Ordi très très lent

Résolu
Bonjour, je vais essayer d'expliquer mon problème simplement :
depuis 1 semaine mon pc est devenu très lent, il met plusieurs minutes pour s'éteindre, quand je vais sur internet, il y a des pages que je ne peux pas afficher ou qui mettent très très longtemps pour finir par s' afficher incomplètes, à partir de ma messagerie je peux envoyer uniquement des messages, si je veux joindre une photo cela ne se télecharge pas (j' ai attendu + de 2h pour une seule photo !)
J' ai contacté mon fournisseur, qui m' a dit que je n' avais aucun problème de connection, que j' avais certainement un virus, j' ai un anti virus, un pare feu, j' ai passé a2free, ad aware, spybot, un anti virus en ligne, j' ai supprimé tout ce qui a été trouvé et cela ne marche pas mieux....je ne sais plus quoi faire, merci si quelqu' un peut m' aider
Configuration: Windows XP
Internet Explorer 6.0

74 réponses

Résumé de la discussion

Une machine est devenue extrêmement lente depuis une semaine : l'extinction prend des minutes, certaines pages Internet se chargent lentement ou incomplètes, et l'envoi de photos échoue malgré antivirus et pare-feu. La défragmentation a été identifiée comme l'action clé lorsque les performances se sont améliorées rapidement, sans suppression de fichiers ni modifications système dans le cadre de l'échange initial. Des interventions plus invasives ont été proposées, telles que la suppression manuelle de fichiers suspects en mode sans échec et une analyse des programmes, bien que leur nécessité dépende d'un diagnostic précis. En pratique, l'expérience montre que des actions simples et ciblées peuvent suffire, mais il convient de surveiller les programmes au démarrage et les extensions installées pour prévenir d'éventuelles lenteurs futures.

Bobot (l’IA à votre service)
  1. Contributeur
    slt,

    Regarde bien et applique ce qui est indiqué en gras pour les 2 installations .

    ==================================

    Télécharge et installe ce log :

    ewido (gratuit même après la période d’essai)
    Téléchargement :
    ewido
    Cliques sur « update » fais les mise à jour ensuite clique sur « scanner » puis sur « complete scan system ».
    Tuto pour la version 4 d’Ewido :
    https://www.malekal.com/tutorial-et-guide-ewido-v4/

    Met le à jour comme indiqué, lance le « delete » (supprime) tout ce qu’il te trouve et copie/colle moi le rapport.

    Puis :

    télécharge HijackThis (version francaise) ici:
    hijackthis

    Dézippe le dans un dossier prévu à cet effet.

    Par exemple C:\hijackthis < Enregistre le bien dans c : !

    Démo (merci à Balltrap) :
    instalation hijackthis
    http://pageperso.aol.fr/balltrap34/Hijenr.gif

    Lance le puis:
    clique sur "faire un scan et sauvegarder le log" (cf démo)
    faire un copier coller du log entier sur le forum

    Démo : (merci à balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/demohijack.htm

    Bon courage

    a+
    0
    1. merci de me répondre aussi rapidement, je vais faire ça tout de suite
      0
      1. j' ai fini ewido, le rapport est là

        + Scan result:

        C:\Documents and Settings\FREDERIE\Local Settings\Temp\res9.tmp -> Adware.180Solutions : Cleaned with backup (quarantined).
        HKLM\SOFTWARE\Classes\SyncroAdX.Installer -> Adware.BlazeFind : Cleaned with backup (quarantined).
        HKLM\SOFTWARE\Classes\SyncroAdX.Installer\CLSID -> Adware.BlazeFind : Cleaned with backup (quarantined).
        HKLM\SOFTWARE\NIX Solutions -> Adware.DailyToolbar : Cleaned with backup (quarantined).
        HKU\S-1-5-21-3660490617-2741028056-2927458464-1005\Software\NIX Solutions -> Adware.DailyToolbar : Cleaned with backup (quarantined).
        HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1C78AB3F-A857-482E-80C0-3A1E5238A565} -> Adware.Isearch : Cleaned with backup (quarantined).
        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WildArcade -> Adware.MidAddle : Cleaned with backup (quarantined).
        HKLM\SOFTWARE\WildMedia -> Adware.MidAddle : Cleaned with backup (quarantined).
        HKLM\SOFTWARE\WildMedia\LicenseStores -> Adware.MidAddle : Cleaned with backup (quarantined).
        C:\WINDOWS\AccesMembre.dll -> Dialer.CDDial : Cleaned with backup (quarantined).
        HKLM\SOFTWARE\Classes\UDConn.UDConnect -> Dialer.Generic : Cleaned with backup (quarantined).
        HKLM\SOFTWARE\Classes\UDConn.UDConnect.1 -> Dialer.Generic : Cleaned with backup (quarantined).
        HKLM\SOFTWARE\Classes\UDConn.UDConnect\CLSID -> Dialer.Generic : Cleaned with backup (quarantined).
        HKLM\SOFTWARE\Classes\UDConn.UDConnect\CurVer -> Dialer.Generic : Cleaned with backup (quarantined).
        C:\WINDOWS\Downloaded Program Files\installer.dll -> Downloader.ClickMe.a : Cleaned with backup (quarantined).
        HKLM\SOFTWARE\Classes\CLSID\{15ACE85C-0BB1-42d1-9E32-07EB0506675A} -> Downloader.Small.nl : Cleaned with backup (quarantined).
        C:\WINDOWS\Downloaded Program Files\CONFLICT.1\USDR6V_0001_D18M3107NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Ignored.
        C:\WINDOWS\Downloaded Program Files\CONFLICT.2\USDR6V_0001_D18M3107NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Ignored.
        C:\WINDOWS\Downloaded Program Files\CONFLICT.3\USDR6V_0001_D18M3107NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Ignored.
        C:\WINDOWS\Downloaded Program Files\USDR6V_0001_D18M3107NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Ignored.
        C:\Documents and Settings\FREDERIE\Cookies\frederie@247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned.
        C:\Documents and Settings\FREDERIE\Cookies\frederie@adviva[2].txt -> TrackingCookie.Adviva : Cleaned.
        C:\Documents and Settings\FREDERIE\Cookies\frederie@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
        C:\Documents and Settings\FREDERIE\Cookies\frederie@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
        C:\Documents and Settings\FREDERIE\Cookies\frederie@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
        C:\Documents and Settings\FREDERIE\Cookies\frederie@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
        C:\Documents and Settings\FREDERIE\Cookies\frederie@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
        C:\Documents and Settings\FREDERIE\Cookies\frederie@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Cleaned.
        C:\Documents and Settings\FREDERIE\Cookies\frederie@weborama[1].txt -> TrackingCookie.Weborama : Cleaned.
        C:\Documents and Settings\FREDERIE\Local Settings\Temp\Cookies\frederie@weborama[1].txt -> TrackingCookie.Weborama : Cleaned.

