Acces Internet

Bonjour

J'ai des accés trés lent qd j'ouvre des pages sur internet, par contre mon PC fonctionne normalement.
Quelqu'un peut me conseiller
merci d'avance
Ollyve

25 réponses

Résumé de la discussion

Le problème décrit concerne un accès lent à l'ouverture des pages web malgré un fonctionnement général normal du PC sous Windows XP et Internet Explorer 7. Des solutions essentielles portent sur des analyses approfondies avec Malwarebytes Anti-Malware et l'utilisation de HijackThis pour détecter et supprimer des malwares et des éléments indésirables impactant la navigation. Des étapes complémentaires préconisent la suppression d'éléments problématiques, la vérification des rapports générés et le redémarrage du système pour observer l'effet après nettoyage, puis l'examen du comportement réseau. En cas de lenteurs persistantes, des options comme la mise à jour vers IE8 ou l'installation d'outils de diagnostic et de sécurité supplémentaires sont évoquées pour améliorer les performances et la stabilité.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonjour, pourrais tu nous poster un rapport de zhpdiag pour voir si infection !!

    Ouvre ce lien et télécharge ZHPDiag :

    https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

    cliques sur télécharger "celui de droite"

    Enregistres le sur ton Bureau.

    Une fois le téléchargement achevé,fais un double cliques sur ZHPDiag.exe et suis les instructions.

    N'oublies pas de cocher la case qui permet de mettre un raccourci sur le Bureau.

    Double cliques sur le raccourci ZHPDiag sur ton Bureau.

    /|\ l'outil a créé 2 icônes ZHPDiag et ZHPFix.

    Clique sur le Tournevis puis sur Tous pour cocher toutes les cases des options.

    Décoches les cases O45 et O61.

    Cliques sur la loupe pour lancer l'analyse.

    Laisses l'outil travailler, il peut être assez long.

    Fermes ZHPDiag en fin d'analyse.

    Pour transmettre le rapport clique sur ce lien :

    http://www.cijoint.fr/index.php

    Clique sur Parcourir et cherche le répertoire où est installé ZHPDiag (en général C:\Program Files\ZHPDiag).

    Sélectionne le fichier ZHPDiag.txt.

    Clique sur "Cliquez ici pour déposer le fichier".

    Un lien bleu de cette forme :

    http://www.cijoint.fr/cjlink.php?file=cj200905/cijSKAP5fU.txt

    est ajouté dans la page.

    Copie ce lien dans ta réponse.
    1. Contributeur sécurité
      bonjour, pas la peinne de passer par pm j'ai la réponse en même temps !!

      bon tu vas passer findykill en option 2

      Télécharge FindyKill (créé par El Desaparecido) allias Chiquitine29 sur ton bureau :

      http://findykill.changelog.fr/Setup.exe
      ou
      http://pagesperso-orange.fr/NosTools/Chiquitine29/Setup.exe

      ! Déconnecte toi et ferme toutes applications en cours !

      * Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...)

      * Double-clique sur le raccourci FindyKill qui est sur ton bureau pour lancer l'outil .

      * Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

      * Au second menu choisis l'option 2 (suppression) et tape sur [entrée]

      * Le pc va redémarrer automatiquement ...

      le programme va travailler , ne touche à rien ... , ton bureau ne sera pas accessible c est normal !

      --> Poste le rapport qui apparait à la fin ( le rapport est sauvegardé aussi sous C:\FindyKill.txt )

      /!\ Si le Bureau ne réapparait pas, presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tape explorer.exe et valide

      Aides en images : http://pagesperso-orange.fr/NosTools/findykill.html
      1. Voici le rapport
        ############################## | FindyKill V5.038 |

        # User : Ollyve () # Ollyv-TTLL6V
        # Update on 15/03/2010 by El Desaparecido
        # Start at: 20:44:19 | 04/04/2010
        # Website : http://pagesperso-orange.fr/NosTools/index.html
        # Contact : FindyKill.Contact@gmail.com

        # Intel(R) Pentium(R) 4 CPU 2.80GHz
        # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
        # Internet Explorer 7.0.5730.11
        # Windows Firewall Status : Disabled
        # AV : AVG Anti-Virus Free 9.0 [ Enabled | Updated ]
        # FW : ZoneAlarm Firewall[ Enabled ]7.0.483.000

