RSIT (3).exe
C:\Program Files\Trend Micro\HijackThis\Compaq_Propriétaire.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=presario&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searcheo.fr/france
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60264
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60264
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60264
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60264
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =

https://support.norton.com/sp/fr/fr/home/current/solutions/v58540272?abproduct=LU&abversion=1.90&build=Symantec&ced=true&entsrc=CED_pubweb&error=1814&module=LU&src=_mi
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer fourni par Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - (no file)
R3 - URLSearchHook: (no name) - {814C76CB-2623-43F4-AAD0-58A0E5190A20} - (no file)
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Shareaza\Plugins\RazaWebHook.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: (no name) - {DB35C569-5624-4CFC-8043-E5139F55A073} - C:\PROGRA~1\Crawler\Shared\CShared.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [EPSON Stylus DX4200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE /P26 "EPSON Stylus DX4200 Series" /O6 "USB001" /M

"Stylus DX4200"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Compaq_Propriétaire] C:\Documents and Settings\Compaq_Propriétaire\Compaq_Propriétaire.exe /i
O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HELPAN~1\Presario\XPHWWRF4\plugin\bin\pchbutton.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: ajouter cette page à vos favoris Orange - C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\cce660.html
O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Shareaza\Plugins\RazaWebHook.dll/3000
O8 - Extra context menu item: traduire la page - C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\cce65E.html
O8 - Extra context menu item: traduire le texte sélectionné - C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\cce65F.html
O9 - Extra button: Crawler Screensaver - {CDAFD956-97BE-443D-8EF7-F4F094EB5766} - C:\Program Files\Crawler\SSaver\CSSaver.exe
O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: https://www.orange.fr/portail
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

http://update.microsoft.com/...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -

http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?e=1232621260938&h=23adf2255bb2954a1a4d17d5efb6f691/&filename=jinstall-6

u11-windows-i586-jc.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -

http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game01.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Update Service (gupdate1c9726b9996aa68) (gupdate1c9726b9996aa68) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel

32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O24 - Desktop Component 0: (no name) - http://www.couriramorlaix.com/courir%20a%20morlaix/fichier_photo-videos/diaporamas/st-martin2007_15km/medium/0012.jpg
O24 - Desktop Component 1: (no name) - https://www.marmiton.org/App_Themes/Recettes/img/recettes/recette_titre.gif2
0
Utilisateur anonyme
 
▶ Télécharge TOOLBAR S&D ( de Eric_71/Team IDN ) sur ton bureau :

!! Déconnecte toi,desactive tes protections résidentes, et ferme toutes tes applications en cours le temps de la manip. !!

▶ Double-clique sur ToolBar SD.exe pour lancer l'outil et laisse toi guider ...

▶ option recherche puis [Entrée].

Un rapport sera généré à la fin du processus : poste son contenu dans ta prochaine réponse

( le rapport est en outre sauvegardé ici -> C:\TB.txt )

Tutoriel

====================

▶ Télécharge et install UsbFix par Chiquitine29

(!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

▶ Double clic sur le raccourci UsbFix présent sur ton bureau .

▶ Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

▶ Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]

▶ Laisse travailler l'outil.

▶ Ensuite post le rapport UsbFix.txt qui apparaitra.

Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
0
patracem
 
je viens d'essayer de telecharger toolbar ,impossible d'aller sur la page;un message en anglais apparait
0
Utilisateur anonyme
 
0
patracem
 
voila ce qui me marque quand je double clique sur toolbar
"The bandwidth or page view limit for this site has been exceeded and the page cannot be viewed at this time. Once the site is below the limit, it will once again begin serving as normal."
0
Utilisateur anonyme
 
Le téléchargement s'effectue ?
0
patracem
 
non, rien du tout ,iln'y a que le message fixe
0
Utilisateur anonyme
 
Dur de désinfecter sans les outils ...

L'outil ne veut pas se télécharger ou il ne veut pas s'exécuter ?

