Probleme virus, page internet ultra lente

Bonjour, excusez moi de vous déranger, je viens vers vous, car mon pc fonctionne bien, les dossiers s'ouvrent assez vite, mais des que j'ouvre une page internet cela met 5minutes a s'ouvrir (mozilla et internet explorer même problème!
Je suis un étudiant et me sert bcp de mon pc, il s'agit surement d'un virus
Pouvez vous me depanner s'il vous plait?
J'ai windows Xp
Merci d'avance
Cyril
Configuration: Windows XP
Firefox 3.5.7

46 réponses

Résumé de la discussion

Des ralentissements importants à l'ouverture des pages web sur Windows XP, constatés avec Mozilla Firefox et Internet Explorer, suggèrent une infection par malware et déclenchent des conseils techniques. Plusieurs recommandations portent sur l'exécution d'outils de détection et de correction, notamment ComboFix et Malwarebytes' Anti-Malware, afin d'identifier les programmes indésirables, les entrées de démarrage et les dépendances système affectées. Des éléments remontés incluent des traces d'infection telles que des programmes malveillants dans le registre, des pilotes et des outils suspects, certains porteurs de mécanismes de rootkit MBR et de redirections internet. En parallèle, des échanges abordent la gestion des antivirus multiples et la nécessité de partager les rapports d'analyse via des services en ligne pour orienter le nettoyage.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonjour, postes un RSIT pour voir si et ou se trouve l'infection !!

    1) Télécharges et installes HijackThis :

    https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/

    Cliques sur le fichier hijackthis téléchargé pour lancer l'installation
    laisses toi guider et ne modifies pas les paramètres d'installation .
    A la fin de l’installation, le programme se lance automatiquement
    fermes le en cliquant sur la croix rouge.

    Ne lances pas ce programme pour l'instant et fais la suite

    2) Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

    -> http://images.malwareremoval.com/random/RSIT.exe

    .Déconnectes toi et fermes toutes tes applications en cours

    Double-clique sur " RSIT.exe " pour le lancer.

    Clic droit sous VISTA (exécuter en tant que…)

    .Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

    .Devant l'option "List files/folders created ..." , tu choisis : 1 months

    .cliques ensuite sur " Continuer " pour lancer l'analyse

    .laisses faire le scan et ne touches pas au PC

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront

    Postes le contenu de " log.txt " , ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

    Important : poste un rapport, puis l'autre dans la réponse suivante

    Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum ??

