Internet très lent.

Bonjour,
Il y a quelques temps, j'ai eu une baisse de ma connection, je faisais du 200 ko/s

en down et du 85 ko/s en up et maintenant, je fais du 80 et 10 O_O

On m'as dit de taper netstat dans le cmd, et j'ai beaucoups de résultats du genre : "ww:51941" et il y en a enormément. Je fais actuellement un scan avec avast et malwarebytes.
Je vous poste mon rapport hijhackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:00:16, on 08/10/2011
Platform: Unknown Windows (WinNT 6.01.3505 SP1)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Thomas\Downloads\HiJackThis.exe
C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files (x86)\OrangeHSS\SearchURLHook\SearchPageURL.dll
R3 - URLSearchHook: (no name) - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Updater For VMN Toolbar - {d5b8015d-68af-4b2c-9412-e349d82ab4a2} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: VMN Toolbar - {f379a94e-3c5d-4bad-b32c-0e3af1cc3617} - (no file)
O3 - Toolbar: (no name) - {f379a94e-3c5d-4bad-b32c-0e3af1cc3617} - (no file)
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [HWSetup] "C:\Program Files\TOSHIBA\Utilities\HWSetup.exe" hwSetUP
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files (x86)\OrangeHSS\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'Système')
O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'Default user')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
O4 - Global Startup: Windows Defender.lnk = C:\plugins\Server.jar
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O13 - Gopher Prefix:
O15 - Trusted Zone: http://*.mappy.com
O15 - Trusted Zone: http://*.orange.fr
O15 - Trusted Zone: http://rw.search.ke.voila.fr
O15 - Trusted Zone: http://orange.weborama.fr
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Gadget Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DeezRip service (DeezRipSvc) - Unknown owner - C:\Program Files (x86)\DeezRip\DeezRipSvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~2\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Service Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12375 bytes

Merci d'avance

31 réponses

Résumé de la discussion

Baisse de la connexion observée: la vitesse passe d'environ 200 ko/s en téléchargement et 85 ko/s en upload à environ 80 et 10 ko/s, avec de nombreux résultats netstat tels que ww:51941. Pour diagnostiquer, l'utilisateur effectue des scans Avast et Malwarebytes et partage un rapport HijackThis détaillant des processus légitimes et des éléments potentiellement indésirables, notamment des BHO et des services suspects. Des indices indiquent des entrées obsolètes ou douteuses dans les démarrages et services, avec des entrées 'file missing' et des propriétaires inconnus, nécessitant une vérification approfondie et un nettoyage ciblé. D'autres éléments utiles incluent la vérification des composants ConfigFree et la comparaison des résultats après désactivation ou suppression d'éléments suspects pour confirmer l'origine de la lenteur.

Bobot (l’IA à votre service)
  1. Bonjour anthony30001 ou anthony1530.

    Merci de ne pas jouer sur plusieurs pseudos, surtout que,
    si c'est pour poster n'importe quoi, il n'y a là aucun intérêt !

    Merci !
    1. ok suprime l'autre
    2. Je supprime rien du tout, je ne suis pas à ton service,
      et toi seul peut le faire !

      On dirait que tu navigues à l'aveugle, le forum VS de CCM
      n'est pas là pour s'entraîner sur le pc des autres, si tu n'as
      pas les compétences et les connaissances pour le faire,
      alors laisse faire les gens qui eux savent se qu'ils font.

      Merci !
  2. Contributeur sécurité
    Bonjour,

    Je prends la suite.

    Infections PUP

    Des logiciels additionnels sont proposés (barre d'outils, adwares) via l'installation de logiciel par éditeurs.
    L'éditeur touche de l'argent à chaque installation réussie de ces additionnels tiers (un genre de sponsoring).
    Seulement certains éditeurs, abusent, pour gagner plus d'argent, ils redistribuent des logiciels libres développés par des bénévoles en y ajoutant ces logiciels additionnels.
    Des pubs trompeuses peuvent aussi être utilisés pour faire installer ces logiciels.

    Outre le fait que les procédés sont discutables, l'accumulation de ces programmes additionnels non essentiels councourent à ralentir condésirablement l'ordinateur (peux aussi faire planter les navigateurs WEB).
    Certains font aussi du tracking anonymes (récupérations des thématiques de sites visités).

    Tu as la même chose avec les barres d'outils :
    Les barres d'outils sont là pour t'affilier à un service (moteur de recherche de Yahoo! ou Google), ça rajoute des fonctionnalités mais en général les navigateurs les ont par défaut.
    De plus, elles enregistrent les sites que tu visites pour les transmettre (tracking) à faire de la publicité ciblée, c'est pas super niveau protection de la vie privée.
    Plusieurs toolbars ralentissent le PC et peuvent faire planter les navigateurs WEB.
    Au final, il est pas conseillé d'en utiliser.

    Lire :
    Les PUPs/LPIs : https://www.malekal.com/adwares-pup-protection/

    Pour les barres d'outils : Les toolbars c'est pas obligatoire!

    ~~

    Télécharge AdwCleaner ( d'Xplode ) sur ton bureau.
    Lance le, clique sur [Recherche] puis patiente le temps du scan.
    Une fois le scan fini, un rapport s'ouvrira. Poste moi son contenu dans ta prochaine réponse.

    Note : Le rapport est également sauvegardé sous C:\AdwCleaner[R1].txt
    1. Scan en cours.

      PS : Aujourd'hui mon PC est anormalement lent a demarrer...