        ::Report end
        0
        1. j' ai fini hijackthis, le rapport est là

          Logfile of HijackThis v1.99.1
          Scan saved at 18:10:34, on 13/12/2006
          Platform: Windows XP SP1 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\AVPersonal\AVWUPSRV.EXE
          C:\Program Files\Ahead\InCD\InCDsrv.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\AGRSMMSG.exe
          C:\PROGRA~1\MESSAG~1\StartMessager.exe
          C:\WINDOWS\System32\ezSP_Px.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\evntsvc.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\Program Files\Winamp\winampa.exe
          C:\WINDOWS\System32\rundll32.exe
          C:\Program Files\Extrafilm FotoFacil\Agent.exe
          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
          C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
          C:\Program Files\MSN Messenger\MsnMsgr.Exe
          C:\WINDOWS\VPro500.exe
          c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
          C:\Program Files\MioNet\MioNetManager.exe
          C:\WINDOWS\System32\nvsvc32.exe
          C:\WINDOWS\System32\PAStiSvc.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\MioNet\jvm\bin\MioNet.exe
          C:\Program Files\Sony\vaio media music server\SSSvr.exe
          C:\Program Files\sony\photo server 20\appsrv\PicAppSrv.exe
          C:\Program Files\Fichiers communs\sony shared\vaio media platform\SV_Httpd.exe
          C:\WINDOWS\System32\MsPMSPSv.exe
          C:\Program Files\Fichiers communs\sony shared\vaio media platform\UPnPFramework.exe
          C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
          C:\Program Files\ewido anti-spyware 4.0\guard.exe
          C:\Program Files\ewido anti-spyware 4.0\ewido.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Documents and Settings\FREDERIE\Mes documents\Mes fichiers reçus\hijackthis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tele2internet.fr/
          R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = ,
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ww1.morwillsearch.com
          R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = ,
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.tele2internet.fr/
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - Default URLSearchHook is missing
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
          O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\System32\BhoECart.dll (file missing)
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
          O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
          O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
          O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
          O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
          O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
          O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
          O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
          O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Fichiers communs\Real\Update_OB\evntsvc.exe -osboot
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
          O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
          O4 - HKLM\..\Run: [G] C:\documents and settings\frederie\local settings\temp\G.exe
          O4 - HKLM\..\Run: [qsmQ32X] fplbisenc.exe
          O4 - HKLM\..\Run: [anassim] c:\programmi\syswin\syswin.exe
          O4 - HKLM\..\Run: [eCarteBleue-BP] "C:\Program Files\e-Carte Bleue\Banque Populaire\ECB-BP.exe" /dontopenmycards
          O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
          O4 - HKLM\..\Run: [ExtraFilmHemmaAgent] "C:\Program Files\Extrafilm FotoFacil\Agent.exe"
          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
          O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
          O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
          O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
          O4 - HKCU\..\Run: [Eree] C:\Documents and Settings\FREDERIE\Application Data\hgnk?.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [bB54RSb3l] tftompos.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
          O4 - Global Startup: hpothb07.dat
          O4 - Global Startup: hpothb07.tif
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
          O4 - Global Startup: VPro500.lnk = ?
          O14 - IERESET.INF: START_PAGE_URL=https://www.free.fr/freebox/index.html
          O15 - Trusted Zone: www.master69.biz
          O15 - Trusted Zone: *.morwillsearch.com
          O15 - Trusted Zone: *.sony-europe.com
          O15 - Trusted Zone: *.sonystyle-europe.com
          O15 - Trusted Zone: *.vaio-link.com
          O15 - Trusted Zone: www.xbeta69.com
          O15 - Trusted Zone: www.yeak.net
          O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
          O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone (HKLM)
          O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://www.advnt01.com/dialer/france.exe
          O16 - DPF: {01347765-1965-426B-91A4-AA6BB342B9A3} (InstallerObj Class) - http://www.1-click.com/common/files/installer-hidden-test.cab
          O16 - DPF: {093F9CF8-0DE1-491C-95D5-5EC257BD4CA3} - https://www.afternic.com/domains/downloadv3.com
          O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
          O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://cdn.downloadcontrol.com/files/installers/cab/SystemDoctor2006FreeInstall_fr.cab
          O16 - DPF: {0E635920-8FD6-5B9E-74E0-5D06757B9A76} - http://205.252.249.254/1/gdnFR1077.exe
          O16 - DPF: {0F7367A4-9D49-2222-BC3F-08DD0A07AF96} - http://66.117.37.5/1/gdnFR116.exe
          O16 - DPF: {0F9EE533-2E1B-7D3A-05B8-3B914781F72C} - http://69.50.188.54/1/gdnSE208.exe
          O16 - DPF: {10ABC6DB-E091-4EAE-98DD-21B5A2460714} (DetInstaller Class) - https://www.pandasecurity.com/?ref=www.pandasoftware.es/avchecker/controles/AvDetInst.cab
          O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
          O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} - https://www.snapfish.fr/2/home
          O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - https://www.afternic.com/domains/downloadv3.com
          O16 - DPF: {49E9412B-76A5-037D-A72E-5E582E85EA56} - http://69.50.188.54/1/gdnFR208.exe
          O16 - DPF: {511F9316-771B-4953-A268-1C36DA667FE9} - http://ip.sponsoradulto.com/cab/3/en/SysWebTelecomInt.cab
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
          O16 - DPF: {6D19696C-DBA2-6A03-DDF9-06411133CECE} - http://66.117.37.5/1/gdnFR116.exe
          O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
          O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
          O16 - DPF: {86EEF11E-FF16-48CE-B1A2-474B663041A9} - http://www.sexequalite.com/11731/Ovidie.exe
          O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - https://www.f-secure.com/en/home/support
          O16 - DPF: {92ABACFE-EF6E-42C7-A824-D50A914B5B70} (MastaCash Loader Class) - http://dx.mastacash.com/loader.cab
          O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - https://www.pandasecurity.com/?ref=www.pandasoftware.com/activescan/as5/asinst.cab
          O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.extrafilm.fr/import/ImageUploader3.cab
          O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
          O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
          O16 - DPF: {AD7A67A5-5461-4B6B-A9C5-09DD071527F5} (MCLPhoto_Upload.PhotoUpload) - http://auchan.fujifilmnet.com/MCLPhoto.CAB
          O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/dlhelper/version7/dlhelper.cab
          O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
          O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/...
          O16 - DPF: {D62B5127-8D03-4175-BA71-E0041595DA4B} (UDConnect Class) - http://03.sharedsource.org/html/TriacomUD_1.0.0.3ie.cab?
          O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
          O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildAppNonUS.cab
          O16 - DPF: {FFFF0001-0001-101A-A3C9-08002B2F49FC} - http://www.desktoplife.net/generale.exe
          O17 - HKLM\System\CCS\Services\Tcpip\..\{8E35E0F0-2E8D-4DAF-9AFD-693BCE880A7D}: NameServer = 212.151.137.166 212.151.136.242
          O21 - SSODL: System - {45C542F0-9158-4963-B328-137D08338468} - C:\WINDOWS\system32\system32.dll (file missing)
          O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
          O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
          O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
          O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
          O23 - Service: MioNet Service (MioNet) - Unknown owner - C:\Program Files\MioNet\MioNetManager.exe" -s "C:\Program Files\MioNet\wrapper.conf (file missing)
          O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
          O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
          O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
          O23 - Service: VAIO Media Music Server (Application) (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\vaio media music server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (Application) (file missing)
          O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\vaio media platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
          O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\vaio media platform\UPnPFramework.exe
          O23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppServer) - Unknown owner - C:\Program Files\sony\photo server 20\appsrv\PicAppSrv.exe
          O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Fichiers communs\sony shared\vaio media platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
          O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Fichiers communs\sony shared\vaio media platform\UPnPFramework.exe
          0
          1. j' ai dû fermer la page de hijackthis, car j' ai redémarrer mon ordi, je ne pouvais plus ouvrir aucune page, plus rien ne marchait, sans que je ne touche rien...j' espère que ce n' est pas trop grave
            0
            1. Contributeur
              ok :)