        # A:\ # Lecteur de disquettes 3 ½ pouces
        # C:\ # Disque fixe local # 37,11 Go (6,61 Go free) [Disque local] # NTFS
        # D:\ # Disque CD-ROM
        # E:\ # Disque CD-ROM
        # F:\ # Disque fixe local # 77,39 Go (62,98 Go free) [Disque local] # NTFS
        # G:\ # Disque amovible
        # H:\ # Disque amovible
        # I:\ # Disque amovible
        # J:\ # Disque amovible
        # L:\ # Disque amovible # 1,92 Go (1,26 Go free) # FAT

        ################## | Eléments infectieux |

        ################## | MD5 ... |

        ################## | CRC32 ... |

        ################## | Registre |

        ################## | Etat |

        # Mode sans echec : OK

        # Affichage des fichiers cachés : OK

        # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
        # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
        # Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
        # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
        # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
        # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

        ################## | Fichiers corrompus |

        ... OK !

        ################## | Upload |

        Veuillez envoyer le fichier : C:\FindyKill_Upload_Me_Ollyv-TTLL6V.zip : https://www.ionos.fr/?affiliate_id=77097
        Merci pour votre contribution .

        ################## | ! Fin du rapport # FindyKill V5.038 ! |
        1. Contributeur sécurité
          ok , lui il nous trouve rien !! bizare vu le rapport de zhpdiag tu fais un examzen complet avec malwarebytes attention près de 2h et des fois plus !!

          Télécharge Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam/program/mbam-setup.exe

          . enregistres le sur le bureau
          . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
          . si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
          . rend-toi dans l'onglet, Recherche
          . Sélectionnes Exécuter un examen complet
          . Cliques sur Rechercher
          . Le scan démarre.
          . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
          . Cliques sur Ok pour poursuivre.
          . Si des malwares ont été détectés, cliques sur Afficher les résultats
          . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
          . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
          . redemarre le pc si il le fait pas lui même
          . une fois redémarré double-cliques sur malwarebytes
          . rends toi dans l'onglet rapport/log
          . tu cliques dessus pour l'afficher une fois affiché
          . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
          . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
          . tu cliques droit dans le cadre de la reponse et coller

          Si tu as besoin d'aide regarde ce tutoriel :
          https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
          1. Malwarebytes' Anti-Malware, jel'ai sur le Pc, demain main je ferai l'analyse et je mettrai le rapport d'analyse
            NB j'en fais de tps en tps
            Merci et a demain
            1. Contributeur sécurité
              ok mais fais la mise à jour avant et fais bien un examen complet
              1. Ok j'ai regardé mon dernier examen Malwarebytes du 26 mars pas de PB et scan de 2H13
                je ferai la mise à jour avt pas de Pb
                salut a demain
                1. Voici le rapport de l'examen complet Malwarebytes .A priori rien d'anormal !

                  A+ pour d'autres conseils

                  Malwarebytes' Anti-Malware 1.45
                  www.malwarebytes.org

                  Version de la base de données: 3955

                  Windows 5.1.2600 Service Pack 3
                  Internet Explorer 7.0.5730.11

                  05/04/2010 08:37:31
                  mbam-log-2010-04-05 (08-37-31).txt

                  Type d'examen: Examen complet (C:\|F:\|)
                  Elément(s) analysé(s): 215489
                  Temps écoulé: 2 heure(s), 6 minute(s), 21 seconde(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 0
                  Valeur(s) du Registre infectée(s): 0
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 0

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Valeur(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  (Aucun élément nuisible détecté)
                  1. Pour info cetaines fois si la page internet tarde à s'ouvrir je clique une 2° ou 3° fois sur le lien '"ou je fais actualiser" et cela marche
                    pour les fonctionnalites sur tout autre logiciel les commandes passent trés bien
                    A+
                    1. Contributeur sécurité
                      ok , tu passes list&kill"em option 1 et 2, et tu postes un Hijackthis pour finaliser cela , merci

                      1) passes lis&kill"em option 1 et 2

                      Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

                      . Télécharge List&Kill'em et enregistre le sur ton bureau

                      . Branche clés usb , disques durs externes , mp3 , mp4 , etc..

                      double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

                      coche la case "creer une icone sur le bureau"

                      une fois terminée , clic sur "terminer" et le programme se lancera seul

                      choisis la langue puis choisis l'option 1 = Mode Recherche

                      . laisse travailler l'outil

                      à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

                      un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

                      . Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

                      tu peux supprimer le rapport catchme.log de ton bureau maintenant.