    Note : les rapports seront en outre sauvegardés dans ce dossier C:\rsit

    0
    1. merci pour votre réponse si rapide voila le premier log
      Logfile of random's system information tool 1.06 (written by random/random)
      Run by hp at 2010-02-15 19:09:48
      Microsoft Windows XP Professionnel Service Pack 3
      System drive C: has 16 GB (15%) free of 105 GB
      Total RAM: 1022 MB (41% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:10:06, on 15/02/2010
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\WINDOWS\eHome\ehRecvr.exe
      C:\WINDOWS\eHome\ehSched.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\mqsvc.exe
      C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
      C:\WINDOWS\system32\mqtgsvc.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\Winamp\winampa.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\Winamp Remote\bin\OrbTray.exe
      C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\DAEMON Tools Lite\daemon.exe
      C:\Program Files\Microsoft ActiveSync\wcescomm.exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\PROGRA~1\MI3AA1~1\rapimgr.exe
      C:\Program Files\SAGEM Wi-Fi USB 802.11g\WLANUTL.exe
      C:\Documents and Settings\hp\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
      C:\Program Files\SpeedFan\speedfan.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
      C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
      C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
      C:\Documents and Settings\hp\Bureau\RSIT.exe
      C:\Program Files\Trend Micro\HijackThis\hp.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre1.dll
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: (no name) - {91bc120b-eb6d-4440-abc5-58d08f96af31} - (no file)
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
      O2 - BHO: SurfingSoftware - {D4070176-F144-22CD-0D5C-71B49B46FF19} - C:\Program Files\SurfingSoftware\SurfingSoftware-2.dll (file missing)
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre1.dll
      O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre1.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
      O4 - HKLM\..\Run: [\\USER-5093E8CEC1\EPSON Stylus DX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE /P44 "\\USER-5093E8CEC1\EPSON Stylus DX4800 Series" /O6 "USB001" /M "Stylus DX4800"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
      O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
      O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
      O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\hp\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
      O4 - Startup: SpeedFan (2).lnk = C:\Program Files\SpeedFan\speedfan.exe
      O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
      O4 - Global Startup: Sagem - Utilitaire réseau pour Clé USB Wi-Fi 802.11g.lnk = ?
      O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
      O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
      O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
      O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
      O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
      O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
      O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.fr/
      O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) -
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
      O20 - AppInit_DLLs: c:\windows\system32\ c:\windows\system32\konovozo.dll
      O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
      O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
      O23 - Service: Service Google Update (gupdate1c9b9fa5b837f50) (gupdate1c9b9fa5b837f50) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
      0
      1. le deuxième
        Logfile of random's system information tool 1.06 (written by random/random)
        Run by hp at 2010-02-15 19:09:48
        Microsoft Windows XP Professionnel Service Pack 3
        System drive C: has 16 GB (15%) free of 105 GB
        Total RAM: 1022 MB (41% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 19:10:06, on 15/02/2010
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v8.00 (8.00.6001.18702)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir Desktop\sched.exe
        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        C:\WINDOWS\eHome\ehRecvr.exe
        C:\WINDOWS\eHome\ehSched.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\mqsvc.exe
        C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
        C:\WINDOWS\system32\mqtgsvc.exe
        C:\WINDOWS\system32\dllhost.exe
        C:\WINDOWS\system32\wbem\wmiapsrv.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\Program Files\Winamp\winampa.exe
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
        C:\Program Files\Winamp Remote\bin\OrbTray.exe
        C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\Program Files\DAEMON Tools Lite\daemon.exe
        C:\Program Files\Microsoft ActiveSync\wcescomm.exe
        C:\Program Files\Windows Media Player\WMPNSCFG.exe
        C:\PROGRA~1\MI3AA1~1\rapimgr.exe
        C:\Program Files\SAGEM Wi-Fi USB 802.11g\WLANUTL.exe
        C:\Documents and Settings\hp\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
        C:\Program Files\SpeedFan\speedfan.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
        C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
        C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
        C:\Documents and Settings\hp\Bureau\RSIT.exe
        C:\Program Files\Trend Micro\HijackThis\hp.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
        R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre1.dll
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll
        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
        O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: (no name) - {91bc120b-eb6d-4440-abc5-58d08f96af31} - (no file)
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
        O2 - BHO: SurfingSoftware - {D4070176-F144-22CD-0D5C-71B49B46FF19} - C:\Program Files\SurfingSoftware\SurfingSoftware-2.dll (file missing)
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre1.dll
        O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre1.dll
        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
        O4 - HKLM\..\Run: [\\USER-5093E8CEC1\EPSON Stylus DX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE /P44 "\\USER-5093E8CEC1\EPSON Stylus DX4800 Series" /O6 "USB001" /M "Stylus DX4800"
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
        O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
        O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
        O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
        O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\hp\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
        O4 - Startup: SpeedFan (2).lnk = C:\Program Files\SpeedFan\speedfan.exe
        O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
        O4 - Global Startup: Sagem - Utilitaire réseau pour Clé USB Wi-Fi 802.11g.lnk = ?
        O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
        O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
        O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
        O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
        O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
        O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
        O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
        O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.fr/
        O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) -
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
        O20 - AppInit_DLLs: c:\windows\system32\ c:\windows\system32\konovozo.dll
        O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
        O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
        O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
        O23 - Service: Service Google Update (gupdate1c9b9fa5b837f50) (gupdate1c9b9fa5b837f50) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
        0
        1. Contributeur sécurité
          bonjour, tu m'as mis 2 fois le log.txt !!

          tu fais ce qui suit , Merci tu as 2 antivirus sur le pc norton et antivir si tu n'utilises plus norton désinstalles le convenablement avec l'outil spèciphique http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924

          1) déactives la protection résidente de spybot pour pas qu'il nous bloque le fixe
          quand tu le réactiveras possible qu'il te demande d'accepter ou pas les modifications il faudra les accepter toutes
          pour t'aider au cas ou : http://www.safer-networking.org/fr/howto/disable.hs.html


          2) passes ad-remover option L

          • Télécharge Ad-remover ( de C_XX ) sur ton bureau :

          https://www.androidworld.fr/

          ! Déconnecte toi et ferme toutes applications en cours !

