ZHPDiag diagnostique

Résolu
Bonjour,je suis ici pour vous demander de l'aider car depuis quelques jours mon ordinateur "rame". En faite sur mon ordinateur je dispose de Windows xp sp3 et Linux sous Linux il y a pas de souci particulier mais en revanche sous Windows xp un ralentissement est survenu je ne sais pas comment.

Par ralentissement j'entend 5 min pour arriver sur le bureau quand j'ouvre une fenetre il mais une éternité a l'ouvrir etc...

J'ai cherché a trouver une solution j'ai deja effectué un coups de CCleaner. J'ai fait un diagnostique avec l'aide de ZHPDiag donc je vous donne le rapport en lien :

http://www.cijoint.fr/cjlink.php?file=cj201003/cijGgqBWRA.txt

Merci de votre aide si vous trouver un souci.
Configuration: Windows XP / Firefox 3.5.8

33 réponses

Résumé de la discussion

Un ralentissement persistant affecte Windows XP SP3 alors que Linux fonctionne sans souci, avec un démarrage qui prend près de cinq minutes et des fenêtres qui s’ouvrent lentement. Plusieurs solutions ont été envisagées, notamment une mise à jour de Malwarebytes et le recours à CCleaner avec des réglages avancés et des scans répétés, accompagnées d’un diagnostic ZHPDiag et d’un partage du rapport. D'autres pistes évoquées incluent l’exécution de Combofix et HijackThis, l’éventualité d'un formatage, et des soucis réseau comme un passage en RJ45 et des erreurs de mise à jour 732, sans verdict sur l’issue.

Bobot (l’IA à votre service)
  1. tu n'a pas mis malwarebyts a jour

    va dans l'onglet mise a jour de malwarebyts puis clique sur mise a jour

    et refais le scan demandé par benurr
    2
    1. Non impossible de le trouver non mais c'est bon j'ai déjà formater je te remercie vraiment beaucoup pour ton implication
      1
      1. Contributeur sécurité
        salut

        télécharge

        http://www.malwarebytes.org/mbam/program/mbam-setup.exe

        a l'installation vérifie que mise a jour et lancer programme et scan complet sont bien cocher

        Une fois a jour, le programme va se lancer; clic sur l´onglet paramètre, et coche la case : "Arrêter internet explorer pendant la suppression".

        A la fin du scan clique sur Afficher les résultats

        Vérifier si tout est coché et clic Supprimer la sélection

        S'il t'es demandé de redémarrer >>> clique sur "Yes"

        Et tu poste le rapport générer
        0
        1. merci de ton aide voila le rapport meme si c'est écrit aucun fichier infectés :

          Malwarebytes' Anti-Malware 1.44
          Version de la base de données: 3510
          Windows 5.1.2600 Service Pack 3
          Internet Explorer 6.0.2900.5512

          04/03/2010 18:10:26
          mbam-log-2010-03-04 (18-10-26).txt

          Type de recherche: Examen complet (C:\|D:\|)
          Eléments examinés: 195044
          Temps écoulé: 5 hour(s), 46 minute(s), 4 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 0
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 0

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          (Aucun élément nuisible détecté)
          0
          1. a exusé moi je repost alors !
            0
            1. Quand je lance le programme et que je clique sur mise a jour le message d'erreur suivant s'ouvre :
              " Une erreur est survenue .Veuillez ocntactez le support."
              code error : 732 (12007)

              Quelqu'un a déjà eu ce problème ? car du coups j'ai pas les mise a jour.
              0
              1. Contributeur sécurité
                re

                erreurs 732 correspond a un problème de connectivité internet ou ton pare feu bloque la sortie

                0
                1. je te laisse faire benurr ces ton topic

                  a plus
                  0
                  1. Contributeur sécurité
                    salut a vous

                    non non tu peut rester j'etait juste de passage en se moment tu est plus présent que moi
                    0
                    1. ces vrai mes moins expérimenter que toi

                      la preuve ces que je ne savais pas ce que voulais dire ce message d'erreur de malwarebyts
                      0
                      1. En tout cas merci de votre aide, pourtant j'ai activer le wifi je comprend pas pourquoi il y a l'erreur 732 donc pour simplifier le problème j'ai branché l'ordinateur en rj45 a la livebox. je refait un scan et vous le remet ! désolé si c'est long mais l'ordinateur est très long.
                        0
                        1. Contributeur sécurité
                          a tu toujours l'erreur 732 ?
                          0
                          1. j'ai plus l'erreur 732 avec le cable rj45
                            je post le rapport qui a durer 5H49 quand même et n'a pas trouvé de fichier infecté :s :