Supprime le et recommence
0
Utilisateur anonyme
 
bonjour
http://eric71.geekstogo.com/tools/ToolBarSD.exe
il y a un problème avec le serveur de Eric, je donne un autre lien
0
patracem
 
..............
BON JE L'ai supprimé puis réexecuté
j'ai selectionné la langue
+ option recherche+entré : est la rien , et pourtant j'ai mis en pause mon antivirus,maintenant ?
0
Utilisateur anonyme
 
Aucun outil de désinfection marche chez toi ...
0
patracem
 
JE COMPREND RIEN Y A UN TRUC QUI COLLE PAS DS CE PC
0
Utilisateur anonyme
 
▶ Télécharge : Gmer (by Przemyslaw Gmerek)

▶ Dezippe gmer ,cliques sur l'onglet rootkit,lances le scan,des lignes rouges vont apparaitre.

▶ Les lignes rouges indiquent la presence d'un rootkit.Postes moi le rapport gmer (cliques sur copy,puis vas dans demarrer ,puis ouvres le bloc note,vas dans edition et cliques sur coller,le rapport gmer va apparaitre,postes moi le)

Ensuite

▶ sur les lignes rouge:

▶ Services:cliques droit delete service
▶ Process:cliques droit kill process
▶ Adl ,file:cliques droit delete files
0
patracem
 
GMER 1.0.15.15252 - http://www.gmer.net
Rootkit quick scan 2009-12-04 14:58:43
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\kxldrpow.sys


---- System - GMER 1.0.15 ----

SSDT sptd.sys ZwEnumerateKey [0xF83B3C7E]
SSDT sptd.sys ZwEnumerateValueKey [0xF83B3FF6]

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 82AB7EB0

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

Device \FileSystem\Fastfat \Fat 8266E300

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

---- EOF - GMER 1.0.15 ----
0
patracem
 
attend il n'est pas complet
0
patracem
 
voici le rapport gmer
GMER 1.0.15.15252 - http://www.gmer.net
Rootkit scan 2009-12-04 16:35:22
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\kxldrpow.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF53636B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF5363574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF5363A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF536314C]
SSDT sptd.sys ZwEnumerateKey [0xF83B3C7E]
SSDT sptd.sys ZwEnumerateValueKey [0xF83B3FF6]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF536364E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF536308C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF53630F0]
SSDT sptd.sys ZwQueryKey [0xF83B40C0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF536376E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF536372E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF53638AE]

---- Kernel code sections - GMER 1.0.15 ----

? C:\WINDOWS\system32\drivers\sptd.sys Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
? C:\WINDOWS\System32\Drivers\SPTD1245.SYS Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
init C:\WINDOWS\system32\drivers\ALCXSENS.SYS entry point in "init" section [0xF6782510]

---- User code sections - GMER 1.0.15 ----

.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtCreateFile + 6 7C91D0B4 4 Bytes [28, 00, 15, 00]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtCreateFile + B 7C91D0B9 1 Byte [E2]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtOpenFile + 6 7C91D5A4 4 Bytes [68, 00, 15, 00]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtOpenFile + B 7C91D5A9 1 Byte [E2]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtOpenProcess + 6 7C91D604 4 Bytes [A8, 01, 15, 00]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtOpenProcess + B 7C91D609 1 Byte [E2]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtOpenProcessToken + 6 7C91D614 4 Bytes CALL 7B91EB1A
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtOpenProcessToken + B 7C91D619 1 Byte [E2]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D624 4 Bytes [A8, 02, 15, 00]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtOpenProcessTokenEx + B 7C91D629 1 Byte [E2]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtOpenThread + 6 7C91D664 4 Bytes [68, 01, 15, 00]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtOpenThread + B 7C91D669 1 Byte [E2]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtOpenThreadToken + 6 7C91D674 4 Bytes [68, 02, 15, 00]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtOpenThreadToken + B 7C91D679 1 Byte [E2]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtOpenThreadTokenEx + 6 7C91D684 4 Bytes CALL 7B91EB8B
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtOpenThreadTokenEx + B 7C91D689 1 Byte [E2]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtQueryAttributesFile + 6 7C91D714 4 Bytes [A8, 00, 15, 00]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtQueryAttributesFile + B 7C91D719 1 Byte [E2]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtQueryFullAttributesFile + 6 7C91D7B4 4 Bytes CALL 7B91ECB9
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtQueryFullAttributesFile + B 7C91D7B9 1 Byte [E2]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtSetInformationFile + 6 7C91DC64 4 Bytes [28, 01, 15, 00]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtSetInformationFile + B 7C91DC69 1 Byte [E2]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtSetInformationThread + 6 7C91DCB4 4 Bytes [28, 02, 15, 00]
.text C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3576] ntdll.dll!NtSetInformationThread + B 7C91DCB9 1 Byte [E2]