          • Double clique sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

          • Double-clique sur le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

          • Au menu principal choisis l'option "L" et tape sur [entrée] .

          • Laisse travailler l'outil et ne touche à rien ...

          --> Poste le rapport qui apparait à la fin , sur le forum ...

          ( Le rapport est sauvegardé sous C:\Ad-report-clean.log )

          ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

          Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

          3) passes usbfix option 2

          • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

          • Télécharges et installes : http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe

          (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

          • Double clic sur le raccourci UsbFix présent sur ton bureau .

          • choisis l'option 2 ( Suppression )

          • Ton bureau disparaitra et le pc redémarrera .

          • Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

          • Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

          • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

          Pendant son nettoyage, l'outil a récolté certains fichiers infectieux.
          Nous vous demandons de nous les faire parvenir pour des futures mises à jour, ainsi que pour un meilleur traitement des infections.
          Nous vous remercions pour votre contribution.


          . UsbFix te proposera d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

          Ce dossier a été créé par UsbFix et est enregistré sur ton bureau.

          Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

          Merci d'avance pour ta contribution !!

          4) fais un examem complet de ton pc avec malwarebytes

          Télécharge Malwarebytes' Anti-Malware: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

          . sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
          . enregistres le sur le bureau
          . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
          . si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
          . rend-toi dans l'onglet, Recherche
          . Sélectionnes Exécuter un examen complet
          . Cliques sur Rechercher
          . Le scan démarre.
          . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
          . Cliques sur Ok pour poursuivre.
          . Si des malwares ont été détectés, cliques sur Afficher les résultats
          . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
          . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
          . redemarre le pc si il le fait pas lui même
          . une fois redémarré double-cliques sur malwarebytes
          . rends toi dans l'onglet rapport/log
          . tu cliques dessus pour l'afficher une fois affiché
          . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
          . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
          . tu cliques droit dans le cadre de la reponse et coller

          Si tu as besoin d'aide regarde ce tutoriel :
          https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
          0
          1. Cher monsieur, je sais pas si le lien est trop gros, mais je n'arrive pas a poser le document inof.
            0
            1. Puis je vous l'envoyer par mail
              Merci
              0
              1. Contributeur sécurité
                tu fais se qui est demander dans le message 4, pense à supprimer un de tes anti-virus car pour ralentir et planter un pc 2 anti-virus c'est pas mal !!

                et pour le info.txt , si trop gros envoie-le sur : http://www.cijoint.fr/index.php ,

                fais parcourir recherche le rapport

                puis sélectionne le rapport en double cliquand dessus

                et puis sur " cliquer ici pour déposer le fichier "

                un lien bleu de cette forme va apparaitre :

                Veuillez noter le lien ci-dessous qui vous permettra d'accéder à ce fichier. 
                C'est ce même lien que vous devrez transmettre à vos correspondants
                http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt 
                


                renvoie le lien tout frais dans ta prochaine reponse .
                0
                1. voila le lien monsieur
                  http://www.cijoint.fr/cjlink.php?file=cj201002/cijTXaGCea.txt
                  0
                  1. Contributeur sécurité
                    ok merci fais ce qu'il est demander demander sur le message 4, on fera un point après malwarebytes lui il mets près de 2 heures !!
                    0
                    1. premier rapport de Ad

                      .
                      ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
                      .
                      Mis à jour par C_XX le 05.02.2010 à 17:34
                      Contact: AdRemover.contact@gmail.com
                      Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                      .
                      Lancé à: 19:58:02, 15/02/2010 | Mode Normal | Option: CLEAN
                      Exécuté de: C:\Ad-Remover\
                      Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
                      Nom du PC: YOUR-A289DD5720 | Utilisateur actuel: hp
                      .
                      ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                      .

                      C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\EoRezo
                      C:\Program Files\EoRezo
                      C:\DOCUME~1\hp\APPLIC~1\EoRezo
                      C:\DOCUME~1\hp\APPLIC~1\ItsLabel

                      (!) -- Fichiers temporaires supprimés.