                      ==============================

                      . Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
                      mais cette fois-ci :

                      . choisis l'option 2 = Mode Suppression

                      laisse travailler l'outil.

                      en fin de scan un rapport s'ouvre

                      . colle le contenu dans ta reponse

                      2) postes un hiajckthis , merci

                      télécharge Hijackthis : http://www.trendsecure.com/portal/fr/_download/HJTInstall.exe

                      .enregistres le sur le bureau
                      .Tu fermes tout les programmes ouverts y compris le navigateur. sauf ton anti-virus et pare-feux
                      .installes le , il va s'installer par défaut dans C:\Program Files\Trend Micro\HijackThis
                      .Cliques sur "Do a system scan and save the logfile"
                      .Cela va t'ouvrir un bloc note à la fin du scan.
                      .Copie son contenu et poste le dans ton prochain message. sinon le rapport est dans C:\Program Files\Trend Micro\HijackThis\ hijackthis "document texte"

                      si besion d'aide pour l'installation : https://www.androidworld.fr/

                      des expliquations en images pour l'utiliser : http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
                      1. List'em by g3n-h@ckm@n 1.7.0.2

                        User : Ollyve ()
                        Update on 02/04/2010 by g3n-h@ckm@n ::::: 18.00
                        Start at: 22:09:46 | 06/04/2010

                        Intel(R) Pentium(R) 4 CPU 2.80GHz
                        Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                        Internet Explorer 7.0.5730.11
                        Windows Firewall Status : Disabled
                        AV : AVG Anti-Virus Free 9.0 [ Enabled | Updated ]
                        FW : ZoneAlarm Firewall[ (!) Disabled ]7.0.483.000

                        A:\ -> Lecteur de disquettes 3 ½ pouces
                        C:\ -> Disque fixe local | 37,11 Go (6,67 Go free) [Disque local] | NTFS
                        D:\ -> Disque CD-ROM
                        E:\ -> Disque CD-ROM
                        F:\ -> Disque fixe local | 77,39 Go (62,98 Go free) [Disque local] | NTFS
                        G:\ -> Disque amovible
                        H:\ -> Disque amovible
                        I:\ -> Disque amovible
                        J:\ -> Disque amovible
                        L:\ -> Disque amovible | 1,92 Go (1,26 Go free) | FAT

                        Boot: Normal

                        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\csrss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\AVG\AVG9\avgchsvx.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        C:\Program Files\Bonjour\mDNSResponder.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Java\jre6\bin\jqs.exe
                        C:\WINDOWS\System32\nvsvc32.exe
                        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                        C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\System32\alg.exe
                        C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                        C:\WINDOWS\System32\wbem\wmiapsrv.exe
                        C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
                        C:\WINDOWS\system32\wbem\wmiprvse.exe
                        C:\WINDOWS\vphc700.exe
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\Program Files\AVG\AVG9\avgwdsvc.exe
                        C:\Program Files\AVG\AVG9\avgnsx.exe
                        C:\Program Files\AVG\AVG9\avgrsx.exe
                        C:\Program Files\AVG\AVG9\avgcsrvx.exe
                        C:\Program Files\List_Kill'em\List_Kill'em.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Windows Live\Toolbar\wltuser.exe
                        C:\WINDOWS\system32\cmd.exe
                        C:\WINDOWS\system32\wbem\wmiprvse.exe
                        C:\Program Files\List_Kill'em\pv.exe

                        ======================
                        Keys "Run"
                        ======================

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
                        BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} REG_SZ "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        NvCplDaemon REG_SZ RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                        nwiz REG_SZ nwiz.exe /install
                        SoundMAXPnP REG_SZ C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                        SoundMAX REG_SZ "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
                        phc710 REG_SZ C:\WINDOWS\vphc700.exe
                        ZoneAlarm Client REG_SZ "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                        YeppStudioAgent REG_SZ C:\Program Files\Samsung\SamsungMediaStudio4.1\SamsungMediaStudioAgent.exe
                        Sony Ericsson PC Suite REG_SZ "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                        PCLEPCI REG_SZ C:\PROGRA~1\Pinnacle\PPE\ppe.exe
                        NeroFilterCheck REG_SZ C:\WINDOWS\system32\NeroCheck.exe
                        SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
                        AVG9_TRAY REG_SZ C:\PROGRA~1\AVG\AVG9\avgtray.exe
                        QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        iTunesHelper REG_SZ "C:\Program Files\iTunes\iTunesHelper.exe"