                            Malwarebytes' Anti-Malware 1.44
                            Version de la base de données: 3825
                            Windows 5.1.2600 Service Pack 3
                            Internet Explorer 6.0.2900.5512

                            05/03/2010 07:34:35
                            mbam-log-2010-03-05 (07-34-35).txt

                            Type de recherche: Examen complet (C:\|D:\|E:\|F:\|)
                            Eléments examinés: 204326
                            Temps écoulé: 5 hour(s), 49 minute(s), 38 second(s)

                            Processus mémoire infecté(s): 0
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 0
                            Valeur(s) du Registre infectée(s): 0
                            Elément(s) de données du Registre infecté(s): 0
                            Dossier(s) infecté(s): 0
                            Fichier(s) infecté(s): 0

                            Processus mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Valeur(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Elément(s) de données du Registre infecté(s):
                            (Aucun élément nuisible détecté)

                            Dossier(s) infecté(s):
                            (Aucun élément nuisible détecté)

                            Fichier(s) infecté(s):
                            (Aucun élément nuisible détecté)
                            0
                            1. Contributeur sécurité
                              Salut :

                              Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

                              Télécharge et installe List&Kill'em et enregistre le sur ton bureau

                              http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

                              Branche clés usb , disques durs externes , mp3 , mp4 , etc..

                              double clique ( clic droit "exécuter en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

                              coche la case "créer une icône sur le bureau"

                              une fois terminée , clic sur "terminer" et le programme se lancera seul

                              choisis la langue puis choisis l'option 1 = Mode Recherche

                              laisse travailler l'outil

                              à l'apparition de la fenêtre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

                              un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

                              Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'écran "COMPLETED"
                              0
                              1. List'em by g3n-h@ckm@n 1.2.8.5

                                User : Gerard (Administrateurs)
                                Update on 03/03/2010 by g3n-h@ckm@n ::::: 18.30
                                Start at: 13:48:23 | 05/03/2010
                                Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                                Intel(R) Pentium(R) M processor 1.73GHz
                                Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                                Internet Explorer 6.0.2900.5512
                                Windows Firewall Status : Disabled
                                AV : AntiVir Desktop 9.0.1.32 [ (!) Disabled | Updated ]

                                C:\ -> Disque fixe local | 32,6 Go (5,58 Go free) [VAIO] | NTFS
                                D:\ -> Disque fixe local | 17,73 Go (17,66 Go free) [VAIO] | NTFS
                                E:\ -> Disque amovible
                                F:\ -> Disque CD-ROM
                                G:\ -> Disque amovible | 14,51 Go (10,14 Go free) [LOÏS] | FAT32
                                I:\ -> Disque CD-ROM | 633,47 Mo (0 Mo free) [WD SmartWare] | UDF

                                Boot: Normal

                                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\csrss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                                C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
                                C:\Program Files\CDBurnerXP\NMSAccessU.exe
                                C:\WINDOWS\system32\nvsvc32.exe
                                C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
                                C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                                C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                C:\WINDOWS\system32\wdfmgr.exe
                                C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                                C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                                C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
                                C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
                                C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
                                C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                                C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                                C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
                                C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
                                C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
                                C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
                                C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
                                C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
                                C:\WINDOWS\System32\alg.exe
                                C:\Program Files\Apoint\Apoint.exe
                                C:\WINDOWS\system32\ICO.EXE
                                C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                                C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                                C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
                                C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
                                C:\Program Files\Apoint\Apntex.exe
                                C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
                                C:\Program Files\Winamp\winampa.exe
                                C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                C:\WINDOWS\RTHDCPL.EXE
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
                                C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
                                C:\Program Files\Sony\VAIO Launcher\Launcher.exe
                                C:\Program Files\List_Kill'em\List_Kill'em.scr
                                C:\WINDOWS\system32\wscntfy.exe
                                C:\WINDOWS\system32\cmd.exe
                                C:\WINDOWS\system32\wbem\wmiprvse.exe
                                C:\Documents and Settings\Gerard\Local Settings\Temp\3.tmp\pv.exe