                      .
                      HKCU\software\EoRezo
                      HKCU\software\ItsLabel
                      HKCU\software\microsoft\internet explorer\searchscopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
                      HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                      HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
                      HKLM\Software\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}
                      HKLM\software\classes\EoRezoBHO.EoBho
                      HKLM\software\classes\EoRezoBHO.EoBho.1
                      HKLM\Software\Classes\Interface\{4A6B3860-FF3F-47A6-A21D-EFE9E56FB1E4}
                      HKLM\Software\Classes\Interface\{6CB9A28B-1D90-F2BA-4DA7-D0630293AC69}
                      HKLM\Software\Classes\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
                      HKLM\Software\Classes\Interface\{F9DD1CE0-8153-F9BE-FFA9-F351EC261D60}
                      HKLM\Software\Classes\TypeLib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
                      HKLM\software\ItsLabel
                      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
                      HKLM\software\microsoft\windows\currentversion\uninstall\eoEngine_is1
                      .
                      ============== Scan additionnel ==============
                      .
                      .
                      * Mozilla FireFox Version 3.5.7 [fr] *
                      .
                      Nom du profil: 23dqz4ay.default (hp)
                      .
                      (hp, prefs.js) Browser.download.lastDir, C:\Documents and Settings\hp\Mes documents
                      (hp, prefs.js) Browser.startup.homepage, hxxp://fr.msn.com/
                      (hp, prefs.js) Extensions.enabledItems, illimitux@illimitux.net:3.5,{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,jqs@sun.com:1.0,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.7
                      (hp, prefs.js) Keyword.URL, hxxp://www.bing.com/search?mkt=fr-FR&form=MIMWA5&q=
                      .
                      .
                      * Internet Explorer Version 8.0.6001.18702 *
                      .
                      [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                      .
                      Do404Search: 01000000
                      Local Page: C:\WINDOWS\system32\blank.htm
                      Show_ToolBar: yes
                      Start Page: hxxp://fr.msn.com/
                      Enable Browser Extensions: yes
                      Use Custom Search URL: 0 (0x0)
                      Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                      Search Bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                      Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                      .
                      [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                      .
                      Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                      Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                      Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                      Delete_Temp_Files_On_Exit: yes
                      Local Page: C:\WINDOWS\system32\blank.htm
                      Start Page: hxxp://fr.msn.com/
                      Use Custom Search URL: 0 (0x0)
                      Search bar: hxxp://search.msn.com/spbasic.htm
                      .
                      [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                      .
                      Tabs: res://ieframe.dll/tabswelcome.htm
                      .
                      ============== Suspect (Cracks, Serials, ...) ==============
                      .
                      C:\Documents and Settings\hp\Application Data\uTorrent\Football Manager 2008 (8.0.2 no-cd crack).zip.torrent
                      C:\Documents and Settings\hp\Application Data\uTorrent\Football Manager 2008 (PC) + crack.torrent
                      C:\Documents and Settings\hp\Application Data\uTorrent\Football Manager 2009 Crack.torrent
                      C:\Documents and Settings\hp\Application Data\uTorrent\Football Manager 2010 [PL] + Patch + Crack.torrent
                      C:\Documents and Settings\hp\Application Data\uTorrent\Football Manager 2010 10.1 Crack [shaks786].rar.torrent
                      C:\Documents and Settings\hp\Application Data\uTorrent\Football_Manager_2008.CRACK-HATRED.torrent
                      C:\Documents and Settings\hp\Mes documents\Downloads\Football Manager 2010 10.1 Crack [shaks786].rar
                      C:\Documents and Settings\hp\Mes documents\Downloads\Football Manager 2010 [PL] + Patch + Crack\FM2010.rar
                      C:\Documents and Settings\hp\Mes documents\Downloads\Football Manager 2010 [PL] + Patch + Crack\ZOBACZ KONIECZNIE !!!!.url
                      C:\Documents and Settings\hp\Mes documents\Downloads\Football Manager 2010 [PL] + Patch + Crack\Crack\fm.exe
                      C:\Documents and Settings\hp\Mes documents\Downloads\Football Manager 2010 [PL] + Patch + Crack\Patch\Patch 10.1.0.exe
                      .
                      ===================================
                      .
                      4824 Octet(s) - C:\Ad-Report-CLEAN[1].log
                      .
                      91 Fichier(s) - C:\DOCUME~1\hp\LOCALS~1\Temp
                      17 Fichier(s) - C:\WINDOWS\Temp
                      9 Fichier(s) - C:\WINDOWS\Prefetch
                      .
                      17 Fichier(s) - C:\Ad-Remover\BACKUP
                      142 Fichier(s) - C:\Ad-Remover\QUARANTINE
                      .
                      Fin à: 20:02:25 | 15/02/2010 - CLEAN[1]
                      .
                      ============== E.O.F ==============
                      .
                      0
                      1. voila le rapport usbfix

                        .