              Télécharges smitfraudfix:(merci a S!RI pour ce programme)

              En image :
              http://siri.urz.free.fr/Fix/SmitfraudFix.php

              tu le décompresses tu doubles cliques sur smitfraudfix.cmd et tu choisis l option 1
              cela vas générer un rapport.
              Si tu vois des lignes avec PRESENT!

              - > Continue la manip qui suit.

              * Redémarres le PC en mode sans échec : Au démarrage tu tapotes sur la touche F8 de ton clavier (ou F5 ) et tu choisis le [mode sans échec]

              * Ouvre le dossier [SmitfraudFix] et double clic sur Smitfraudfix.cmd, choisit l’option 2 et tu réponds oui à tout.

              Copie/colle le rapport sur le forum stp.

              a+
              0
              1. merci de ton aide

                le rapport est là (pas de ligne PRESENT)

                SmitFraudFix v2.130

                Rapport fait à 8:44:40,17, 14/12/2006
                Executé à partir de C:\Documents and Settings\FREDERIE\Mes documents\Mes fichiers re‡us\SmitfraudFix
                OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                Le type du système de fichiers est NTFS
                Fix executé en mode normal

                »»»»»»»»»»»»»»»»»»»»»»»» C:\

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\FREDERIE

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\FREDERIE\Application Data

                »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\FREDERIE\Favoris

                »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                "Source"="About:Home"
                "SubscribedURL"="About:Home"
                "FriendlyName"="Ma page d'accueil"

                »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                SrchSTS.exe by S!Ri
                Search SharedTaskScheduler's .dll