                                ======================
                                Keys "Run"
                                ======================
                                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
                                msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                Apoint REG_SZ C:\Program Files\Apoint\Apoint.exe
                                NvCplDaemon REG_SZ RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                AzMixerSel REG_SZ C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                                Mouse Suite 98 Daemon REG_SZ ICO.EXE
                                Persistence REG_SZ C:\WINDOWS\system32\igfxpers.exe
                                SonyPowerCfg REG_SZ C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                                ISBMgr.exe REG_SZ C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                                VAIO Update 2 REG_SZ "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
                                PDService.exe REG_SZ C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
                                IgfxTray REG_SZ C:\WINDOWS\system32\igfxtray.exe
                                HotKeysCmds REG_SZ C:\WINDOWS\system32\hkcmd.exe
                                Acrobat Assistant 7.0 REG_SZ "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
                                <NO NAME> REG_SZ
                                WinampAgent REG_SZ "C:\Program Files\Winamp\winampa.exe"
                                avgnt REG_SZ "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                                High Definition Audio Property Page Shortcut REG_SZ HDAShCut.exe
                                RTHDCPL REG_SZ RTHDCPL.EXE

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                                =====================
                                Other Keys
                                =====================
                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                                dontdisplaylastusername REG_DWORD 0 (0x0)
                                legalnoticecaption REG_SZ
                                legalnoticetext REG_SZ
                                shutdownwithoutlogon REG_DWORD 1 (0x1)
                                undockwithoutlogon REG_DWORD 1 (0x1)

                                ===============
                                [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                                NoDriveTypeAutoRun REG_DWORD 145 (0x91)

                                ===============
                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                                HonorAutoRunSetting REG_DWORD 1 (0x1)

                                ===============
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                                AppInit_DLLS REG_SZ

                                ===============
                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                AutoRestartShell REG_DWORD 1 (0x1)
                                DefaultDomainName REG_SZ THOMAS_PORTABLE
                                DefaultUserName REG_SZ Gerard
                                LegalNoticeCaption REG_SZ
                                LegalNoticeText REG_SZ
                                PowerdownAfterShutdown REG_SZ 0
                                ReportBootOk REG_SZ 1
                                Shell REG_SZ Explorer.exe
                                ShutdownWithoutLogon REG_SZ 0
                                System REG_SZ
                                Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
                                VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                                SfcQuota REG_DWORD -1 (0xffffffff)
                                allocatecdroms REG_SZ 0
                                allocatedasd REG_SZ 0
                                allocatefloppies REG_SZ 0
                                cachedlogonscount REG_SZ 10
                                forceunlocklogon REG_DWORD 0 (0x0)
                                passwordexpirywarning REG_DWORD 14 (0xe)
                                scremoveoption REG_SZ 0
                                AllowMultipleTSSessions REG_DWORD 1 (0x1)
                                UIHost REG_EXPAND_SZ logonui.exe
                                LogonType REG_DWORD 1 (0x1)
                                Background REG_SZ 0 0 0
                                DebugServerCommand REG_SZ no
                                SFCDisable REG_DWORD 0 (0x0)
                                WinStationsDisabled REG_SZ 0
                                HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
                                ShowLogonOptions REG_DWORD 0 (0x0)
                                AltDefaultUserName REG_SZ Gerard
                                AltDefaultDomainName REG_SZ THOMAS_PORTABLE
                                ChangePasswordUseKerberos REG_DWORD 1 (0x1)

                                ===============
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

                                ===============
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                                {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