                        ############################## | UsbFix V6.095 |

                        User : hp (Administrateurs) # YOUR-A289DD5720
                        Update on 15/02/2010 by El Desaparecido , C_XX & Chimay8
                        Start at: 20:11:52 | 15/02/2010
                        Website : http://pagesperso-orange.fr/NosTools/index.html
                        Contact : FindyKill.Contact@gmail.com

                        Intel(R) Core(TM)2 CPU T5200 @ 1.60GHz
                        Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                        Internet Explorer 8.0.6001.18702
                        Windows Firewall Status : Enabled
                        AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

                        C:\ -> Disque fixe local # 102,53 Go (15,47 Go free) # NTFS
                        D:\ -> Disque fixe local # 8,23 Go (1,38 Go free) [HP_RECOVERY] # FAT32
                        E:\ -> Disque CD-ROM
                        F:\ -> Disque CD-ROM
                        G:\ -> Disque CD-ROM
                        H:\ -> Disque amovible # 1,92 Go (1,87 Go free) # FAT

                        ############################## | Processus actifs |

                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\csrss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Avira\AntiVir Desktop\sched.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\msdtc.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\Program Files\Google\Update\GoogleUpdate.exe
                        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                        C:\WINDOWS\eHome\ehRecvr.exe
                        C:\WINDOWS\eHome\ehSched.exe
                        C:\Program Files\Google\Update\GoogleUpdate.exe
                        C:\WINDOWS\eHome\ehRec.exe
                        C:\Program Files\Google\Update\GoogleUpdate.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Java\jre6\bin\jqs.exe
                        C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                        C:\WINDOWS\system32\nvsvc32.exe
                        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\ehome\mcrdsvc.exe
                        C:\WINDOWS\system32\mqsvc.exe
                        C:\Program Files\Windows Media Player\WMPNetwk.exe
                        C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                        C:\WINDOWS\system32\mqtgsvc.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\WINDOWS\system32\wbem\wmiprvse.exe

                        ################## | Elements infectieux |

                        Supprimé ! C:\Recycler\S-1-5-21-340340069-3844311140-563639754-1005
                        Supprimé ! D:\autorun.inf
                        Supprimé ! H:\log.txt
                        Supprimé ! H:\HJTInstall.exe

                        ################## | Registre |

                        ################## | Mountpoints2 |

                        Supprimé ! HKCU\...\Explorer\MountPoints2\{14f0795d-0a17-11dd-9fac-0016369f69d2}\Shell\Auto\Command
                        Supprimé ! HKCU\...\Explorer\MountPoints2\{42ba7304-1929-11de-a1d4-0016369f69d2}\Shell\AutoRun\Command
                        Supprimé ! HKCU\...\Explorer\MountPoints2\{65cd77ba-07eb-11dd-9fa4-0016369f69d2}\Shell\Auto\Command