      Edit :

      # AdwCleaner v1.310 - Rapport créé le 09/10/2011 à 16:51:25
      # Mis à jour le 07/10/11 à 19h par Xplode
      # Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
      # Nom d'utilisateur : Thomas - ORDI (Administrateur)
      # Exécuté depuis : C:\Users\Thomas\Downloads\adwcleaner.exe
      # Option [Recherche]

      ***** [Processus] *****

      ***** [Services] *****

      ***** [Fichiers / Dossiers] *****

      Dossier Présent : C:\Users\Thomas\AppData\LocalLow\Conduit
      Dossier Présent : C:\Users\Thomas\AppData\LocalLow\ShoppingReport2
      Dossier Présent : C:\Users\Thomas\AppData\LocalLow\PriceGong

      ***** [Registre] *****

      Clé Présente : HKCU\Software\Conduit
      Clé Présente : HKCU\Software\Headlight
      Clé Présente : HKCU\Software\AppDataLow\Software\PriceGong
      Clé Présente : HKCU\Software\AppDataLow\Software\ShoppingReport2
      Clé Présente : HKLM\SOFTWARE\Classes\pdfforge.DllInfo
      Clé Présente : HKLM\SOFTWARE\Classes\pdfforge.PDF.PDF
      Clé Présente : HKLM\SOFTWARE\Classes\pdfforge.PDF.PDFEncryptor
      Clé Présente : HKLM\SOFTWARE\Classes\pdfforge.PDF.PDFLine
      Clé Présente : HKLM\SOFTWARE\Classes\pdfforge.PDF.PDFText
      Clé Présente : HKLM\SOFTWARE\Classes\pdfforge.Tools
      Clé Présente : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
      Clé Présente : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
      Clé Présente : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
      Clé Présente : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
      Clé Présente : HKLM\SOFTWARE\Classes\Interface\{419EDA30-6DFF-432C-B534-E15D899ABEE4}
      Clé Présente : HKLM\SOFTWARE\Classes\Interface\{30B15818-E110-4527-9C05-46ACE5A3460D}
      Clé Présente : HKLM\SOFTWARE\Classes\Interface\{618aad04-921f-44c2-be38-c0818af69861}
      Clé Présente : HKLM\SOFTWARE\Classes\Interface\{b5d2ed96-62f9-4c2c-956d-e425b1f67337}
      Clé Présente : HKLM\SOFTWARE\Classes\Interface\{d3a412e8-1e4b-47d2-9b12-f88291f5afbb}
      Clé Présente : HKLM\SOFTWARE\Classes\Interface\{B5D2ED96-62F9-4C2C-956D-E425B1F67337}
      Clé Présente : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
      Clé Présente : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
      Clé Présente : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
      Clé Présente : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
      Clé Présente : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
      Clé Présente : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
      Clé Présente : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
      Clé Présente : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
      Clé Présente : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
      Clé Présente : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
      Clé Présente : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}

      ***** [Navigateurs] *****

      -\\ Internet Explorer v9.0.8112.16421

      [OK] Le registre ne contient aucune entrée illégitime.

      -\\ Google Chrome v14.0.835.202

      Fichier : C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Preferences

      [OK] Le fichier ne contient aucune entrée illégitime.

      *************************

      AdwCleaner[R1].txt - [3432 octets] - [09/10/2011 16:50:50]
      AdwCleaner[R2].txt - [3425 octets] - [09/10/2011 16:51:25]

      ########## EOF - C:\AdwCleaner[R2].txt - [3553 octets] ##########
      1. Contributeur sécurité
        Relance AdwCleaner, clique cette fois sur [Suppression] puis patiente le temps du scan.
        Une fois le scan fini, un rapport s'ouvrira. Poste moi son contenu dans ta prochaine réponse.

        Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt

        ~~

        ▶ Télécharge AD-Remover sur ton Bureau : (TeamXScript)

        http://www.teamxscript.org/adremoverTelechargement.html ( Lien officiel )
        OU
        https://www.androidworld.fr/ ( Miroir )

        /!\ Ferme toutes applications en cours /!\

        ▶ Double-clique sur l'icône Ad-remover située sur ton Bureau.
        ▶ Sur la page, clique sur le bouton « Scanner »
        ▶ Confirme le lancement du scan
        ▶ Laisse travailler l'outil.
        ▶ Quand il a fini, un rapport s'ouvrira : ferme le.

        ♦ Pour me transmettre le rapport

        clique sur ce lien : http://www.cijoint.fr/

        ▶ Clique sur Parcourir et cherche le fichier C:\Ad-Report-SCAN[1].txt

        ▶ Clique sur Ouvrir.

        ▶ Clique sur "Cliquez ici pour déposer le fichier".

        Un lien de cette forme :

        http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

        est ajouté dans la page.

        ▶ Copie ce lien dans ta réponse.
        1. AdwCleaner :

          # AdwCleaner v1.310 - Rapport créé le 09/10/2011 à 17:02:24
          # Mis à jour le 07/10/11 à 19h par Xplode
          # Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
          # Nom d'utilisateur : Thomas - ORDI (Administrateur)
          # Exécuté depuis : C:\Users\Thomas\Downloads\adwcleaner.exe
          # Option [Suppression]

          ***** [Processus] *****

          ***** [Services] *****

          ***** [Fichiers / Dossiers] *****

          Dossier Supprimé : C:\Users\Thomas\AppData\LocalLow\Conduit
          Dossier Supprimé : C:\Users\Thomas\AppData\LocalLow\ShoppingReport2
          Dossier Supprimé : C:\Users\Thomas\AppData\LocalLow\PriceGong