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                        =====================
                        Other Keys
                        =====================
                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                        dontdisplaylastusername REG_DWORD 0 (0x0)
                        legalnoticecaption REG_SZ
                        legalnoticetext REG_SZ
                        shutdownwithoutlogon REG_DWORD 1 (0x1)
                        undockwithoutlogon REG_DWORD 1 (0x1)

                        ===============
                        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                        NoDriveTypeAutoRun REG_DWORD 255 (0xff)

                        ===============
                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                        NoDriveTypeAutoRun REG_DWORD 0 (0x0)
                        HonorAutoRunSetting REG_DWORD 1 (0x1)
                        NoCDBurning REG_DWORD 0 (0x0)

                        ===============
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                        AppInit_DLLS REG_SZ

                        ===============

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                        AutoRestartShell REG_DWORD 1 (0x1)
                        DefaultDomainName REG_SZ -TTLL6V
                        DefaultUserName REG_SZ Ollyve
                        LegalNoticeCaption REG_SZ
                        LegalNoticeText REG_SZ
                        PowerdownAfterShutdown REG_SZ 0
                        ReportBootOk REG_SZ 1
                        Shell REG_SZ Explorer.exe
                        ShutdownWithoutLogon REG_SZ 0
                        System REG_SZ
                        Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
                        VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                        SfcQuota REG_DWORD -1 (0xffffffff)
                        allocatecdroms REG_SZ 0
                        allocatedasd REG_SZ 0
                        allocatefloppies REG_SZ 0
                        cachedlogonscount REG_SZ 10
                        forceunlocklogon REG_DWORD 0 (0x0)
                        passwordexpirywarning REG_DWORD 14 (0xe)
                        scremoveoption REG_SZ 0
                        AllowMultipleTSSessions REG_DWORD 1 (0x1)
                        UIHost REG_EXPAND_SZ logonui.exe
                        LogonType REG_DWORD 1 (0x1)
                        Background REG_SZ 0 0 0
                        DebugServerCommand REG_SZ no
                        SFCDisable REG_DWORD 0 (0x0)
                        WinStationsDisabled REG_SZ 0
                        HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
                        ShowLogonOptions REG_DWORD 0 (0x0)
                        AltDefaultUserName REG_SZ Ollyve
                        AltDefaultDomainName REG_SZ Olliv-TTLL6V
                        ChangePasswordUseKerberos REG_DWORD 1 (0x1)

                        ===============

                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

                        ===============

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                        {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

                        ===============
                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                        %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                        %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
                        C:\Program Files\Electronic Arts\La Bataille pour la Terre du Milieu II\game.dat REG_SZ C:\Program Files\Electronic Arts\La Bataille pour la Terre du Milieu II\game.dat:*:Enabled:La Bataille pour la Terre du Milieu (TM) II
                        C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
                        C:\Program Files\AVG\AVG8\avgupd.exe REG_SZ C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe
                        C:\Program Files\AVG\AVG8\avgnsx.exe REG_SZ C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                        C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
                        C:\Program Files\AVG\AVG9\avgupd.exe REG_SZ C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe
                        C:\Program Files\AVG\AVG9\avgnsx.exe REG_SZ C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe
                        C:\Program Files\Bonjour\mDNSResponder.exe REG_SZ C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
                        C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes

                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                        %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                        %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                        C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare

                        ===============
                        ActivX controls
                        ===============
                        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{0CCA191D-13A6-4E29-B746-314DEE697D83}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{166B1BCA-3F9C-11CF-8075-444553540000}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{233C1507-6A77-46A4-9443-F871F945D258}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D6F45B3-9043-443D-A792-115447494D24}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{B8BE5E93-A60C-4D26-A2DC-220313175592}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D27CDB6E-AE6D-11CF-96B8-444553540000}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}]