                        ################## | Listing des fichiers présent |

                        [15/02/2010 20:02|--a------|5160] C:\Ad-Report-CLEAN[1].log
                        [13/03/2008 09:35|-rahs----|209] C:\boot.ini
                        [25/03/2006 05:00|-rahs----|4952] C:\Bootfont.bin
                        [29/03/2008 16:23|--a------|1096] C:\hdd.log
                        [?|?|?] C:\hiberfil.sys
                        [18/03/2008 20:19|--a------|1072] C:\hpqp.ini
                        [29/03/2008 16:14|-rahs----|0] C:\IO.SYS
                        [29/03/2008 16:14|-rahs----|0] C:\MSDOS.SYS
                        [25/03/2006 05:00|-rahs----|47564] C:\ntdetect.com
                        [17/08/2008 10:33|-rahs----|252240] C:\ntldr
                        [?|?|?] C:\pagefile.sys
                        [14/02/2010 20:55|--a------|2018] C:\rapport.txt
                        [17/07/2008 19:55|--a------|91] C:\Setup.log
                        [15/02/2010 20:16|--a------|3549] C:\UsbFix.txt
                        [18/03/2008 20:19|--a------|44] C:\XP_TV.ini
                        [27/07/2001 13:07|---hs----|0] D:\AUTOEXEC.BAT
                        [09/01/2002 17:52|---hs----|244] D:\BOOT.INI
                        [25/03/2005 05:00|---hs----|298096] D:\CMLDR
                        [28/07/2001 05:07|---hs----|0] D:\CONFIG.SYS
                        [25/05/2005 01:48|---hs----|102] D:\Desktop.ini
                        [10/09/2002 07:21|---hs----|7850] D:\Folder.htt
                        [17/06/2001 14:31|---hs----|0] D:\GRAPH
                        [25/01/2002 07:21|---hs----|0] D:\GRAPH16
                        [30/11/2004 02:01|---hs----|73728] D:\Info.exe
                        [28/07/2001 05:07|---hs----|0] D:\IO.SYS
                        [28/07/2001 05:07|---hs----|0] D:\MSDOS.SYS
                        [25/07/2001 21:00|---hs----|45124] D:\NTDETECT.COM
                        [17/08/2001 05:32|---hs----|0] D:\NTFS
                        [25/03/2005 05:00|---hs----|298096] D:\NTLDR
                        [03/11/2005 06:19|---hs----|181736] D:\protect.ed
                        [13/09/2006 16:28|---hs----|36] D:\SAVEFILE.DIR
                        [08/02/2002 06:44|---hs----|88038] D:\Warning.bmp
                        [25/03/2005 05:00|---hs----|10] D:\WIN51
                        [25/03/2005 05:00|---hs----|10] D:\WIN51IA
                        [25/03/2005 05:00|---hs----|10] D:\WIN51IA.SP1
                        [25/03/2005 05:00|---hs----|167] D:\WINBOM.INI
                        [23/05/2001 18:19|---hs----|0] D:\XGA
                        [13/09/2006 16:29|---hs----|34] D:\BLOCK.RIN
                        [13/09/2006 16:41|---hs----|894] D:\MASTER.LOG
                        [13/09/2006 16:29|---hs----|0] D:\USER
                        [31/01/2010 11:42|--a------|23828183] H:\lille (v02).fm
                        [31/01/2010 16:20|--a------|24665258] H:\lille.fm
                        [01/02/2010 20:22|--a------|299559] H:\img019.jpg
                        [15/02/2010 19:07|--a------|11597] H:\cyril.docx
                        [15/02/2010 19:07|--a------|781909] H:\RSIT.exe
                        [15/02/2010 19:10|--a------|38839] H:\info.txt
                        [15/02/2010 19:42|--a------|793600] H:\Norton_Removal_Tool.exe
                        [15/02/2010 19:43|--a------|1263511] H:\C_XX_AD-R.exe
                        [15/02/2010 19:44|--a------|11129] H:\2.docx
                        [15/02/2010 19:50|--a------|1942] H:\BOOTEX.LOG
                        [15/02/2010 20:00|--a------|1771828] H:\UsbFix.exe
                        [15/02/2010 20:01|--a------|11850] H:\3.docx
                        [15/02/2010 20:02|--a------|5160] H:\Ad-Report-CLEAN[1].log

                        ################## | Vaccination |

                        # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                        # D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                        # H:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

                        ################## | Upload |

                        Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_YOUR-A289DD5720.zip : https://www.ionos.fr/?affiliate_id=77097
                        Merci pour votre contribution .