                »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                "AppInit_DLLs"=""

                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                "System"=""

                »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

                »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                »»»»»»»»»»»»»»»»»»»»»»»» Fin
                0
                1. il y a quoi dans les rapports que je t' ai envoyé ?
                  0
                  1. le problème est toujours là, là encore j' ai dû redémarrer mon ordi, je suis connecté à internet et d'un coup, cela me dit impossible d' afficher la page, si je me déconnecte et reconnecte, cela ne change rien au problème, il faut que je redémarre l' ordi une fois ou +sieurs, cela dépend des jours, et cela se produit au moins une fois par jour..........au secours
                    0
                    1. Slt

                      Pour avancer
                      tu peux refaire un rapport Hitjackthis
                      stp
                      merci

                      0
                      1. merci, je refais ça tout de suite
                        0
                        1. le rapport est là

                          Logfile of HijackThis v1.99.1
                          Scan saved at 11:01:15, on 14/12/2006
                          Platform: Windows XP SP1 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\AVPersonal\AVWUPSRV.EXE
                          C:\Program Files\ewido anti-spyware 4.0\guard.exe
                          C:\Program Files\Ahead\InCD\InCDsrv.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\AGRSMMSG.exe
                          C:\PROGRA~1\MESSAG~1\StartMessager.exe
                          C:\WINDOWS\System32\ezSP_Px.exe
                          C:\Program Files\Fichiers communs\Real\Update_OB\evntsvc.exe
                          C:\Program Files\QuickTime\qttask.exe
                          C:\Program Files\Winamp\winampa.exe
                          C:\WINDOWS\System32\rundll32.exe
                          C:\Program Files\Extrafilm FotoFacil\Agent.exe
                          C:\Program Files\MioNet\MioNetManager.exe
                          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                          C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
                          C:\WINDOWS\System32\nvsvc32.exe
                          C:\Program Files\MioNet\jvm\bin\MioNet.exe
                          C:\WINDOWS\System32\PAStiSvc.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Sony\vaio media music server\SSSvr.exe
                          C:\Program Files\ewido anti-spyware 4.0\ewido.exe
                          C:\Program Files\sony\photo server 20\appsrv\PicAppSrv.exe
                          C:\Program Files\Fichiers communs\sony shared\vaio media platform\SV_Httpd.exe
                          C:\WINDOWS\System32\MsPMSPSv.exe
                          C:\Program Files\Fichiers communs\sony shared\vaio media platform\UPnPFramework.exe
                          C:\Program Files\MSN Messenger\MsnMsgr.Exe
                          c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
                          C:\WINDOWS\VPro500.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
                          C:\Documents and Settings\FREDERIE\Mes documents\Mes fichiers reçus\hijackthis\HijackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tele2internet.fr/
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = ,
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ww1.morwillsearch.com
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = ,
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.tele2internet.fr/
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          R3 - Default URLSearchHook is missing
                          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                          O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\System32\BhoECart.dll (file missing)
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                          O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
                          O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                          O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
                          O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
                          O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                          O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                          O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
                          O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Fichiers communs\Real\Update_OB\evntsvc.exe -osboot
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                          O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
                          O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                          O4 - HKLM\..\Run: [G] C:\documents and settings\frederie\local settings\temp\G.exe
                          O4 - HKLM\..\Run: [qsmQ32X] fplbisenc.exe
                          O4 - HKLM\..\Run: [anassim] c:\programmi\syswin\syswin.exe
                          O4 - HKLM\..\Run: [eCarteBleue-BP] "C:\Program Files\e-Carte Bleue\Banque Populaire\ECB-BP.exe" /dontopenmycards
                          O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
                          O4 - HKLM\..\Run: [ExtraFilmHemmaAgent] "C:\Program Files\Extrafilm FotoFacil\Agent.exe"
                          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                          O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
                          O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
                          O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
                          O4 - HKCU\..\Run: [Eree] C:\Documents and Settings\FREDERIE\Application Data\hgnk?.exe
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                          O4 - HKCU\..\Run: [bB54RSb3l] tftompos.exe
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
                          O4 - Global Startup: hpothb07.dat
                          O4 - Global Startup: hpothb07.tif
                          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                          O4 - Global Startup: VPro500.lnk = ?
                          O14 - IERESET.INF: START_PAGE_URL=https://www.free.fr/freebox/index.html
                          O15 - Trusted Zone: www.master69.biz
                          O15 - Trusted Zone: *.morwillsearch.com
                          O15 - Trusted Zone: *.sony-europe.com
                          O15 - Trusted Zone: *.sonystyle-europe.com
                          O15 - Trusted Zone: *.vaio-link.com
                          O15 - Trusted Zone: www.xbeta69.com
                          O15 - Trusted Zone: www.yeak.net
                          O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
                          O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone (HKLM)
                          O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://www.advnt01.com/dialer/france.exe
                          O16 - DPF: {01347765-1965-426B-91A4-AA6BB342B9A3} (InstallerObj Class) - http://www.1-click.com/common/files/installer-hidden-test.cab
                          O16 - DPF: {093F9CF8-0DE1-491C-95D5-5EC257BD4CA3} - https://www.afternic.com/domains/downloadv3.com
                          O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
                          O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://cdn.downloadcontrol.com/files/installers/cab/SystemDoctor2006FreeInstall_fr.cab
                          O16 - DPF: {0E635920-8FD6-5B9E-74E0-5D06757B9A76} - http://205.252.249.254/1/gdnFR1077.exe
                          O16 - DPF: {0F7367A4-9D49-2222-BC3F-08DD0A07AF96} - http://66.117.37.5/1/gdnFR116.exe
                          O16 - DPF: {0F9EE533-2E1B-7D3A-05B8-3B914781F72C} - http://69.50.188.54/1/gdnSE208.exe
                          O16 - DPF: {10ABC6DB-E091-4EAE-98DD-21B5A2460714} (DetInstaller Class) - https://www.pandasecurity.com/?ref=www.pandasoftware.es/avchecker/controles/AvDetInst.cab
                          O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
                          O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} - https://www.snapfish.fr/2/home
                          O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - https://www.afternic.com/domains/downloadv3.com
                          O16 - DPF: {49E9412B-76A5-037D-A72E-5E582E85EA56} - http://69.50.188.54/1/gdnFR208.exe
                          O16 - DPF: {511F9316-771B-4953-A268-1C36DA667FE9} - http://ip.sponsoradulto.com/cab/3/en/SysWebTelecomInt.cab
                          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                          O16 - DPF: {6D19696C-DBA2-6A03-DDF9-06411133CECE} - http://66.117.37.5/1/gdnFR116.exe
                          O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                          O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
                          O16 - DPF: {86EEF11E-FF16-48CE-B1A2-474B663041A9} - http://www.sexequalite.com/11731/Ovidie.exe
                          O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - https://www.f-secure.com/en/home/support
                          O16 - DPF: {92ABACFE-EF6E-42C7-A824-D50A914B5B70} (MastaCash Loader Class) - http://dx.mastacash.com/loader.cab
                          O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - https://www.pandasecurity.com/?ref=www.pandasoftware.com/activescan/as5/asinst.cab
                          O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.extrafilm.fr/import/ImageUploader3.cab
                          O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
                          O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
                          O16 - DPF: {AD7A67A5-5461-4B6B-A9C5-09DD071527F5} (MCLPhoto_Upload.PhotoUpload) - http://auchan.fujifilmnet.com/MCLPhoto.CAB
                          O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/dlhelper/version7/dlhelper.cab
                          O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
                          O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/...
                          O16 - DPF: {D62B5127-8D03-4175-BA71-E0041595DA4B} (UDConnect Class) - http://03.sharedsource.org/html/TriacomUD_1.0.0.3ie.cab?
                          O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
                          O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildAppNonUS.cab
                          O16 - DPF: {FFFF0001-0001-101A-A3C9-08002B2F49FC} - http://www.desktoplife.net/generale.exe
                          O17 - HKLM\System\CCS\Services\Tcpip\..\{8E35E0F0-2E8D-4DAF-9AFD-693BCE880A7D}: NameServer = 212.151.137.166 212.151.136.242
                          O21 - SSODL: System - {45C542F0-9158-4963-B328-137D08338468} - C:\WINDOWS\system32\system32.dll (file missing)
                          O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
                          O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
                          O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
                          O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
                          O23 - Service: MioNet Service (MioNet) - Unknown owner - C:\Program Files\MioNet\MioNetManager.exe" -s "C:\Program Files\MioNet\wrapper.conf (file missing)
                          O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                          O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
                          O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
                          O23 - Service: VAIO Media Music Server (Application) (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\vaio media music server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (Application) (file missing)
                          O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\vaio media platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
                          O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\vaio media platform\UPnPFramework.exe
                          O23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppServer) - Unknown owner - C:\Program Files\sony\photo server 20\appsrv\PicAppSrv.exe
                          O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Fichiers communs\sony shared\vaio media platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
                          O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Fichiers communs\sony shared\vaio media platform\UPnPFramework.exe
                          0
                          1. Contributeur
                            Télécharge ceci:

                            1)http://pageperso.aol.fr/balltrap34/lopxp.zip (Merci Moe31 et Balltrap34)
                            2) Dézippe-le (clic droit dessus > extraire tout)
                            et lance lopxp.bat

                            Copies et colles le rapport ici.

                            a+
                            0
                            1. Salut

                              Evite d'aller sur des sites PORNOS.....

                              Faut commencer par ça...

                              Bonjour,

                              Méthode à suivre dans l'ordre...
                              ----------------------------------------------------------------------------
                              Télécharger ces logiciels (sauf si tu les as)
                              A utiliser plus tard

                              A - ad-aware version 1.06
                              (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite
                              voir demo
                              http://pageperso.aol.fr/balltrap34/adwseflash.zip

                              B - spybot version 1.4
                              (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite
                              voir demo d utilisation
                              http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

                              C - Ccleaner : ( nettoyeur de registre, cookies+temps+tempos+prefetch+historique+etc..)
                              Télécharge ici :
                              https://www.ccleaner.com/ccleaner/download
                              Tutorial ici:
                              https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

                              D - Ewido
                              https://www.malekal.com/tutorial-et-guide-ewido-v4/
                              ----------------------------------------------------------------------------
                              ¤Affiche tous les fichiers et dossiers :
                              Clique sur démarrer/panneau de configuration/outil/option des dossiers/affichage

                              Coche « afficher les fichiers et dossiers cachés »

                              Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                              Décoche « masquer les extensions dont le type est connu »
                              Puis fais «Ok» pour valider les changements.