                                ===============
                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                                %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                                C:\Program Files\BitComet\BitComet.exe REG_SZ C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet.exe
                                C:\Program Files\Mozilla Firefox\firefox.exe REG_SZ C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox
                                C:\Program Files\Internet Explorer\IEXPLORE.EXE REG_SZ C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer
                                C:\Program Files\Skype\Phone\Skype.exe REG_SZ C:\Program Files\Skype\Phone\Skype.exe:*:Disabled:Skype
                                C:\Program Files\Yahoo!\Messenger\YServer.exe REG_SZ C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Disabled:Yahoo! FT Server
                                C:\Program Files\Yahoo!\Messenger\YPager.exe REG_SZ C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Disabled:Yahoo! Messenger
                                C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                                C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                                C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
                                C:\Program Files\ma-config.com\maconfservice.exe REG_SZ C:\Program Files\ma-config.com\maconfservice.exe:LocalSubNet:Enabled:maconfservice
                                C:\Program Files\PokerStrategy.com\PokerStrategy.com Equilator\Equilator.exe REG_SZ C:\Program Files\PokerStrategy.com\PokerStrategy.com Equilator\Equilator.exe:*:Enabled:PokerStrategy Equilator
                                C:\Program Files\Warcraft III\Warcraft III.exe REG_SZ C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III
                                C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE REG_SZ C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook
                                %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                                %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                                C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                                C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                                C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
                                %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000

                                ===============
                                ActivX controls
                                ===============
                                HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{867E13F2-7F31-44FB-AC97-CD38E0DC46EF}
                                HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
                                HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}

                                ===============
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
                                HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}

                                ==============
                                BHO :
                                ======
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]

                                ===
                                DNS
                                ===

                                HKLM\SYSTEM\CCS\Services\Tcpip\..\{602AE184-2DC5-476D-A943-970E7BC305AE}: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS1\Services\Tcpip\..\{889C0D38-4A42-43D3-9A7C-82870A0D296D}: NameServer=81.243.149.1,80.10.246.3
                                HKLM\SYSTEM\CS2\Services\Tcpip\..\{602AE184-2DC5-476D-A943-970E7BC305AE}: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                                ================
                                Internet Explorer :
                                ================
                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                                Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home

                                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                Start Page REG_SZ http://google.atcomet.com/b/

                                ========
                                Services
                                ========
                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                                Ndisuio : 0x3 ( OK = 3 )
                                EapHost : 0x3 ( OK = 2 )
                                SharedAccess : 0x2 ( OK = 2 )
                                wuauserv : 0x2 ( OK = 2 )

                                =========
                                Atapi.sys
                                =========

                                %%%% HASHDEEP-1.0
                                %%%% size,md5,sha256,filename
                                ## Invoked from: C:\Documents and Settings\Gerard\Local Settings\Temp\3.tmp
                                ## C:\> hashdeep.exe C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
                                ##
                                95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
                                %%%% HASHDEEP-1.0
                                %%%% size,md5,sha256,filename
                                ## Invoked from: C:\Documents and Settings\Gerard\Local Settings\Temp\3.tmp
                                ## C:\> hashdeep.exe C:\WINDOWS\ServicePackFiles\i386\atapi.sys
                                ##
                                96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\ServicePackFiles\i386\atapi.sys
                                %%%% HASHDEEP-1.0
                                %%%% size,md5,sha256,filename
                                ## Invoked from: C:\Documents and Settings\Gerard\Local Settings\Temp\3.tmp
                                ## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
                                ##
                                96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\system32\drivers\atapi.sys
                                %%%% HASHDEEP-1.0
                                %%%% size,md5,sha256,filename
                                ## Invoked from: C:\Documents and Settings\Gerard\Local Settings\Temp\3.tmp
                                ## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\i386\atapi.sys
                                ##
                                95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\i386\atapi.sys

                                Référence :
                                ==========

                                Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
                                Win XP_32b : a64013e98426e1877cb653685c5c0009
                                Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                                Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                                Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                                Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                                Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                                Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                                Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                                Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

                                =======
                                Drive :
                                =======

                                D‚fragmenteur de disque Windows
                                Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

                                Rapport d'analyse
                                32,60 Go total, 5,58 Go libre (17%), 4% fragment‚ (fragmentation du fichier 8%)

                                Il ne vous est pas n‚cessaire de d‚fragmenter ce volume.

                                ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                                Present !! : C:\WINDOWS\002693_.tmp
                                Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
                                Present !! : C:\Documents and Settings\Gerard\Local Settings\Application Data\postgresinstall.bat

                                ¤¤¤¤¤¤¤¤¤¤ Keys :

                                Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                                Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                                Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
                                Present !! : HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
                                Present !! : HKLM\Software\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}

                                ============

                                catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                Rootkit scan 2010-03-05 14:11:10
                                Windows 5.1.2600 Service Pack 3 NTFS

                                scanning hidden processes ...