                        ################## | ! Fin du rapport # UsbFix V6.095 ! |
                        0
                        1. J'ai lancé malwayr, le dernier point du message 4, je n'ai pas réussi a mettre a jour , impossible de se connecter au serveur, surement lié avec le possible virus
                          0
                          1. Contributeur sécurité
                            ============== Suspect (Cracks, Serials, ...) ============== 
                            . 
                            C:\Documents and Settings\hp\Application Data\uTorrent\Football Manager 2008 (8.0.2 no-cd crack).zip.torrent 
                            C:\Documents and Settings\hp\Application Data\uTorrent\Football Manager 2008 (PC) + crack.torrent 
                            C:\Documents and Settings\hp\Application Data\uTorrent\Football Manager 2009 Crack.torrent 
                            C:\Documents and Settings\hp\Application Data\uTorrent\Football Manager 2010 [PL] + Patch + Crack.torrent 
                            C:\Documents and Settings\hp\Application Data\uTorrent\Football Manager 2010 10.1 Crack [shaks786].rar.torrent 
                            C:\Documents and Settings\hp\Application Data\uTorrent\Football_Manager_2008.CRACK-HATRED.torrent 
                            C:\Documents and Settings\hp\Mes documents\Downloads\Football Manager 2010 10.1 Crack [shaks786].rar 
                            C:\Documents and Settings\hp\Mes documents\Downloads\Football Manager 2010 [PL] + Patch + Crack\FM2010.rar 
                            C:\Documents and Settings\hp\Mes documents\Downloads\Football Manager 2010 [PL] + Patch + Crack\ZOBACZ KONIECZNIE !!!!.url 
                            C:\Documents and Settings\hp\Mes documents\Downloads\Football Manager 2010 [PL] + Patch + Crack\Crack\fm.exe 
                            C:\Documents and Settings\hp\Mes documents\Downloads\Football Manager 2010 [PL] + Patch + Crack\Patch\Patch 10.1.0.exe 


                            tous cela c'est pas très bon sur le pc !!

                            supprimes malwarebytes de sur ton pc , on verras après tu vas passer findykill option 2

                            Télécharge FindyKill (créé par El Desaparecido) allias Chiquitine29 sur ton bureau :

                            http://findykill.changelog.fr/Setup.exe
                            ou
                            http://pagesperso-orange.fr/NosTools/Chiquitine29/Setup.exe

                            ! Déconnecte toi et ferme toutes applications en cours !

                            • Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...)

                            • Double-clique sur le raccourci FindyKill qui est sur ton bureau pour lancer l'outil .

                            • Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

                            • Au second menu choisis l'option 2 (suppression) et tape sur [entrée]

                            • Le pc va redémarrer automatiquement ...

                            le programme va travailler , ne touche à rien ... , ton bureau ne sera pas accessible c est normal !

                            --> Poste le rapport qui apparait à la fin ( le rapport est sauvegardé aussi sous C:\FindyKill.txt )

                            /!\ Si le Bureau ne réapparait pas, presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tape explorer.exe et valide

                            Aides en images : http://pagesperso-orange.fr/NosTools/findykill.html
                            0
                            1. merci encore pour la réponse
                              malwayrabytes tourne depuis 1h30 déjà ca devrai bientot être terminé
                              je le laisse finir, et revient vers vous
                              0
                              1. Contributeur sécurité
                                ok si tu as réussi à lancer malwarebytes laisses le finir et supprimes bien la sélection une fois le scan fini, des fois cela prends du temps généralement 2h mais j'ai vu beaucoup plus !!
                                0
                                1. Pas de problème d'après malwarabytes
                                  pourtant je n'arrive toujours pas a ouvrir la moindre page internet, et par ex impossible de me connecter a msn ( problème fichier host etc)
                                  je met quand meme le rapport

                                  Malwarebytes' Anti-Malware 1.44
                                  Version de la base de données: 3510
                                  Windows 5.1.2600 Service Pack 3
                                  Internet Explorer 8.0.6001.18702

                                  15/02/2010 21:53:48
                                  mbam-log-2010-02-15 (21-53-48).txt

                                  Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|)
                                  Eléments examinés: 224241
                                  Temps écoulé: 1 hour(s), 22 minute(s), 31 second(s)

                                  Processus mémoire infecté(s): 0
                                  Module(s) mémoire infecté(s): 0
                                  Clé(s) du Registre infectée(s): 0
                                  Valeur(s) du Registre infectée(s): 0
                                  Elément(s) de données du Registre infecté(s): 0
                                  Dossier(s) infecté(s): 0
                                  Fichier(s) infecté(s): 0

                                  Processus mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Module(s) mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Clé(s) du Registre infectée(s):
                                  (Aucun élément nuisible détecté)