                              Et appliquer !
                              =================================
                              Relance HijackThis, choisis " do a scan only" coche la case devant les lignes ci-dessous et clique en bas sur "fix checked"
                              R3 - Default URLSearchHook is missing
                              O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\System32\BhoECart.dll (file missing)
                              O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" –atboottime
                              O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                              O4 - HKLM\..\Run: [G] C:\documents and settings\frederie\local settings\temp\G.exe
                              O4 - HKLM\..\Run: [qsmQ32X] fplbisenc.exe
                              O4 - HKLM\..\Run: [anassim] c:\programmi\syswin\syswin.exe
                              O4 - HKLM\..\Run: [eCarteBleue-BP] "C:\Program Files\e-Carte Bleue\Banque Populaire\ECB-BP.exe" /dontopenmycards
                              O4 - HKLM\..\Run: [ExtraFilmHemmaAgent] "C:\Program Files\Extrafilm FotoFacil\Agent.exe"
                              O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
                              O4 - HKCU\..\Run: [Eree] C:\Documents and Settings\FREDERIE\Application Data\hgnk?.exe
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                              O4 - HKCU\..\Run: [bB54RSb3l] tftompos.exe
                              O4 - Global Startup: hpothb07.dat
                              O4 - Global Startup: hpothb07.tif
                              O4 - Global Startup: VPro500.lnk = ?

                              O15 - Trusted Zone: www.master69.biz
                              O15 - Trusted Zone: *.morwillsearch.com
                              O15 - Trusted Zone: www.xbeta69.com
                              O15 - Trusted Zone: www.yeak.net
                              O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
                              O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone (HKLM)
                              O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://www.advnt01.com/dialer/france.exe
                              O16 - DPF: {01347765-1965-426B-91A4-AA6BB342B9A3} (InstallerObj Class) - http://www.1-click.com/common/files/installer-hidden-test.cab
                              O16 - DPF: {093F9CF8-0DE1-491C-95D5-5EC257BD4CA3} - https://www.afternic.com/domains/downloadv3.com
                              O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
                              O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://cdn.downloadcontrol.com/
                              O16 - DPF: {0E635920-8FD6-5B9E-74E0-5D06757B9A76} - http://205.252.249.254/1/gdnFR1077.exe
                              O16 - DPF: {0F7367A4-9D49-2222-BC3F-08DD0A07AF96} - http://66.117.37.5/1/gdnFR116.exe
                              O16 - DPF: {0F9EE533-2E1B-7D3A-05B8-3B914781F72C} - http://69.50.188.54/1/gdnSE208.exe
                              O16 - DPF: {10ABC6DB-E091-4EAE-98DD-21B5A2460714} (DetInstaller Class) - https://www.pandasecurity.com/?ref=www.pandasoftware.es/avchecker/controles/AvDetInst.cab
                              O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
                              O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} - https://www.snapfish.fr/2/home
                              O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - https://www.afternic.com/domains/downloadv3.com
                              O16 - DPF: {49E9412B-76A5-037D-A72E-5E582E85EA56} - http://69.50.188.54/1/gdnFR208.exe
                              O16 - DPF: {511F9316-771B-4953-A268-1C36DA667FE9} - http://ip.sponsoradulto.com/cab/3/en/SysWebTelecomInt.cab
                              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/default.aspx
                              O16 - DPF: {6D19696C-DBA2-6A03-DDF9-06411133CECE} - http://66.117.37.5/1/gdnFR116.exe
                              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/
                              O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
                              O16 - DPF: {86EEF11E-FF16-48CE-B1A2-474B663041A9} - http://www.sexequalite.com/11731/Ovidie.exe
                              O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - https://www.f-secure.com/en/home/support
                              O16 - DPF: {92ABACFE-EF6E-42C7-A824-D50A914B5B70} (MastaCash Loader Class) - http://dx.mastacash.com/loader.cab
                              O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - https://www.pandasecurity.com/?ref=www.pandasoftware.com/activescan/as5/asinst.cab
                              O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.extrafilm.fr/import/ImageUploader3.cab
                              O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
                              O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
                              O16 - DPF: {AD7A67A5-5461-4B6B-A9C5-09DD071527F5} (MCLPhoto_Upload.PhotoUpload) - http://auchan.fujifilmnet.com/MCLPhoto.CAB
                              O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/dlhelper/version7/dlhelper.cab
                              O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
                              O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/
                              O16 - DPF: {D62B5127-8D03-4175-BA71-E0041595DA4B} (UDConnect Class) - http://03.sharedsource.org/html/TriacomUD_1.0.0.3ie.cab?
                              O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
                              O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildAppNonUS.cab

                              Faut que je me renseigne pour cette ligne
                              O21 - SSODL: System - {45C542F0-9158-4963-B328-137D08338468} - C:\WINDOWS\system32\system32.dll (file missing

                              Connais tu ces programmes , supprime les

                              \Extrafilm FotoFacil
                              WOOTASKBARICON
                              : e-Carte Bleue Browser
                              ============ ============================
                              ¤Démarre en mode sans échec :
                              Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                              Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                              Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                              (Si F8 ne marche pas utilise la touche F5).
                              ----------------------------------------------------------------------------
                              ¤Vide tes fichiers temps et temporary internet file:

                              Maintenant tu lances
                              A/ Ad-Aware supprime quarantaine
                              B/ Spybot Supprime quarantaine
                              C/ Ccleaner Ewido Copier/coller le rapport
                              D/
                              ----------------------------------------------------------------------------
                              ¤ Vide ta Corbeille.
                              ----------------------------------------------------------------------------
                              ¤ Redémarre en mode normal, relance Hijackthis et copie/colle un nouveau rapport sur le forum.

                              Tiens nous au courant

                              A+

                              Edit ==> y'en a encore...