                                scanning hidden services & system hive ...

                                scanning hidden registry entries ...

                                scanning hidden files ...

                                scan completed successfully
                                hidden processes: 0
                                hidden services: 0
                                hidden files: 0

                                Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                                device: opened successfully
                                user: MBR read successfully
                                called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
                                kernel: MBR read successfully
                                user & kernel MBR OK

                                ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                                End of scan : 14:39:58,56
                                0
                                1. Contributeur sécurité
                                  ▶ Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
                                  mais cette fois-ci :

                                  ▶ choisis l'option 2 = Mode Suppression

                                  laisse travailler l'outil.

                                  en fin de scan un rapport s'ouvre

                                  ▶ colle le contenu dans ta réponse

                                  ensuite :

                                  ▶ Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
                                  mais cette fois-ci :

                                  ▶ choisis l'option 6 = Restore MBR

                                  laisse travailler l'outil.

                                  en fin de scan un rapport s'ouvre

                                  ▶ colle le contenu dans ta réponse
                                  0
                                  1. voici le rapport pour l'option 2 :

                                    List'em by g3n-h@ckm@n 1.2.8.5

                                    User : Gerard (Administrateurs)
                                    Update on 03/03/2010 by g3n-h@ckm@n ::::: 18.30
                                    Start at: 13:48:23 | 05/03/2010
                                    Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                                    Intel(R) Pentium(R) M processor 1.73GHz
                                    Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                                    Internet Explorer 6.0.2900.5512
                                    Windows Firewall Status : Disabled
                                    AV : AntiVir Desktop 9.0.1.32 [ (!) Disabled | Updated ]

                                    C:\ -> Disque fixe local | 32,6 Go (5,58 Go free) [VAIO] | NTFS
                                    D:\ -> Disque fixe local | 17,73 Go (17,66 Go free) [VAIO] | NTFS
                                    E:\ -> Disque amovible
                                    F:\ -> Disque CD-ROM
                                    G:\ -> Disque amovible | 14,51 Go (10,14 Go free) [LOÏS] | FAT32
                                    I:\ -> Disque CD-ROM | 633,47 Mo (0 Mo free) [WD SmartWare] | UDF

                                    Boot: Normal

                                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\csrss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                                    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                    C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
                                    C:\Program Files\CDBurnerXP\NMSAccessU.exe
                                    C:\WINDOWS\system32\nvsvc32.exe
                                    C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
                                    C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                                    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                    C:\WINDOWS\system32\wdfmgr.exe
                                    C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                                    C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                                    C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
                                    C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
                                    C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
                                    C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                                    C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                                    C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
                                    C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
                                    C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
                                    C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
                                    C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
                                    C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
                                    C:\WINDOWS\System32\alg.exe
                                    C:\Program Files\Apoint\Apoint.exe
                                    C:\WINDOWS\system32\ICO.EXE
                                    C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                                    C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                                    C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
                                    C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
                                    C:\Program Files\Apoint\Apntex.exe
                                    C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
                                    C:\Program Files\Winamp\winampa.exe
                                    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                    C:\WINDOWS\RTHDCPL.EXE
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                    C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
                                    C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
                                    C:\Program Files\Sony\VAIO Launcher\Launcher.exe
                                    C:\Program Files\List_Kill'em\List_Kill'em.scr
                                    C:\WINDOWS\system32\wscntfy.exe
                                    C:\WINDOWS\system32\cmd.exe
                                    C:\WINDOWS\system32\wbem\wmiprvse.exe
                                    C:\Documents and Settings\Gerard\Local Settings\Temp\3.tmp\pv.exe

                                    ======================
                                    Keys "Run"
                                    ======================
                                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
                                    msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    Apoint REG_SZ C:\Program Files\Apoint\Apoint.exe
                                    NvCplDaemon REG_SZ RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                    AzMixerSel REG_SZ C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                                    Mouse Suite 98 Daemon REG_SZ ICO.EXE
                                    Persistence REG_SZ C:\WINDOWS\system32\igfxpers.exe
                                    SonyPowerCfg REG_SZ C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                                    ISBMgr.exe REG_SZ C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                                    VAIO Update 2 REG_SZ "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
                                    PDService.exe REG_SZ C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
                                    IgfxTray REG_SZ C:\WINDOWS\system32\igfxtray.exe
                                    HotKeysCmds REG_SZ C:\WINDOWS\system32\hkcmd.exe
                                    Acrobat Assistant 7.0 REG_SZ "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
                                    <NO NAME> REG_SZ
                                    WinampAgent REG_SZ "C:\Program Files\Winamp\winampa.exe"
                                    avgnt REG_SZ "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                                    High Definition Audio Property Page Shortcut REG_SZ HDAShCut.exe
                                    RTHDCPL REG_SZ RTHDCPL.EXE