          ***** [Registre] *****

          Clé Supprimée : HKCU\Software\Conduit
          Clé Supprimée : HKCU\Software\Headlight
          Clé Supprimée : HKCU\Software\AppDataLow\Software\PriceGong
          Clé Supprimée : HKCU\Software\AppDataLow\Software\ShoppingReport2
          Clé Supprimée : HKLM\SOFTWARE\Classes\pdfforge.DllInfo
          Clé Supprimée : HKLM\SOFTWARE\Classes\pdfforge.PDF.PDF
          Clé Supprimée : HKLM\SOFTWARE\Classes\pdfforge.PDF.PDFEncryptor
          Clé Supprimée : HKLM\SOFTWARE\Classes\pdfforge.PDF.PDFLine
          Clé Supprimée : HKLM\SOFTWARE\Classes\pdfforge.PDF.PDFText
          Clé Supprimée : HKLM\SOFTWARE\Classes\pdfforge.Tools
          Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
          Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
          Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
          Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
          Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{419EDA30-6DFF-432C-B534-E15D899ABEE4}
          Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{30B15818-E110-4527-9C05-46ACE5A3460D}
          Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{618aad04-921f-44c2-be38-c0818af69861}
          Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{b5d2ed96-62f9-4c2c-956d-e425b1f67337}
          Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{d3a412e8-1e4b-47d2-9b12-f88291f5afbb}
          Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
          Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
          Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
          Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
          Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
          Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
          Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
          Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
          Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
          Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
          Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}

          ***** [Navigateurs] *****

          -\\ Internet Explorer v9.0.8112.16421

          [OK] Le registre ne contient aucune entrée illégitime.

          -\\ Google Chrome v14.0.835.202

          Fichier : C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Preferences

          [OK] Le fichier ne contient aucune entrée illégitime.

          *************************

          AdwCleaner[R1].txt - [3432 octets] - [09/10/2011 16:50:50]
          AdwCleaner[R2].txt - [3492 octets] - [09/10/2011 16:51:25]
          AdwCleaner[R3].txt - [3552 octets] - [09/10/2011 16:53:07]
          AdwCleaner[S1].txt - [3491 octets] - [09/10/2011 17:02:24]

          *************************

          Dossier Temporaire : 29 dossier(s) et 84 fichier(s) supprimé(s)

          ########## EOF - C:\AdwCleaner[S1].txt - [3715 octets] ##########
          1. AD-Remover :

            ======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======

            Mis à jour par TeamXscript le 12/04/11
            Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
            Site web: http://www.teamxscript.org

            C:\Program Files (x86)\Ad-Remover\main.exe (SCAN [1]) -> Lancé à 17:03:35 le 09/10/2011, Mode normal

            Microsoft Windows 7 Édition Familiale Premium Service Pack 1 (X64)
            Thomas@ORDI (TOSHIBA Satellite L500)

            ============== RECHERCHE ==============

            Dossier trouvé: C:\Users\Thomas\AppData\LocalLow\Toolbar4

            Clé trouvée: HKLM\Software\Classes\TypeLib\{96F7FABC-5789-EFA4-B6ED-1272F4C1D27B}
            Clé trouvée: HKLM\Software\Conduit
            Clé trouvée: HKCU\Software\iMesh
            Clé trouvée: HKLM\Software\Messenger Plus!\OpenCandy
            Clé trouvée: HKLM\Software\Wow6432Node\Messenger Plus!\OpenCandy
            Clé trouvée: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
            Clé trouvée: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}
            Clé trouvée: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}
            Clé trouvée: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}

            ============== SCAN ADDITIONNEL ==============

            **** Google Chrome Version [14.0.835.202] ****

            Extension - jfmjfhklogoienhpfnppmbcbjfjnkonk (x)

            -- C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default --
            Preferences - default_search_provider: "Google" (Activé: true) (?)
            Preferences - homepage: hxxp://google.fr/
            Preferences - homepage_is_newtabpage: false
            Plugin - Remoting Viewer (Activé: true) (internal-remoting-viewer) (x)
            Plugin - Native Client (Activé: true) (C:\Users\Thomas\AppData\Local\Google\Chrome\Application\14.0.835.202\ppGoogleNaClPluginChrome.dll)
            Plugin - "Java" (Activé: true)
            Plugin - "Silverlight" (Activé: true)
            Plugin - "Remoting Viewer" (Activé: true)
            Plugin - "Native Client" (Activé: true)
            Plugin - "Picasa" (Activé: true)

            ========================================

            **** Internet Explorer Version [9.0.8112.16421] ****

            HKCU_Main|Default_Page_URL - hxxp://www.google.com/ig/redirectdomain?brand=TSEH&bmod=TSEH
            HKCU_Main|Start Page - hxxp://www.google.com/ig/redirectdomain?brand=TSEH&bmod=TSEH
            HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=69157
            HKLM_Main|Default_Search_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
            HKLM_Main|Start Page - hxxp://www.msn.com/
            HKCU_URLSearchHooks|{08C06D61-F1F3-4799-86F8-BE1A89362C85} - "Search Class" (C:\Program Files (x86)\OrangeHSS\SearchURLHook\SearchPageURL.dll)
            HKCU_URLSearchHooks|{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} (x)
            HKCU_SearchScopes\{117086E1-E5EB-4E79-84E5-ABF65658D2AE} - "eBay" (hxxp://rover.ebay.com/rover/1/709-44555-9400-8/4?satitle={searchTerms})
            HKCU_SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} - "Search The Web" (hxxp://www.mystart.com/search_w.php?fr=chr-vmn&type=vmn3_2msch&q={searchTerms})
            HKCU_SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59} - "Web Search" (hxxp://search.imesh.com/web?src=ieb&q={searchTerms})
            HKLM_SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59} - "Web Search" (hxxp://search.imesh.com/web?src=ieb&q={searchTerms})
            HKLM_SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} - "PHPNukeEN Customized Web Search" (hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT...)
            HKLM_SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} - "SweetIM Search" (hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms})
            HKCU_Toolbar\WebBrowser|{EEE6C35B-6118-11DC-9C72-001320C79847} (x)
            HKCU_Toolbar\WebBrowser|{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E} (x)
            HKLM_Toolbar|{f379a94e-3c5d-4bad-b32c-0e3af1cc3617} (x)
            HKLM_Toolbar|{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} (C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll)
            HKCU_ElevationPolicy\{1902485B-CE75-42C1-BA2D-57E660793D9A} - C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (x)
            HKCU_ElevationPolicy\{D4F53593-0CF9-49A4-B58B-358982D4FE4E} - C:\Program Files (x86)\WinRAR\WinRAR.exe (?)
            HKCU_ElevationPolicy\{E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4} - C:\Program Files (x86)\Internet Download Manager\IDMan.exe (x)
            HKLM_ElevationPolicy\7d660634-e4e8-45f0-a88a-fc8de9235ffe - C:\Program Files (x86)\PHPNukeEN\PHPNukeENToolbarHelper.exe (x)
            HKLM_ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a} - C:\Windows\SysWOW64\wpcer.exe (x)
            HKLM_ElevationPolicy\{0a402d70-1f10-4ae7-bec9-286a98240695} - C:\Windows\SysWOW64\winfxdocobj.exe (x)
            HKLM_ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} - C:\Program Files (x86)\HyperCam Toolbar\TbHelper2.exe (x)
            HKLM_ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999} - C:\Program Files (x86)\Internet Explorer\iedw.exe (x)
            HKLM_ElevationPolicy\{B43A0C1E-B63F-4691-B68F-CD807A45DA01} - C:\Windows\system32\TSWbPrxy.exe (x)
            HKLM_ElevationPolicy\{E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4} - C:\Program Files (x86)\Internet Download Manager\IDMan.exe (x)
            BHO\{5C255C8A-E604-49b4-9D64-90988571CECB} (?)
            BHO\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - "avast! WebRep" (C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll)
            BHO\{d5b8015d-68af-4b2c-9412-e349d82ab4a2} (?)
            BHO\{f379a94e-3c5d-4bad-b32c-0e3af1cc3617} (?)