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F83BCDB2] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F83D271E] sptd.sys
IAT ftdisk.sys[ntoskrnl.exe!IoGetAttachedDeviceReference] [F83BD3B2] sptd.sys
IAT ftdisk.sys[ntoskrnl.exe!IoGetDeviceObjectPointer] [F83BD2B6] sptd.sys
IAT ftdisk.sys[ntoskrnl.exe!IofCallDriver] [F83BD482] sptd.sys
IAT PartMgr.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F83D2032] sptd.sys
IAT PartMgr.sys[ntoskrnl.exe!IoDetachDevice] [F83BCF6E] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IofCompleteRequest] [F83D1C76] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F83BCE06] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F83AFA32] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F83AFB6E] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F83AFAF6] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F83B06CC] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F83B05A2] sptd.sys
IAT disk.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F83D2864] sptd.sys
IAT \WINDOWS\system32\DRIVERS\CLASSPNP.SYS[ntoskrnl.exe!IoDetachDevice] [F83C1F78] sptd.sys
IAT \SystemRoot\system32\DRIVERS\cdrom.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F83D2864] sptd.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!IofCompleteRequest] [F83D1C76] sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F83D1C82] sptd.sys

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\WINDOWS\system32\services.exe[732] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[732] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 82AB7EB0

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

Device \FileSystem\Fastfat \FatCdrom 8266E300

AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\Ftdisk \Device\HarddiskVolume1 82AB86D0
Device \Driver\Ftdisk \Device\HarddiskVolume2 82AB86D0
Device \Driver\Cdrom \Device\CdRom0 82903870
Device \Driver\atapi \Device\Ide\IdePort0 [F8328B40] atapi.sys[unknown section] {MOV EAX, 0x82ab8338; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf83c4442; RET }
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-1b [F8328B40] atapi.sys[unknown section] {MOV EAX, 0x82ab8338; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf83c4442; RET }
Device \Driver\atapi \Device\Ide\IdePort1 [F8328B40] atapi.sys[unknown section] {MOV EAX, 0x82ab8338; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf83c4442; RET }
Device \Driver\atapi \Device\Ide\IdePort2 [F8328B40] atapi.sys[unknown section] {MOV EAX, 0x82ab8338; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf83c4442; RET }
Device \Driver\atapi \Device\Ide\IdePort3 [F8328B40] atapi.sys[unknown section] {MOV EAX, 0x82ab8338; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf83c4442; RET }
Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-8 [F8328B40] atapi.sys[unknown section] {MOV EAX, 0x82ab8338; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf83c4442; RET }
Device \Driver\NetBT \Device\NetBt_Wins_Export 8243C6A0
Device \Driver\NetBT \Device\NetbiosSmb 8243C6A0

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\Disk \Device\Harddisk0\DR0 82AB70E8

AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \FileSystem\Npfs \Device\NamedPipe 8252A280
Device \Driver\Ftdisk \Device\FtControl 82AB86D0
Device \Driver\NetBT \Device\NetBT_Tcpip_{1BF0BA87-9129-46D8-8E49-F080968FAF72} 8243C6A0
Device \FileSystem\Msfs \Device\Mailslot 827C2BE0
Device \FileSystem\Fastfat \Fat 8266E300