                                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                                    =====================
                                    Other Keys
                                    =====================
                                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                                    dontdisplaylastusername REG_DWORD 0 (0x0)
                                    legalnoticecaption REG_SZ
                                    legalnoticetext REG_SZ
                                    shutdownwithoutlogon REG_DWORD 1 (0x1)
                                    undockwithoutlogon REG_DWORD 1 (0x1)

                                    ===============
                                    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                                    NoDriveTypeAutoRun REG_DWORD 145 (0x91)

                                    ===============
                                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                                    HonorAutoRunSetting REG_DWORD 1 (0x1)

                                    ===============
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                                    AppInit_DLLS REG_SZ

                                    ===============
                                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                    AutoRestartShell REG_DWORD 1 (0x1)
                                    DefaultDomainName REG_SZ THOMAS_PORTABLE
                                    DefaultUserName REG_SZ Gerard
                                    LegalNoticeCaption REG_SZ
                                    LegalNoticeText REG_SZ
                                    PowerdownAfterShutdown REG_SZ 0
                                    ReportBootOk REG_SZ 1
                                    Shell REG_SZ Explorer.exe
                                    ShutdownWithoutLogon REG_SZ 0
                                    System REG_SZ
                                    Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
                                    VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                                    SfcQuota REG_DWORD -1 (0xffffffff)
                                    allocatecdroms REG_SZ 0
                                    allocatedasd REG_SZ 0
                                    allocatefloppies REG_SZ 0
                                    cachedlogonscount REG_SZ 10
                                    forceunlocklogon REG_DWORD 0 (0x0)
                                    passwordexpirywarning REG_DWORD 14 (0xe)
                                    scremoveoption REG_SZ 0
                                    AllowMultipleTSSessions REG_DWORD 1 (0x1)
                                    UIHost REG_EXPAND_SZ logonui.exe
                                    LogonType REG_DWORD 1 (0x1)
                                    Background REG_SZ 0 0 0
                                    DebugServerCommand REG_SZ no
                                    SFCDisable REG_DWORD 0 (0x0)
                                    WinStationsDisabled REG_SZ 0
                                    HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
                                    ShowLogonOptions REG_DWORD 0 (0x0)
                                    AltDefaultUserName REG_SZ Gerard
                                    AltDefaultDomainName REG_SZ THOMAS_PORTABLE
                                    ChangePasswordUseKerberos REG_DWORD 1 (0x1)

                                    ===============
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

                                    ===============
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                                    {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

                                    ===============
                                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                                    %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                                    C:\Program Files\BitComet\BitComet.exe REG_SZ C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet.exe
                                    C:\Program Files\Mozilla Firefox\firefox.exe REG_SZ C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox
                                    C:\Program Files\Internet Explorer\IEXPLORE.EXE REG_SZ C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer
                                    C:\Program Files\Skype\Phone\Skype.exe REG_SZ C:\Program Files\Skype\Phone\Skype.exe:*:Disabled:Skype
                                    C:\Program Files\Yahoo!\Messenger\YServer.exe REG_SZ C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Disabled:Yahoo! FT Server
                                    C:\Program Files\Yahoo!\Messenger\YPager.exe REG_SZ C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Disabled:Yahoo! Messenger
                                    C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                                    C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
                                    C:\Program Files\ma-config.com\maconfservice.exe REG_SZ C:\Program Files\ma-config.com\maconfservice.exe:LocalSubNet:Enabled:maconfservice
                                    C:\Program Files\PokerStrategy.com\PokerStrategy.com Equilator\Equilator.exe REG_SZ C:\Program Files\PokerStrategy.com\PokerStrategy.com Equilator\Equilator.exe:*:Enabled:PokerStrategy Equilator
                                    C:\Program Files\Warcraft III\Warcraft III.exe REG_SZ C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III
                                    C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE REG_SZ C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook
                                    %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000