            ========================================

            C:\Program Files (x86)\Ad-Remover\Quarantine: 0 Fichier(s)
            C:\Program Files (x86)\Ad-Remover\Backup: 0 Fichier(s)

            C:\Ad-Report-SCAN[1].txt - 09/10/2011 17:03:40 (5446 Octet(s))

            Fin à: 17:05:20, 09/10/2011

            ============== E.O.F ==============
            1. Contributeur sécurité
              ▶ Relance AD-Remover, clique sur [ Nettoyer ]
              ▶ Laisse le pc redémarrer.
              ▶ Une fois revenu sur le bureau, le rapport devrait s'ouvrir : ferme-le

              ♦ Pour me transmettre le rapport

              clique sur ce lien : http://www.cijoint.fr/

              ▶ Clique sur Parcourir et cherche le fichier C:\Ad-Report-CLEAN[1].txt

              ▶ Clique sur Ouvrir.

              ▶ Clique sur "Cliquez ici pour déposer le fichier".

              Un lien de cette forme :

              http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

              est ajouté dans la page.

              ▶ Copie ce lien dans ta réponse.

              ~~

              ▶ Télécharge MBAM et installe le selon l'emplacement par défaut
              https://www.malwarebytes.com/mwb-download/
              ▶ Effectue la mise à jour et lance Malwarebytes' Anti-Malware

              ▶ ▶ Si tu n''arrive pas à le mettre à jour, télécharge ce fichier , ferme MBAM, et exécute le

              ▶ Clique dans l'onglet du haut "Recherche"
              ▶ Coche l'option "Exécuter un examen complet" puis sur le bouton "Rechercher"
              ▶ Choisis de scanner tous tes disques durs, puis clique sur 'Lancer l'examen"

              A la fin de l'analyse, si MBAM n'a rien trouvé :

              ▶ Clique sur OK, le rapport s'ouvre spontanément

              Si des menaces ont été détectées :

              ▶ Clique sur OK puis "Afficher les résultats"
              ▶ Choisis l'option "Supprimer la sélection"
              ▶ Si MBAM demande le redémarrage de Windows : Clique sur "Oui"
              ▶ Une fois le PC redémarré, le rapport se trouve dans l'onglet "Rapports/Logs"
              ▶ Sinon le rapport s'ouvre automatiquement après la suppression

              Quelque soit le résultat, copie/colle le rapport dans le prochain message
              1. Je redémarre le PC, mais j'ai deja fais un scan MBAM moi même ainsi qu'un scan avast!, et il n'ont rien trouvé
                1. Contributeur sécurité
                  Heu t'es sûr d'avoir lu ce que je demande? ^^
                  T'as bien fais le nettoyage avec ad-remover?

                  Pour mbam quand tu l'as fait il était à jour? Si non, à refaire.
                  1. Contributeur sécurité
                    ok ben quand il a fini poste son rapport puis on fera autre chose.
                    1. Contributeur sécurité
                      Parfait.

                      ▶ Télécharge ZHPDiag

                      ▶ Laisse toi guider lors de l''installation,coche "Ajouter une icône sur le bureau" et "Exécuter ZHPDiag"

                      ▶ Clique sur l''icône représentant une loupe (« Lancer le diagnostic »)

                      ▶ Une fois le scan aux 100%, ferme ZHPDiag. Héberge le rapport ZHPDiag.txt présent sur ton bureau :

                      Voici comment procéder

                      ▶ Rends toi sur pjjoint.malekal.com
                      ▶ Clique sur le bouton Parcourir
                      ▶ Sélectionne le fichier que tu veux heberger et clique sur Ouvrir
                      ▶ Clique sur le bouton Envoyer
                      ▶ Un message de confirmation s''affiche (L''upload a réussi ! - Le lien à transmettre à vos correspondant pour visualiser le fichier est : https://pjjoint.malekal.com/files.php?id=df5ea299241015 Copie le lien dans ta prochaine réponse.