                        ===============
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\WriteRegStr]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{057997dd-71e4-43cc-b161-3f8180691a9e}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{233C1507-6A77-46A4-9443-F871F945D258}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{689e5762-8d75-4346-90cf-bc1902c32d63}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{abcdf74f-9a64-4e6e-b8eb-6e5a41de6550}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{F5776D81-AE53-4935-8E84-B0B283D8BCEF}]

                        ==============
                        BHO :
                        ======
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

                        ===
                        DNS
                        ===

                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{50E80319-F3F4-4D56-AE8E-EAE1E0905D91}: DhcpNameServer=212.27.40.241 212.27.40.240
                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{50E80319-F3F4-4D56-AE8E-EAE1E0905D91}: DhcpNameServer=212.27.40.241 212.27.40.240
                        HKLM\SYSTEM\CS2\Services\Tcpip\..\{50E80319-F3F4-4D56-AE8E-EAE1E0905D91}: DhcpNameServer=212.27.40.241 212.27.40.240
                        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240
                        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240
                        HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240

                        ================
                        Internet Explorer :
                        ================
                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                        Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                        Start Page REG_SZ https://www.msn.com/fr-fr

                        ========
                        Services
                        ========
                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                        Ndisuio : 0x3 ( OK = 3 )
                        EapHost : 0x2 ( OK = 2 )
                        SharedAccess : 0x2 ( OK = 2 )
                        wuauserv : 0x2 ( OK = 2 )

                        =========
                        Atapi.sys
                        =========

                        %%%% HASHDEEP-1.0
                        %%%% size,md5,sha256,filename
                        ## Invoked from: C:\Program Files\List_Kill'em
                        ## C:\> hashdeep.exe C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
                        ##
                        95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
                        %%%% HASHDEEP-1.0
                        %%%% size,md5,sha256,filename
                        ## Invoked from: C:\Program Files\List_Kill'em
                        ## C:\> hashdeep.exe C:\WINDOWS\ServicePackFiles\i386\atapi.sys
                        ##
                        96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\ServicePackFiles\i386\atapi.sys
                        %%%% HASHDEEP-1.0
                        %%%% size,md5,sha256,filename
                        ## Invoked from: C:\Program Files\List_Kill'em
                        ## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
                        ##
                        96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\system32\drivers\atapi.sys
                        %%%% HASHDEEP-1.0
                        %%%% size,md5,sha256,filename
                        ## Invoked from: C:\Program Files\List_Kill'em
                        ## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
                        ##
                        86912,95b858761a00e1d4f81f79a0da019aca,5e41dae055bcb8ee8ad23d3c77d69df09c6b1e301c889aec6f02193d7dec352b,C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys

                        Référence :
                        ==========

                        Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
                        Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
                        Win XP_32b : a64013e98426e1877cb653685c5c0009
                        Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                        Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                        Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                        Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                        Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                        Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                        Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                        Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
                        Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e

                        =======
                        Drive :
                        =======

                        D'fragmenteur de disque Windows
                        Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

                        Rapport d'analyse
                        37,11 Go total, 6,67 Go libre (17%), 34% fragment' (fragmentation du fichier 56%)

                        Vous devriez d'fragmenter ce volume.

                        ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                        Present !! : C:\WINDOWS\002426_.tmp
                        Present !! : C:\WINDOWS\005563_.tmp
                        Present !! : C:\WINDOWS\SET3.tmp
                        Present !! : C:\WINDOWS\SET7.tmp
                        Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
                        Present !! : C:\WINDOWS\System32\drivers\Sonyhcp.dll"
                        Present !! : C:\WINDOWS\System32\MSINET.oca
                        Present !! : C:\Documents and Settings\Ollyve\Application Data\GDIPFONTCACHEV1.DAT
                        Present !! : C:\Documents and Settings\Ollyve\Application Data\GDIPFONTCACHEV1.DAT
                        Present !! : C:\Documents and Settings\Ollyve\err.log
                        Present !! : C:\Documents and Settings\Ollyve\LOCAL Settings\Temp\jre-6u19-windows-i586-iftw-rv.exe

                        ¤¤¤¤¤¤¤¤¤¤ Keys :

                        Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                        Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools
                        Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                        Present !! : HKLM\SYSTEM\ControlSet001\Enum\Root\Legacy_NDISRD
                        Present !! : HKLM\SYSTEM\ControlSet002\Enum\Root\Legacy_NDISRD
                        Present !! : HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_NDISRD

                        ============

                        catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                        Rootkit scan 2010-04-06 22:25:56
                        Windows 5.1.2600 Service Pack 3 FAT NTAPI

                        scanning hidden processes ...