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

Device \FileSystem\Cdfs \Cdfs 828570E8

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s0 -716554510
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 1539707631
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 756851384
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls@C:\Program Files\orange\jeux\Women\x2019s Murder Club\Uninstall.exe 2

---- Files - GMER 1.0.15 ----

File C:\WINDOWS\system32\DRVSTORE\hpf4200a_E7EAA61E164BFBDDC91BBD6CE28A51D38C4562F7\hpF4200a.cab 9865903 bytes
File C:\WINDOWS\system32\DRVSTORE\hpf4200a_E7EAA61E164BFBDDC91BBD6CE28A51D38C4562F7\hpF4200a.cat 121459 bytes
File C:\WINDOWS\system32\DRVSTORE\hpf4200a_E7EAA61E164BFBDDC91BBD6CE28A51D38C4562F7\hpf4200a.inf 23820 bytes
File C:\WINDOWS\system32\DRVSTORE\hpf4200a_E7EAA61E164BFBDDC91BBD6CE28A51D38C4562F7\hpzids01.dll 271704 bytes executable
File C:\WINDOWS\system32\DRVSTORE\hpf4200a_E7EAA61E164BFBDDC91BBD6CE28A51D38C4562F7\P3i2frww.cab 6829 bytes
File C:\WINDOWS\system32\DRVSTORE\hpof4200_s_512EC285D237602EBFD04DE1FE5F9769470B7E5F\drivers 0 bytes
File C:\WINDOWS\system32\DRVSTORE\hpof4200_s_512EC285D237602EBFD04DE1FE5F9769470B7E5F\drivers\dot4 0 bytes
File C:\WINDOWS\system32\DRVSTORE\hpof4200_s_512EC285D237602EBFD04DE1FE5F9769470B7E5F\drivers\dot4\Win2000 0 bytes
File C:\WINDOWS\system32\DRVSTORE\hpof4200_s_512EC285D237602EBFD04DE1FE5F9769470B7E5F\drivers\dot4\Win2000\difxapi.dll 309760 bytes executable
File C:\WINDOWS\system32\DRVSTORE\hpof4200_s_512EC285D237602EBFD04DE1FE5F9769470B7E5F\drivers\dot4\Win2000\hppldcoi.dll 372736 bytes executable
File C:\WINDOWS\system32\DRVSTORE\hpof4200_s_512EC285D237602EBFD04DE1FE5F9769470B7E5F\drivers\scanner 0 bytes
File C:\WINDOWS\system32\DRVSTORE\hpof4200_s_512EC285D237602EBFD04DE1FE5F9769470B7E5F\drivers\scanner\x32 0 bytes
File C:\WINDOWS\system32\DRVSTORE\hpof4200_s_512EC285D237602EBFD04DE1FE5F9769470B7E5F\drivers\scanner\x32\hpotscl6.dll 581632 bytes executable
File C:\WINDOWS\system32\DRVSTORE\hpof4200_s_512EC285D237602EBFD04DE1FE5F9769470B7E5F\drivers\scanner\x32\hpotsti1.dll 229376 bytes executable
File C:\WINDOWS\system32\DRVSTORE\hpof4200_s_512EC285D237602EBFD04DE1FE5F9769470B7E5F\drivers\scanner\x32\hpovst15.dll 303104 bytes executable
File C:\WINDOWS\system32\DRVSTORE\hpof4200_s_512EC285D237602EBFD04DE1FE5F9769470B7E5F\drivers\scanner\x32\hpowiax7.dll 729088 bytes executable
File C:\WINDOWS\system32\DRVSTORE\hpof4200_s_512EC285D237602EBFD04DE1FE5F9769470B7E5F\hpoF4200_sc.cat 15309 bytes
File C:\WINDOWS\system32\DRVSTORE\hpof4200_s_512EC285D237602EBFD04DE1FE5F9769470B7E5F\hpof4200_sc.inf 73846 bytes
File C:\WINDOWS\system32\DRVSTORE\hpzid413_F2DA46DE686A3E981420574C9735FC7A1D1CEC02\drivers\dot4 0 bytes

---- EOF - GMER 1.0.15 ----
0