                      A bientôt.
                      1. http://pjjoint.malekal.com/files.php?id=ZHPDiag_o7n14z8u14e13l14m9g7h7o9k127g13d8n5z5v10g15e15q13
                        1. Contributeur sécurité
                          Désinstalle Spybot il est inutile

                          ~~

                          /!\ Ne pas utiliser ce logiciel en dehors du cadre de cette désinfection : DANGEREUX /!\

                          ▶ /!\ IMPORTANT /!\

                          Désactive ton Antivirus, antispyware et Pare feu avant le scan avec Combofix :
                          Protections résidentes : https://forum.pcastuces.com/default.asp
                          et https://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/
                          ~~
                          Pare feu Windows XP : http://support.microsoft.com/kb/283673/fr
                          Pare feu Windows Vista/7 : https://support.microsoft.com/en-us/windows?ui=en-US&rs=en-001&ad=US
                          ~~
                          Windows Defender : https://support.microsoft.com/en-us/windows?ui=en-US&rs=en-001&ad=US
                          _______________________________________________________________

                          ▶ Fais un clic droit sur le lien ci dessous, choisi "Enregistrer la cible du lien sous", comme destination : ton Bureau, change son nom (ton_pseudo.exe par exemple) :

                          http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                          ▶ Double-clique sur ComboFix.exe
                          Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter

                          ▶ ▶ SI TU ES SOUS WINDOWS XP, SURTOUT INSTALLES LA CONSOLE DE RÉCUPÉRATION [Si tu travailles avec Vista ou seven ne tiens pas compte de cet avertissement]
                          ▶ ▶ Ne touche à rien (souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC

                          ▶ En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

                          ▶ Une fois le scan achevé, un rapport va s''afficher : Poste son contenu
                          ▶ ▶ /!\ Réactive la protection en temps réel de ton antivirus avant de te reconnecter à Internet. /!\

                          Notes:
                          -> Le rapport se trouve également là : C:\ComboFix.txt
                          -> tutoriel combofix
                          1. http://www.cijoint.fr/cjlink.php?file=cj201110/cijDa1KYCU.txt

                            EDIT : Spybot n'était pas installé.

                            Edit² : Je vais devoir y aller, je suivrais tes conseils mercredi après-midi
                            1. Contributeur sécurité
                              Ok.

                              ▶ ▶ DÉSACTIVE TES PROTECTIONS DURANT LA PROCÉDURE

                              ▶ ▶ SCRIPT PERSONNALISE A CET ORDINATEUR, NE PAS REPRODUIRE : DANGEREUX !!!!


                              ▶ Créé un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

                              KillAll::
                              
                              File::
                              c:\windows\system32\23D0.tmp      
                              c:\users\Thomas\AppData\Local\Temp\0034837.tmp 
                              c:\users\Thomas\AppData\Local\Temp\005A89D.tmp [
                              
                              Registry::
                              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]  
                              "msnmsgr"=-
                              "Steam"=-
                              "DAEMON Tools Lite"=-
                              
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 
                              "Adobe Reader Speed Launcher"=-
                              QuickTime Task"=-
                              
                              Driver::
                              X6va003
                              X6va005
                              
                              RegLock::
                              [HKEY_USERS\S-1-5-21-1625509770-3664408973-3642232316-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_f 3*N} ]
                               
                              [HKEY_USERS\S-1-5-21-1625509770-3664408973-3642232316-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_f 3*N} hQè þ"¥c]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
                               
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                              
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
                              
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
                              
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
                              
                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
                              
                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
                              
                              


                              ▶ Enregistre ce fichier sous le nom CFScript

                              ▶ Fait un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture :http://i261.photobucket.com/albums/ii49/Malekal_morte/CFScript-2.gif

                              ▶ Combofix se lance, laisse toi guider..

                              ▶ Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal!
                              Ne touche à rien tant que le scan n'est pas terminé.
                              ▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu, en précisant où en sont tes soucis