                              0
                              1. seb et marie, merci pour votre aide, je vais faire ça tout de suite
                                0
                                1. seb, le rapport que tu m' as demandé est là

                                  Rapport fait à 17:04:59,87 le 14/12/2006

                                  Le volume dans le lecteur C s'appelle VAIO
                                  Le num‚ro de s‚rie du volume est 3CD7-514A

                                  R‚pertoire de C:\Documents and Settings\All Users\Application Data

                                  29/10/2006 18:32 <REP> Kaspersky Anti-Virus Personal Pro
                                  29/10/2006 15:57 <REP> Kaspersky Lab
                                  27/09/2006 12:10 <REP> Google
                                  16/05/2006 18:16 <REP> CyberLink
                                  30/08/2005 11:00 0 hpothb07.dat
                                  30/08/2005 11:00 0 hpothb07.tif
                                  11/08/2004 12:05 <REP> Spybot - Search & Destroy
                                  23/11/2003 21:57 <REP> VAIO Media Platform
                                  10/04/2003 15:03 <REP> QuickTime
                                  10/04/2003 01:44 62 desktop.ini
                                  10/04/2003 01:44 <REP> Microsoft
                                  10/04/2003 01:44 <REP> ..
                                  10/04/2003 01:44 <REP> .
                                  10/04/2003 01:16 <REP> Sony Corporation
                                  10/04/2003 00:56 <REP> SBSI
                                  3 fichier(s) 62 octets
                                  12 R‚p(s) 3255283712 octets libres
                                  Le volume dans le lecteur C s'appelle VAIO
                                  Le num‚ro de s‚rie du volume est 3CD7-514A

                                  R‚pertoire de C:\Documents and Settings\Default User\Application Data

                                  30/08/2005 11:01 0 hpothb07.dat
                                  30/08/2005 11:01 0 hpothb07.tif
                                  06/11/2003 20:34 <REP> Real
                                  06/11/2003 20:34 <REP> InterTrust
                                  10/04/2003 01:44 62 desktop.ini
                                  10/04/2003 01:44 <REP> ..
                                  10/04/2003 01:44 <REP> Microsoft
                                  10/04/2003 01:44 <REP> .
                                  10/04/2003 00:51 <REP> Identities
                                  3 fichier(s) 62 octets
                                  6 R‚p(s) 3255283712 octets libres
                                  Le volume dans le lecteur C s'appelle VAIO
                                  Le num‚ro de s‚rie du volume est 3CD7-514A

                                  R‚pertoire de C:\Documents and Settings\FREDERIE\Application Data

                                  21/08/2006 15:12 <REP> vlc
                                  17/05/2006 19:02 <REP> CyberLink
                                  04/05/2006 19:35 <REP> EFF
                                  09/04/2006 20:25 <REP> Sun
                                  23/10/2005 19:56 <REP> Google
                                  09/10/2005 18:36 <REP> ArcSoft
                                  30/08/2005 11:01 0 hpothb07.tif
                                  30/08/2005 11:01 0 hpothb07.dat
                                  07/04/2005 14:32 <REP> Sony Corporation
                                  18/03/2005 10:59 <REP> Winds_24
                                  24/01/2005 18:05 <REP> SysDown
                                  19/07/2004 15:57 <REP> aseo
                                  02/04/2004 13:10 <REP> Microsoft Web Folders
                                  20/03/2004 15:36 <REP> Dossier de t‚l‚chargement Share-to-Web
                                  29/02/2004 18:21 <REP> Ahead
                                  01/02/2004 16:35 <REP> Roxio
                                  11/01/2004 19:20 <REP> Template
                                  11/01/2004 17:56 <REP> Hewlett-Packard
                                  11/01/2004 09:57 <REP> Macromedia
                                  11/01/2004 00:39 <REP> Dossier de t‚l‚chargement Share-to-Web
                                  23/11/2003 21:47 <REP> Adobe
                                  10/11/2003 18:30 <REP> Help
                                  06/11/2003 20:35 62 desktop.ini
                                  06/11/2003 20:35 <REP> Identities
                                  06/11/2003 20:35 <REP> InterTrust
                                  06/11/2003 20:35 <REP> Microsoft
                                  06/11/2003 20:35 <REP> ..
                                  06/11/2003 20:35 <REP> .
                                  06/11/2003 20:35 <REP> Real
                                  3 fichier(s) 62 octets
                                  26 R‚p(s) 3255283712 octets libres
                                  ******************************************
                                  Recherche des taches planifiées dans C:\WINDOWS\tasks

                                  Le volume dans le lecteur C s'appelle VAIO
                                  Le num‚ro de s‚rie du volume est 3CD7-514A

                                  R‚pertoire de C:\WINDOWS\Tasks

                                  10/04/2003 00:51 6 SA.DAT
                                  10/04/2003 00:50 <REP> ..
                                  10/04/2003 00:50 <REP> .
                                  10/04/2003 00:40 65 desktop.ini
                                  2 fichier(s) 71 octets
                                  2 R‚p(s) 3ÿ255ÿ283ÿ712 octets libres

                                  ******************************************
                                  Recherche dans Program files

                                  Le dossier C:\Program Files\C2Media n'existe pas

                                  *************** Fin du rapport ****************
                                  0
                                  1. marie, au sujet des programmes dont tu me parles, il s'agit d' extrafilm c'est pour développer des photos sur internet (pas important, ça je peux le supprimer) et l' autre c'est ma carte bleue "virtuelle" pour faire des achats, si je supprime ce programme elle ne va plus fonctionner, non ?
                                    0
                                    1. Contributeur
                                      Faut que je me renseigne pour cette ligne
                                      O21 - SSODL: System - {45C542F0-9158-4963-B328-137D08338468} - C:\WINDOWS\system32\system32.dll (file missing


                                      Fixe la aussi .