                        scanning hidden services ...

                        scanning hidden autostart entries ...

                        scanning hidden files ...

                        scan completed successfully
                        hidden processes: 0
                        hidden services: 0
                        hidden files: 0

                        Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                        device: opened successfully
                        user: MBR read successfully
                        called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
                        kernel: MBR read successfully
                        user & kernel MBR OK

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                        FirewallDisableNotify REG_DWORD 0 (0x0)
                        UpdatesDisableNotify REG_DWORD 0 (0x0)
                        AntiVirusOverride REG_DWORD 1 (0x1)
                        FirewallOverride REG_DWORD 1 (0x1)

                        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                        End of scan : 22:25:58,75
                        1. Kill'em by g3n-h@ckm@n 1.7.0.2

                          User : ollyve ()
                          Update on 02/04/2010 by g3n-h@ckm@n ::::: 18.00
                          Start at: 22:51:31 | 06/04/2010

                          Intel(R) Pentium(R) 4 CPU 2.80GHz
                          Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                          Internet Explorer 7.0.5730.11
                          Windows Firewall Status : Enabled
                          AV : AVG Anti-Virus Free 9.0 [ Enabled | Updated ]
                          FW : ZoneAlarm Firewall[ Enabled ]7.0.483.000

                          A:\ -> Lecteur de disquettes 3 ½ pouces
                          C:\ -> Disque fixe local | 37,11 Go (6,66 Go free) [Disque local] | NTFS
                          D:\ -> Disque CD-ROM
                          E:\ -> Disque CD-ROM
                          F:\ -> Disque fixe local | 77,39 Go (62,98 Go free) [Disque local] | NTFS
                          G:\ -> Disque amovible
                          H:\ -> Disque amovible
                          I:\ -> Disque amovible
                          J:\ -> Disque amovible
                          L:\ -> Disque amovible | 1,92 Go (1,26 Go free) | FAT

                          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                          C:\Program Files\AVG\AVG9\avgchsvx.exe
                          C:\Program Files\AVG\AVG9\avgrsx.exe
                          C:\Program Files\AVG\AVG9\avgcsrvx.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\cmd.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          C:\Program Files\AVG\AVG9\avgwdsvc.exe
                          C:\Program Files\Bonjour\mDNSResponder.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Java\jre6\bin\jqs.exe
                          C:\WINDOWS\System32\nvsvc32.exe
                          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                          C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\wuauclt.exe
                          C:\Program Files\AVG\AVG9\avgnsx.exe
                          C:\WINDOWS\system32\wbem\wmiprvse.exe
                          C:\WINDOWS\System32\alg.exe
                          C:\Program Files\List_Kill'em\ERUNT.EXE
                          C:\Program Files\List_Kill'em\pv.exe
                          C:\WINDOWS\System32\wbem\wmiapsrv.exe
                          C:\WINDOWS\system32\wbem\wmiprvse.exe

                          Detections :
                          ==========

                          ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                          Quarantined & Deleted !! : C:\WINDOWS\002426_.tmp
                          Quarantined & Deleted !! : C:\WINDOWS\005563_.tmp
                          Quarantined & Deleted !! : C:\WINDOWS\SET3.tmp
                          Quarantined & Deleted !! : C:\WINDOWS\SET7.tmp

                          Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
                          Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\Sonyhcp.dll
                          Quarantined & Deleted !! : C:\WINDOWS\System32\MSINET.oca
                          Quarantined & Deleted !! : C:\Documents and Settings\ollyve\Application Data\GDIPFONTCACHEV1.DAT
                          Quarantined & Deleted !! : C:\Documents and Settings\ollyve\err.log
                          Quarantined & Deleted !! : C:\Documents and Settings\ollyve\LOCAL Settings\Temp\jre-6u19-windows-i586-iftw-rv.exe
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc10.txt
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc11.txt
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc12.txt
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc13.txt
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc14.txt
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc15.txt
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc16.txt
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc17.txt
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc18.m4a
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc19.m4a
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc20.m4a
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc21.mp3
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc22.dcf
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc23.dcf
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc24.dcf
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc25.dcf
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc26.dcf
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc27.dcf
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc28.dcf
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc29.dcf
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc30.exe
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc31.txt
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc32.txt
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc33.zip
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc4.exe
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc6.txt
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc7.txt
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc8.txt
                          Deleted !! : C:\RECYCLER\S-1-5-21-1177238915-884357618-682003330-1004\Dc9.txt