                              ▶ Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
                              1. ComboFix 11-10-09.01 - Thomas 10/10/2011 20:05:38.2.2 - x64
                                Microsoft Windows 7 Édition Familiale Premium 6.1.7601.1.1252.33.1036.18.3933.2526 [GMT 2:00]
                                Lancé depuis: c:\users\Thomas\Desktop\Thomas.exe
                                Commutateurs utilisés :: c:\users\Thomas\Desktop\CFScript.txt
                                AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
                                SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
                                SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                                .
                                FILE ::
                                "c:\users\Thomas\AppData\Local\Temp\0034837.tmp"
                                "c:\users\Thomas\AppData\Local\Temp\005A89D.tmp ["
                                "c:\windows\system32\23D0.tmp"
                                .
                                .
                                (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                .
                                c:\windows\system32\23D0.tmp
                                .
                                .
                                ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                .
                                -------\Legacy_X6VA003
                                -------\Legacy_X6VA005
                                -------\Service_X6va003
                                -------\Service_X6va005
                                -------\Service_MEMSWEEP2
                                .
                                .
                                ((((((((((((((((((((((((((((( Fichiers créés du 2011-09-10 au 2011-10-10 ))))))))))))))))))))))))))))))))))))
                                .
                                .
                                2011-10-10 18:20 . 2011-10-10 18:20 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C211A69C-33AD-427C-87F7-2FB3669FC1B4}\offreg.dll
                                2011-10-10 18:17 . 2011-10-10 18:17 -------- d-----w- c:\users\Marie Jo\AppData\Local\temp
                                2011-10-10 18:17 . 2011-10-10 18:17 -------- d-----w- c:\users\Default\AppData\Local\temp
                                2011-10-09 15:38 . 2011-10-09 16:48 -------- d-----w- C:\Thomas
                                2011-10-09 15:03 . 2011-10-09 15:03 -------- d-----w- c:\program files (x86)\Ad-Remover
                                2011-10-09 15:00 . 2011-09-13 00:26 9049936 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C211A69C-33AD-427C-87F7-2FB3669FC1B4}\mpengine.dll
                                2011-10-08 17:11 . 2011-10-08 17:11 -------- d-----w- c:\program files (x86)\Sophos
                                2011-10-08 16:34 . 2011-10-09 15:28 512 ----a-w- C:\PhysicalDisk0_MBR.bin
                                2011-10-08 16:31 . 2011-10-09 15:28 -------- d-----w- C:\ZHP
                                2011-10-08 16:30 . 2011-10-09 15:28 -------- d-----w- c:\program files (x86)\ZHPDiag
                                2011-10-08 16:20 . 2011-10-08 16:20 -------- d-----w- c:\program files (x86)\PMFplay H.264 Decoder
                                2011-10-08 11:29 . 2011-10-08 11:29 -------- d-----w- c:\users\Thomas\AppData\Local\Sony
                                2011-10-08 11:29 . 2011-10-08 11:29 -------- d-----w- c:\users\Thomas\Podcasts
                                2011-10-08 11:28 . 2011-10-08 11:28 -------- d-----w- c:\program files (x86)\Common Files\Sony Shared
                                2011-10-08 11:27 . 2011-10-08 11:28 -------- d-----w- c:\program files (x86)\Sony
                                2011-10-08 11:25 . 2011-10-08 11:29 -------- d-----w- c:\users\Thomas\AppData\Roaming\Sony
                                2011-10-08 11:25 . 2011-10-08 11:28 -------- d-----w- c:\program files (x86)\Sony Media Go Install
                                2011-10-08 07:03 . 2011-10-10 18:32 -------- d-----w- c:\users\Thomas\AppData\Local\LogMeIn Hamachi
                                2011-10-08 07:02 . 2011-10-08 07:02 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
                                2011-10-08 06:55 . 2011-10-08 06:55 -------- d-----w- c:\windows\system32\Macromed
                                2011-10-08 06:49 . 2011-10-08 06:49 -------- d-----w- c:\users\Marie Jo\AppData\Roaming\Malwarebytes
                                2011-09-27 17:51 . 2011-09-27 17:51 -------- d-----w- c:\program files (x86)\7-Zip
                                2011-09-15 20:28 . 2011-10-08 09:31 -------- d-----w- c:\users\Thomas\AppData\Roaming\.minecraft
                                .
                                .
                                .
                                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                2011-10-08 06:55 . 2011-09-10 16:54 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
                                2011-09-10 16:55 . 2011-09-10 16:55 270912 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
                                2011-09-06 20:45 . 2010-12-24 23:49 41184 ----a-w- c:\windows\avastSS.scr
                                2011-09-06 20:45 . 2010-12-24 23:49 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
                                2011-09-06 20:45 . 2011-01-15 16:39 254400 ----a-w- c:\windows\system32\aswBoot.exe
                                2011-09-06 20:38 . 2011-04-10 08:28 601944 ----a-w- c:\windows\system32\drivers\aswSnx.sys
                                2011-09-06 20:38 . 2010-12-24 23:49 301912 ----a-w- c:\windows\system32\drivers\aswSP.sys
                                2011-09-06 20:36 . 2010-12-24 23:49 58200 ----a-w- c:\windows\system32\drivers\aswTdi.sys
                                2011-09-06 20:36 . 2010-12-24 23:49 42328 ----a-w- c:\windows\system32\drivers\aswRdr.sys
                                2011-09-06 20:36 . 2010-12-24 23:49 65368 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
                                2011-09-06 20:36 . 2010-12-24 23:49 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
                                2011-08-31 15:00 . 2011-07-21 18:00 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
                                2011-08-24 08:11 . 2011-08-24 08:11 51776 ----a-w- c:\windows\system32\drivers\pssdk41.sys
                                2011-07-22 05:42 . 2011-08-13 01:01 2303488 ----a-w- c:\windows\system32\jscript9.dll
                                2011-07-22 05:36 . 2011-08-13 01:01 1389056 ----a-w- c:\windows\system32\wininet.dll
                                2011-07-22 05:32 . 2011-08-13 01:01 2382848 ----a-w- c:\windows\system32\mshtml.tlb
                                2011-07-22 02:54 . 2011-08-13 01:01 1797632 ----a-w- c:\windows\SysWow64\jscript9.dll
                                2011-07-22 02:48 . 2011-08-13 01:01 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
                                2011-07-22 02:44 . 2011-08-13 01:01 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
                                2011-07-16 05:41 . 2011-08-12 17:27 362496 ----a-w- c:\windows\system32\wow64win.dll
                                2011-07-16 05:41 . 2011-08-12 17:27 243200 ----a-w- c:\windows\system32\wow64.dll
                                2011-07-16 05:41 . 2011-08-12 17:27 13312 ----a-w- c:\windows\system32\wow64cpu.dll
                                2011-07-16 05:39 . 2011-08-12 17:27 16384 ----a-w- c:\windows\system32\ntvdm64.dll
                                2011-07-16 05:37 . 2011-08-12 17:27 421888 ----a-w- c:\windows\system32\KernelBase.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
                                2011-07-16 05:21 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
                                2011-07-16 04:29 . 2011-08-12 17:27 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
                                2011-07-16 04:26 . 2011-08-12 17:27 44032 ----a-w- c:\windows\apppatch\acwow64.dll
                                2011-07-16 04:25 . 2011-08-12 17:27 25600 ----a-w- c:\windows\SysWow64\setup16.exe
                                2011-07-16 04:24 . 2011-08-12 17:27 5120 ----a-w- c:\windows\SysWow64\wow32.dll
                                2011-07-16 04:24 . 2011-08-12 17:27 272384 ----a-w- c:\windows\SysWow64\KernelBase.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 5120 ---ha-w- c:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
                                2011-07-16 04:15 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
                                2011-07-16 02:21 . 2011-08-12 17:27 7680 ----a-w- c:\windows\SysWow64\instnm.exe
                                2011-07-16 02:21 . 2011-08-12 17:27 2048 ----a-w- c:\windows\SysWow64\user.exe
                                2011-07-16 02:17 . 2011-08-12 17:27 6144 ---ha-w- c:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
                                2011-07-16 02:17 . 2011-08-12 17:27 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
                                2011-07-16 02:17 . 2011-08-12 17:27 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
                                2011-07-16 02:17 . 2011-08-12 17:27 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
                                .
                                .
                                ((((((((((((((((((((((((((((( SnapShot@2011-10-09_16.29.26 )))))))))))))))))))))))))))))))))))))))))
                                .
                                + 2009-09-04 13:08 . 2011-10-10 18:01 78058 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
                                - 2009-07-14 05:10 . 2011-10-09 15:17 49344 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
                                + 2009-07-14 05:10 . 2011-10-10 18:01 49344 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
                                + 2009-12-26 17:45 . 2011-10-10 18:01 18012 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1625509770-3664408973-3642232316-1000_UserData.bin
                                - 2011-10-09 16:27 . 2011-10-09 16:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
                                + 2011-10-10 18:19 . 2011-10-10 18:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
                                - 2011-10-09 16:27 . 2011-10-09 16:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
                                + 2011-10-10 18:19 . 2011-10-10 18:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
                                - 2009-07-14 05:01 . 2011-10-09 16:27 383080 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
                                + 2009-07-14 05:01 . 2011-10-10 18:18 383080 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
                                + 2011-01-29 22:04 . 2011-10-10 18:18 11861576 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1625509770-3664408973-3642232316-1000-12288.dat
                                - 2011-01-29 22:04 . 2011-10-09 16:27 11861576 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1625509770-3664408973-3642232316-1000-12288.dat
                                .
                                ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                .
                                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                REGEDIT4
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
                                "SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2009-08-12 352256]
                                "KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2009-01-13 34088]
                                "HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2009-06-02 423936]
                                "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
                                "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
                                "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
                                "avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-09-06 3722416]
                                "ORAHSSSessionManager"="c:\program files (x86)\OrangeHSS\SessionManager\SessionManager.exe" [2007-12-12 107248]
                                "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
                                "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-08-15 1955208]
                                .
                                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                "TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe" [2009-08-12 6203296]
                                .
                                c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
                                Windows Defender.lnk - c:\plugins\Server.jar [2010-5-23 1875007]
                                .
                                c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                                TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
                                .
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                                "ConsentPromptBehaviorAdmin"= 0 (0x0)
                                "ConsentPromptBehaviorUser"= 3 (0x3)
                                "EnableLUA"= 0 (0x0)
                                "EnableUIADesktopToggle"= 0 (0x0)
                                "PromptOnSecureDesktop"= 0 (0x0)
                                "SoftwareSASGeneration"= 1 (0x1)
                                .
                                [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
                                "aux"=wdmaud.drv
                                .
                                R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
                                R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
                                R2 DeezRipSvc;DeezRip service;c:\program files (x86)\DeezRip\DeezRipSvc.exe [x]