                                      Tiens nous au courant.

                                      a+
                                      0
                                      1. j' ai enfin fini de tout faire(je n' ai pas supprimé les lignes concernant ma e carte) le rapport ewido est là

                                        ewido anti-spyware - Scan Report
                                        ---------------------------------------------------------

                                        + Created at: 19:24:49 14/12/2006

                                        + Scan result:

                                        C:\WINDOWS\Downloaded Program Files\CONFLICT.1\USDR6V_0001_D18M3107NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Ignored.
                                        C:\WINDOWS\Downloaded Program Files\CONFLICT.2\USDR6V_0001_D18M3107NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Ignored.
                                        C:\WINDOWS\Downloaded Program Files\CONFLICT.3\USDR6V_0001_D18M3107NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Ignored.
                                        C:\WINDOWS\Downloaded Program Files\USDR6V_0001_D18M3107NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Ignored.

                                        ::Report end
                                        0
                                        1. rapport hijackthis

                                          Logfile of HijackThis v1.99.1
                                          Scan saved at 19:36:38, on 14/12/2006
                                          Platform: Windows XP SP1 (WinNT 5.01.2600)
                                          MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                                          Running processes:
                                          C:\WINDOWS\System32\smss.exe
                                          C:\WINDOWS\system32\winlogon.exe
                                          C:\WINDOWS\system32\services.exe
                                          C:\WINDOWS\system32\lsass.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\WINDOWS\system32\spoolsv.exe
                                          C:\Program Files\AVPersonal\AVWUPSRV.EXE
                                          C:\Program Files\ewido anti-spyware 4.0\guard.exe
                                          C:\Program Files\Ahead\InCD\InCDsrv.exe
                                          C:\WINDOWS\Explorer.EXE
                                          C:\WINDOWS\AGRSMMSG.exe
                                          C:\WINDOWS\System32\ezSP_Px.exe
                                          C:\Program Files\MioNet\MioNetManager.exe
                                          C:\Program Files\Fichiers communs\Real\Update_OB\evntsvc.exe
                                          C:\WINDOWS\System32\nvsvc32.exe
                                          C:\WINDOWS\System32\rundll32.exe
                                          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                                          C:\Program Files\MioNet\jvm\bin\MioNet.exe
                                          C:\Program Files\ewido anti-spyware 4.0\ewido.exe
                                          C:\WINDOWS\System32\PAStiSvc.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\Program Files\Sony\vaio media music server\SSSvr.exe
                                          C:\Program Files\sony\photo server 20\appsrv\PicAppSrv.exe
                                          C:\WINDOWS\System32\MsPMSPSv.exe
                                          C:\Program Files\Fichiers communs\sony shared\vaio media platform\SV_Httpd.exe
                                          C:\Program Files\Fichiers communs\sony shared\vaio media platform\UPnPFramework.exe
                                          C:\Program Files\Internet Explorer\iexplore.exe
                                          C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
                                          C:\Documents and Settings\FREDERIE\Mes documents\Mes fichiers reçus\hijackthis\HijackThis.exe

                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tele2internet.fr/
                                          R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = ,
                                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ww1.morwillsearch.com
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = ,
                                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.tele2internet.fr/
                                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                                          O2 - BHO: ECarteBleueBrowserHelper Class - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\System32\BhoECart.dll (file missing)
                                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                                          O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                                          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                                          O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
                                          O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                                          O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
                                          O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                                          O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                                          O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
                                          O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Fichiers communs\Real\Update_OB\evntsvc.exe -osboot
                                          O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
                                          O4 - HKLM\..\Run: [eCarteBleue-BP] "C:\Program Files\e-Carte Bleue\Banque Populaire\ECB-BP.exe" /dontopenmycards
                                          O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
                                          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                                          O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
                                          O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
                                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
                                          O4 - Global Startup: hpothb07.dat
                                          O4 - Global Startup: hpothb07.tif
                                          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                                          O14 - IERESET.INF: START_PAGE_URL=https://www.free.fr/freebox/index.html
                                          O15 - Trusted Zone: *.sony-europe.com
                                          O15 - Trusted Zone: *.sonystyle-europe.com
                                          O15 - Trusted Zone: *.vaio-link.com
                                          O16 - DPF: {FFFF0001-0001-101A-A3C9-08002B2F49FC} - http://www.desktoplife.net/generale.exe
                                          O17 - HKLM\System\CCS\Services\Tcpip\..\{8E35E0F0-2E8D-4DAF-9AFD-693BCE880A7D}: NameServer = 212.151.137.170 212.151.136.246
                                          O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
                                          O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
                                          O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
                                          O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
                                          O23 - Service: MioNet Service (MioNet) - Unknown owner - C:\Program Files\MioNet\MioNetManager.exe" -s "C:\Program Files\MioNet\wrapper.conf (file missing)
                                          O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                                          O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
                                          O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
                                          O23 - Service: VAIO Media Music Server (Application) (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\vaio media music server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (Application) (file missing)
                                          O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\vaio media platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
                                          O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\vaio media platform\UPnPFramework.exe
                                          O23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppServer) - Unknown owner - C:\Program Files\sony\photo server 20\appsrv\PicAppSrv.exe
                                          O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Fichiers communs\sony shared\vaio media platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
                                          O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Fichiers communs\sony shared\vaio media platform\UPnPFramework.exe
                                          0
                                          • 1
                                          • 2
                                          • 3
                                          • 4