                                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                                    %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                                    C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                                    C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
                                    %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000

                                    ===============
                                    ActivX controls
                                    ===============
                                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{867E13F2-7F31-44FB-AC97-CD38E0DC46EF}
                                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
                                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}

                                    ===============
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
                                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}

                                    ==============
                                    BHO :
                                    ======
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]

                                    ===
                                    DNS
                                    ===

                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{602AE184-2DC5-476D-A943-970E7BC305AE}: DhcpNameServer=192.168.1.1
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{889C0D38-4A42-43D3-9A7C-82870A0D296D}: NameServer=81.243.149.1,80.10.246.3
                                    HKLM\SYSTEM\CS2\Services\Tcpip\..\{602AE184-2DC5-476D-A943-970E7BC305AE}: DhcpNameServer=192.168.1.1
                                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                    HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                                    ================
                                    Internet Explorer :
                                    ================
                                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                                    Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home

                                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                    Start Page REG_SZ http://google.atcomet.com/b/

                                    ========
                                    Services
                                    ========
                                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                                    Ndisuio : 0x3 ( OK = 3 )
                                    EapHost : 0x3 ( OK = 2 )
                                    SharedAccess : 0x2 ( OK = 2 )
                                    wuauserv : 0x2 ( OK = 2 )

                                    =========
                                    Atapi.sys
                                    =========

                                    %%%% HASHDEEP-1.0
                                    %%%% size,md5,sha256,filename
                                    ## Invoked from: C:\Documents and Settings\Gerard\Local Settings\Temp\3.tmp
                                    ## C:\> hashdeep.exe C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
                                    ##
                                    95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
                                    %%%% HASHDEEP-1.0
                                    %%%% size,md5,sha256,filename
                                    ## Invoked from: C:\Documents and Settings\Gerard\Local Settings\Temp\3.tmp
                                    ## C:\> hashdeep.exe C:\WINDOWS\ServicePackFiles\i386\atapi.sys
                                    ##
                                    96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\ServicePackFiles\i386\atapi.sys
                                    %%%% HASHDEEP-1.0
                                    %%%% size,md5,sha256,filename
                                    ## Invoked from: C:\Documents and Settings\Gerard\Local Settings\Temp\3.tmp
                                    ## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
                                    ##
                                    96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\system32\drivers\atapi.sys
                                    %%%% HASHDEEP-1.0
                                    %%%% size,md5,sha256,filename
                                    ## Invoked from: C:\Documents and Settings\Gerard\Local Settings\Temp\3.tmp
                                    ## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\i386\atapi.sys
                                    ##
                                    95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\i386\atapi.sys

                                    Référence :
                                    ==========

                                    Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
                                    Win XP_32b : a64013e98426e1877cb653685c5c0009
                                    Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                                    Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                                    Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                                    Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                                    Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                                    Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                                    Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                                    Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

                                    =======
                                    Drive :
                                    =======

                                    D‚fragmenteur de disque Windows
                                    Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

                                    Rapport d'analyse
                                    32,60 Go total, 5,58 Go libre (17%), 4% fragment‚ (fragmentation du fichier 8%)

                                    Il ne vous est pas n‚cessaire de d‚fragmenter ce volume.

                                    ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                                    Present !! : C:\WINDOWS\002693_.tmp
                                    Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
                                    Present !! : C:\Documents and Settings\Gerard\Local Settings\Application Data\postgresinstall.bat

                                    ¤¤¤¤¤¤¤¤¤¤ Keys :

                                    Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                                    Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                                    Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
                                    Present !! : HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
                                    Present !! : HKLM\Software\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}

                                    ============

                                    catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                    Rootkit scan 2010-03-05 14:11:10
                                    Windows 5.1.2600 Service Pack 3 NTFS

                                    scanning hidden processes ...

                                    scanning hidden services & system hive ...

                                    scanning hidden registry entries ...

                                    scanning hidden files ...