                                R2 gupdate;Service Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-13 135664]
                                R3 dump_wmimmc;dump_wmimmc;c:\ijji\ENGLISH\u_sf\GameGuard\dump_wmimmc.sys [x]
                                R3 gupdatem;Service Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-13 135664]
                                R3 MobileAdapter;Mobile Adapter USB Modem and USB Serial;c:\windows\system32\DRIVERS\qscnusb.sys [x]
                                R3 PCAMp50a64;PCAMp50a64 NDIS Protocol Driver;c:\windows\system32\Drivers\PCAMp50a64.sys [x]
                                R3 PCASp50a64;PCASp50a64 NDIS Protocol Driver;c:\windows\system32\Drivers\PCASp50a64.sys [x]
                                R3 PsSdk41;PsSdk41;c:\windows\system32\Drivers\pssdk41.sys [x]
                                R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
                                R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
                                R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-08-17 51512]
                                R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-08-04 826224]
                                R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
                                R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
                                S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x]
                                S1 aswSnx;aswSnx; [x]
                                S1 aswSP;aswSP; [x]
                                S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
                                S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
                                S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
                                S2 aswFsBlk;aswFsBlk; [x]
                                S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
                                S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2009-08-10 248688]
                                S2 ConfigFree Gadget Service;ConfigFree Gadget Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe [2009-07-14 42368]
                                S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
                                S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-08-15 2329480]
                                S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
                                S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-08-30 2358656]
                                S2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2009-08-06 116104]
                                S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-08-27 251760]
                                S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
                                S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [x]
                                S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
                                S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
                                S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
                                S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]
                                S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-03 137560]
                                .
                                .
                                [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
                                Akamai REG_MULTI_SZ Akamai
                                .
                                Contenu du dossier 'Tâches planifiées'
                                .
                                2011-10-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                                - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-13 07:35]
                                .
                                2011-10-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                                - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-13 07:35]
                                .
                                2011-10-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1625509770-3664408973-3642232316-1000Core.job
                                - c:\users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-11 18:52]
                                .
                                2011-10-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1625509770-3664408973-3642232316-1000UA.job
                                - c:\users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-11 18:52]
                                .
                                .
                                --------- x86-64 -----------
                                .
                                .
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
                                @="{472083B0-C522-11CF-8763-00608CC02F24}"
                                [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
                                2011-09-06 20:45 134384 ----a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "TPwrMain"="c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE" [BU]
                                "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-03 709976]
                                "TosReelTimeMonitor"="c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe" [BU]
                                "TosNC"="c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe" [BU]
                                "Teco"="c:\program files (x86)\TOSHIBA\TECO\Teco.exe" [BU]
                                "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
                                "SmoothView"="c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe" [BU]
                                "SmartFaceVWatcher"="c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [BU]
                                "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-28 7982112]
                                "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-02 365592]
                                "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-02 165912]
                                "HSON"="c:\program files (x86)\TOSHIBA\TBS\HSON.exe" [BU]
                                "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-02 387608]
                                "00TCrdMain"="c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe" [BU]
                                "TosWaitSrv"="c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe" [BU]
                                "combofix"="c:\thomas6868t\CF18417.3XE" [2010-11-20 345088]
                                .
                                ------- Examen supplémentaire -------
                                .
                                uLocal Page = c:\windows\system32\blank.htm
                                mLocal Page = c:\windows\SysWOW64\blank.htm
                                IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
                                IE: E&xporter vers Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
                                IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
                                IE: ????3?? - c:\users\Thomas\AppData\Roaming\FlashGetBHO\GetUrl.htm
                                IE: ????3?????? - c:\users\Thomas\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
                                Trusted Zone: localhost
                                Trusted Zone: mappy.com
                                Trusted Zone: orange.fr
                                Trusted Zone: voila.fr\rw.search.ke
                                Trusted Zone: weborama.fr\orange
                                .
                                - - - - ORPHELINS SUPPRIMES - - - -
                                .
                                BHO-{d5b8015d-68af-4b2c-9412-e349d82ab4a2} - (no file)
                                BHO-{f379a94e-3c5d-4bad-b32c-0e3af1cc3617} - (no file)
                                Toolbar-{f379a94e-3c5d-4bad-b32c-0e3af1cc3617} - (no file)
                                WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
                                .
                                .
                                .
                                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
                                "ImagePath"="c:\windows\system32\GameMon.des -service"
                                .
                                --------------------- CLES DE REGISTRE BLOQUEES ---------------------
                                .
                                [HKEY_USERS\S-1-5-21-1625509770-3664408973-3642232316-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_f 3*N} ]
                                @Allowed: (Read) (RestrictedCode)
                                @="c:\\Users\\Thomas\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
                                "contexts"=dword:00000022
                                .
                                [HKEY_USERS\S-1-5-21-1625509770-3664408973-3642232316-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_f 3*N} hQè þ"¥c]
                                @Allowed: (Read) (RestrictedCode)
                                @="c:\\Users\\Thomas\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
                                "contexts"=dword:000000f3
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
                                @Denied: (A 2) (Everyone)
                                @="FlashBroker"
                                "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
                                "Enabled"=dword:00000001
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
                                @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
                                @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
                                @Denied: (A 2) (Everyone)
                                @="Shockwave Flash Object"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
                                @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
                                "ThreadingModel"="Apartment"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
                                @="0"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
                                @="ShockwaveFlash.ShockwaveFlash.10"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                                @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
                                @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
                                @="1.0"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                                @="ShockwaveFlash.ShockwaveFlash"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
                                @Denied: (A 2) (Everyone)
                                @="Macromedia Flash Factory Object"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
                                @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
                                "ThreadingModel"="Apartment"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
                                @="FlashFactory.FlashFactory.1"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                                @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
                                @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
                                @="1.0"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                                @="FlashFactory.FlashFactory"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
                                @Denied: (A 2) (Everyone)
                                @="IFlashBroker4"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
                                @="{00020424-0000-0000-C000-000000000046}"
                                .
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
                                @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                                "Version"="1.0"
                                .
                                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
                                @Denied: (A) (Users)
                                @Denied: (A) (Everyone)
                                @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                                "BlindDial"=dword:00000000
                                .
                                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
                                @Denied: (Full) (Everyone)
                                .
                                ------------------------ Autres processus actifs ------------------------
                                .
                                c:\program files\Alwil Software\Avast5\AvastSvc.exe
                                c:\windows\SysWOW64\PnkBstrA.exe
                                c:\windows\SysWOW64\PnkBstrB.exe
                                c:\program files (x86)\Java\jre6\bin\javaw.exe
                                .
                                **************************************************************************
                                .
                                Heure de fin: 2011-10-10 20:51:09 - La machine a redémarré
                                ComboFix-quarantined-files.txt 2011-10-10 18:51
                                .
                                Avant-CF: 150 611 443 712 octets libres
                                Après-CF: 150 161 088 512 octets libres
                                .
                                - - End Of File - - E0290CCCB46BC97EF643A6DE2DA77A56
                                1. Il y a eu une erreur avec le truc toshiba HDD SS Alert et au démarrage il y a 2 messages d'erreurs :