                                  Valeur(s) du Registre infectée(s):
                                  (Aucun élément nuisible détecté)

                                  Elément(s) de données du Registre infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Dossier(s) infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Fichier(s) infecté(s):
                                  (Aucun élément nuisible détecté)
                                  0
                                  1. Contributeur sécurité
                                    peux tu faire findykill comme proposé dans le message 13 !!
                                    0
                                    1. j'ai l'impression qu'il a bloqué a 40%...
                                      0
                                      1. a nn pardon c'est juste long
                                        0
                                        1. ############################## | FindyKill V5.035 |

                                          # User : hp (Administrateurs) # YOUR-A289DD5720
                                          # Update on 08/02/2010 by El Desaparecido
                                          # Start at: 22:30:07 | 15/02/2010
                                          # Website : http://pagesperso-orange.fr/NosTools/index.html
                                          # Contact : FindyKill.Contact@gmail.com

                                          # Intel(R) Core(TM)2 CPU T5200 @ 1.60GHz
                                          # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                                          # Internet Explorer 8.0.6001.18702
                                          # Windows Firewall Status : Enabled
                                          # AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

                                          # C:\ # Disque fixe local # 102,53 Go (15,42 Go free) # NTFS
                                          # D:\ # Disque fixe local # 8,23 Go (1,38 Go free) [HP_RECOVERY] # FAT32
                                          # E:\ # Disque CD-ROM
                                          # F:\ # Disque CD-ROM
                                          # G:\ # Disque CD-ROM
                                          # H:\ # Disque amovible # 1,92 Go (1,86 Go free) # FAT

                                          ############################## | Processus actifs |

                                          C:\WINDOWS\System32\smss.exe
                                          C:\WINDOWS\system32\csrss.exe
                                          C:\WINDOWS\system32\winlogon.exe
                                          C:\WINDOWS\system32\services.exe
                                          C:\WINDOWS\system32\lsass.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\system32\spoolsv.exe
                                          C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\Explorer.EXE
                                          C:\WINDOWS\system32\msdtc.exe
                                          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                          C:\WINDOWS\eHome\ehRecvr.exe
                                          C:\WINDOWS\eHome\ehSched.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\Program Files\Java\jre6\bin\jqs.exe
                                          C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                          C:\WINDOWS\system32\nvsvc32.exe
                                          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\system32\mqsvc.exe
                                          C:\WINDOWS\system32\wuauclt.exe
                                          C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                          C:\WINDOWS\ehome\mcrdsvc.exe
                                          C:\Program Files\Windows Media Player\WMPNetwk.exe
                                          C:\WINDOWS\system32\mqtgsvc.exe
                                          C:\WINDOWS\system32\dllhost.exe
                                          C:\WINDOWS\system32\wbem\wmiprvse.exe
                                          C:\WINDOWS\system32\wbem\wmiprvse.exe
                                          C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                          C:\WINDOWS\System32\alg.exe

                                          ################## | C: |

                                          ################## | C:\WINDOWS |

                                          ################## | C:\WINDOWS\Prefetch |

                                          Supprimé ! C:\WINDOWS\prefetch\WINUPGRO.EXE-2D513C93.pf

                                          ################## | C:\WINDOWS\system32 |

                                          ################## | C:\WINDOWS\system32\drivers |

                                          ################## | C:\Documents and Settings\hp\Application Data |

                                          ################## | MD5 ... |

                                          ################## | CRC32 ... |

                                          ################## | Temporary Internet Files |

                                          ################## | Registre |

                                          ################## | Etat |

                                          # Mode sans echec : OK

                                          # Affichage des fichiers cachés : OK

                                          # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
                                          # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
                                          # Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
                                          # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
                                          # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
                                          # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

                                          ################## | Fichiers corrompus # Réinstallation requise |

                                          ... OK !

                                          ################## | Upload |

                                          Veuillez envoyer le fichier : C:\FindyKill_Upload_Me_YOUR-A289DD5720.zip : https://www.ionos.fr/?affiliate_id=77097
                                          Merci pour votre contribution .

                                          ################## | ! Fin du rapport # FindyKill V5.035 ! |
                                          0
                                          • 1
                                          • 2
                                          • 3