                                    scan completed successfully
                                    hidden processes: 0
                                    hidden services: 0
                                    hidden files: 0

                                    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                                    device: opened successfully
                                    user: MBR read successfully
                                    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
                                    kernel: MBR read successfully
                                    user & kernel MBR OK

                                    ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                                    End of scan : 14:39:58,56

                                    voici le rapport pour l'option6 :

                                    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                                    device: opened successfully
                                    user: MBR read successfully
                                    kernel: MBR read successfully
                                    user & kernel MBR OK

                                    Merci de ton aide toujours et encore !
                                    0
                                    1. Contributeur sécurité
                                      Bonjourrr;

                                      poste un rapport hijackthis (outil de diagnostic)
                                      Télécharge http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe

                                      --) Enregistre HJTInstall.exe sur ton bureau
                                      --) Double-clique sur HJTInstall.exe pour lancer le programme
                                      --) Par défaut, il s'installera içi C:\Programme Files\Trend Micro\HijackThis
                                      --) Accepte la license en cliquant sur le bouton "I Accept"
                                      --) Choisis l'option "Do a system scan and save a log file"
                                      --) Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
                                      --) Clique sur "Édition -> Sélectionner tout", puis sur "Édition -> Copier" pour copier tout le contenu du rapport
                                      --) Colle le rapport que tu viens de copier sur ce forum
                                      --) Ne fixe encore AUCUNE ligne,
                                      0
                                      1. Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 14:56:38, on 06/03/2010
                                        Platform: Windows XP SP3 (WinNT 5.01.2600)
                                        MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\WINDOWS\System32\smss.exe
                                        C:\WINDOWS\system32\winlogon.exe
                                        C:\WINDOWS\system32\services.exe
                                        C:\WINDOWS\system32\lsass.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                        C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                        C:\WINDOWS\Explorer.EXE
                                        C:\WINDOWS\system32\spoolsv.exe
                                        C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                        C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                                        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                        C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
                                        C:\Program Files\CDBurnerXP\NMSAccessU.exe
                                        C:\WINDOWS\system32\nvsvc32.exe
                                        C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                                        C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                        C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                                        C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                                        C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
                                        C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
                                        C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                                        C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                                        C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
                                        C:\Program Files\Apoint\Apoint.exe
                                        C:\WINDOWS\system32\ICO.EXE
                                        C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                                        C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                                        C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
                                        C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
                                        C:\Program Files\Apoint\Apntex.exe
                                        C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
                                        C:\Program Files\Winamp\winampa.exe
                                        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                        C:\WINDOWS\RTHDCPL.EXE
                                        C:\WINDOWS\system32\ctfmon.exe
                                        C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
                                        C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
                                        C:\WINDOWS\system32\wscntfy.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
                                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                        O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.7.16.dll
                                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                        O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                        O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                                        O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
                                        O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                                        O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                                        O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                                        O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
                                        O4 - HKLM\..\Run: [PDService.exe] C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
                                        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                                        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                                        O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
                                        O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                                        O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                                        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                        O4 - HKUS\S-1-5-21-734083892-158431949-3728071396-1007\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'elephant')
                                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                        O4 - S-1-5-21-734083892-158431949-3728071396-1007 Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'elephant')
                                        O4 - S-1-5-21-734083892-158431949-3728071396-1007 User Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'elephant')
                                        O4 - S-1-5-18 Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'SYSTEM')
                                        O4 - .DEFAULT Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'Default user')
                                        O4 - .DEFAULT User Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'Default user')
                                        O4 - Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe
                                        O4 - Global Startup: WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
                                        O4 - Global Startup: WDSmartWare.lnk = C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
                                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
                                        O8 - Extra context menu item: Tout télécharger avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                                        O8 - Extra context menu item: Télécharger avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                                        O8 - Extra context menu item: Télécharger toutes les vidéos avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                                        O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
                                        O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.7.16.dll/206 (file missing)
                                        O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/fr/
                                        O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (Ma-Config control) - http://ma-config.com/plugins/MaConfig_4_0_1_3.cab
                                        O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                                        O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                        O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                        O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                        O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
                                        O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                                        O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
                                        O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
                                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                        O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
                                        O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
                                        O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                                        O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                        O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                        O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
                                        O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
                                        O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
                                        O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\VAIO Entertainment\VzTaskScheduler.exe
                                        O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                                        O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                                        O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                                        O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                                        O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                                        O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                                        O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
                                        O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                                        O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                                        O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                                        O23 - Service: WD SmartWare Drive Manager (WDDMService) - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
                                        O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
                                        0
                                        • 1
                                        • 2