                                  -Windows ne trouve pas "C:/plugins/msn.exe" -> Je sais que c'est une erreur de windows defender

                                  -Une erreur de DLL introuvable de Session Manager d'Orange.

                                  Mon test de debit : http://www.speedtest.net/result/1527477743.png

                                  J'avais du 1MB il y a quelques mois. Puis mon débit a baissé petit a petit. Mon PC démarre toujours lentement, mais moins qu'avant ComboFix
                                  1. Contributeur sécurité
                                    ▶ ▶ DÉSACTIVE TES PROTECTIONS DURANT LA PROCÉDURE

                                    ▶ ▶ SCRIPT PERSONNALISE A CET ORDINATEUR, NE PAS REPRODUIRE : DANGEREUX !!!!


                                    ▶ Créé un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

                                    KillAll::
                                    
                                    File::
                                    c:\users\Thomas\AppData\Local\Temp\005A89D.tmp
                                    
                                    RegLock::
                                    
                                    [HKEY_USERS\S-1-5-21-1625509770-3664408973-3642232316-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_f 3*N} ]
                                     
                                    [HKEY_USERS\S-1-5-21-1625509770-3664408973-3642232316-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_f 3*N} hQè þ"¥c]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
                                     
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
                                     
                                    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
                                     
                                    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
                                     
                                    


                                    ▶ Enregistre ce fichier sous le nom CFScript

                                    ▶ Fait un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture :http://i261.photobucket.com/albums/ii49/Malekal_morte/CFScript-2.gif

                                    ▶ Combofix se lance, laisse toi guider..

                                    ▶ Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal!
                                    Ne touche à rien tant que le scan n'est pas terminé.
                                    ▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu, en précisant où en sont tes soucis

                                    ▶ Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
                                    • 1
                                    • 2