                          ==============
                          host file OK !
                          ==============

                          ========
                          Registry
                          ========

                          Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                          Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools
                          Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                          ========
                          Services
                          =========

                          Ndisuio : Start = 3
                          EapHost : Start = 2
                          Ip6Fw : Start = 2
                          SharedAccess : Start = 2
                          wuauserv : Start = 2
                          wscsvc : Start = 2

                          ============
                          Disk Cleaned
                          ============

                          =================
                          anti-ver blaster : OK !!
                          =================

                          ================
                          Prefetch cleaned
                          ================

                          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                          1. Contributeur sécurité
                            bonjour, ok comment va le pc peux tu poster un hijackthis pour finaliser , merci

                            télécharge Hijackthis : http://www.trendsecure.com/portal/fr/_download/HJTInstall.exe

                            .enregistres le sur le bureau
                            .Tu fermes tout les programmes ouverts y compris le navigateur. sauf ton anti-virus et pare-feux
                            .installes le , il va s'installer par défaut dans C:\Program Files\Trend Micro\HijackThis
                            .Cliques sur "Do a system scan and save the logfile"
                            .Cela va t'ouvrir un bloc note à la fin du scan.
                            .Copie son contenu et poste le dans ton prochain message. sinon le rapport est dans C:\Program Files\Trend Micro\HijackThis\ hijackthis "document texte"

                            si besion d'aide pour l'installation : https://www.androidworld.fr/

                            des expliquations en images pour l'utiliser : http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
                            1. Ps de pb avec le PC sinon le tps d'accés internet et aléatoire
                              voici le hijackthis

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 18:50:33, on 07/04/2010
                              Platform: Windows XP SP3 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v7.00 (7.00.6000.17023)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                              C:\Program Files\AVG\AVG9\avgchsvx.exe
                              C:\Program Files\AVG\AVG9\avgrsx.exe
                              C:\Program Files\AVG\AVG9\avgcsrvx.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              C:\Program Files\AVG\AVG9\avgwdsvc.exe
                              C:\Program Files\Bonjour\mDNSResponder.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Java\jre6\bin\jqs.exe
                              C:\WINDOWS\System32\nvsvc32.exe
                              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                              C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\AVG\AVG9\avgnsx.exe
                              C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                              C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
                              C:\WINDOWS\vphc700.exe
                              C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                              C:\WINDOWS\System32\wbem\wmiapsrv.exe
                              C:\Program Files\Java\jre6\bin\jusched.exe
                              C:\PROGRA~1\AVG\AVG9\avgtray.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
                              C:\Program Files\Philips\Philips SPC710NC Webcam\TrayMin710.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              R3 - URLSearchHook: (no name) - CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
                              O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                              O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
                              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                              O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                              O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
                              O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                              O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                              O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
                              O4 - HKLM\..\Run: [phc710] C:\WINDOWS\vphc700.exe
                              O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                              O4 - HKLM\..\Run: [YeppStudioAgent] C:\Program Files\Samsung\SamsungMediaStudio4.1\SamsungMediaStudioAgent.exe
                              O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                              O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\Pinnacle\PPE\ppe.exe
                              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                              O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
                              O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1150600.exe -Update -1150600 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; OfficeLiveConnector.1.3; OfficeLivePatch.0.0; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.jeux.fr/jeu/table-tennis.html"
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                              O4 - Global Startup: TrayMin710.exe.lnk = ?
                              O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                              O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
                              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
                              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                              O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                              O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game03.zylom.com/activex/zylomgamesplayer.cab
                              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                              O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                              O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
                              O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
                              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                              O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                              O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                              1. ce soir je peux pas continuer merci qd meme et peut etre à demain
                                1. Contributeur sécurité
                                  ok tu installes IE8 et puis deldomains, et si tu pouvais poster un nouveau hijackthis pour voir cela !!!
                                  • 1
                                  • 2