Besoin de renseignement hijack

Résolu
Bonjour,

j'aimerais qu 'une personne m'aide a logger un hijack et voir par la meme occasion si dans mon pc il y a pas des betites merdasse!!
car depuis peu mon pc rame.... ma corbeille se place pas sur le bureau ou je voudrais et ma zone de lancement rapide se desinstalle a chaque demarage et d'autre souci je pense lolll
j'attends votre aide et merci a vous
Configuration: Windows XP
Internet Explorer 6.0

19 réponses

  1. je vous poste le rapport merci:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:13:17, on 26/12/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\SuperCopier2\SuperCopier2.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\a-squared Free\a2service.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\WINDOWS\system32\oodag.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\ehome\mcrdsvc.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\VideoLAN\VLC\vlc.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.acer.com/worldwide/selection.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.acer.com/worldwide/selection.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
    O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: &Télécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Tout t&élécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
    O20 - Winlogon Notify: tapiperf32 - tapiperf32.dll (file missing)
    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
    O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
    0
    1. Contributeur sécurité
      bonsoir,

      lance AVG AS pour un scan complet, et poste le rapport ici ensuite stp
      0
      1. merci de ta reponse j'ai lancé avg a suivre....
        0
        1. re voici le rapport avg:

          AVG Anti-Spyware - Rapport d'analyse
          ---------------------------------------------------------

          + Créé à: 22:41:27 26/12/2007

          + Résultat de l'analyse:

          C:\Documents and Settings\laurent\Local Settings\Temporary Internet Files\Content.IE5\QDF5NQJQ\common[1].js -> Downloader.Agent.zf : Aucune action entreprise.
          :mozilla.116:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
          :mozilla.202:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
          C:\Documents and Settings\laurent\Cookies\laurent@2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
          C:\Documents and Settings\laurent\Cookies\laurent@pinnaclesystems.122.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
          :mozilla.100:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Adtech : Aucune action entreprise.
          C:\Documents and Settings\laurent\Cookies\laurent@adtech[1].txt -> TrackingCookie.Adtech : Aucune action entreprise.
          :mozilla.14:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Advertising : Aucune action entreprise.
          :mozilla.15:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Advertising : Aucune action entreprise.
          :mozilla.16:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Advertising : Aucune action entreprise.
          :mozilla.17:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Advertising : Aucune action entreprise.
          C:\Documents and Settings\laurent\Cookies\laurent@advertising[1].txt -> TrackingCookie.Advertising : Aucune action entreprise.
          :mozilla.72:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Adviva : Aucune action entreprise.
          :mozilla.104:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Atdmt : Aucune action entreprise.
          C:\Documents and Settings\laurent\Cookies\laurent@atdmt[2].txt -> TrackingCookie.Atdmt : Aucune action entreprise.
          :mozilla.63:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
          C:\Documents and Settings\laurent\Cookies\laurent@bluestreak[1].txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
          :mozilla.22:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
          C:\Documents and Settings\laurent\Cookies\laurent@doubleclick[1].txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
          :mozilla.7:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Estat : Aucune action entreprise.
          C:\Documents and Settings\laurent\Cookies\laurent@estat[1].txt -> TrackingCookie.Estat : Aucune action entreprise.
          :mozilla.154:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Googleadservices : Aucune action entreprise.
          :mozilla.85:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
          C:\Documents and Settings\laurent\Cookies\laurent@mediaplex[1].txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
          :mozilla.106:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Overture : Aucune action entreprise.
          :mozilla.64:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          :mozilla.65:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          :mozilla.66:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          :mozilla.67:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          :mozilla.68:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          :mozilla.69:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          :mozilla.70:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurent\Cookies\laurent@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          C:\Documents and Settings\laurent\Cookies\laurent@serving-sys[2].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
          :mozilla.18:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          :mozilla.19:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          :mozilla.20:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          :mozilla.21:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurent\Cookies\laurent@smartadserver[1].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
          C:\Documents and Settings\laurent\Cookies\laurent@statcounter[1].txt -> TrackingCookie.Statcounter : Aucune action entreprise.
          :mozilla.28:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
          :mozilla.29:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
          :mozilla.30:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
          :mozilla.59:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
          C:\Documents and Settings\laurent\Cookies\laurent@weborama[1].txt -> TrackingCookie.Weborama : Aucune action entreprise.
          :mozilla.36:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.
          :mozilla.37:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.
          :mozilla.39:C:\Documents and Settings\laurent\Application Data\Mozilla\Firefox\Profiles\fv9i0zt7.laurent\cookies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.

          Fin du rapport
          0
          1. Contributeur sécurité
            as tu appliqué les actions avec AVG ou non ?
            0
            1. oui j'ai appliqué donc supprimer!!!
              0
              1. Contributeur sécurité
                ok et tjs les mêmes soucis ?

                * Fait un scan antivirus en ligne avec Internet Explorer
                https://www.bitdefender.fr/
                et copie colle le résultat ici
                * En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
                * Dans la nouvelle fenêtre, clique sur I agree
                * La fenêtre change encore, clique sur Click here to scan
                * Les signatures se chargent, etc.

                tuto en image

                http://pageperso.aol.fr/rginformatique/mapage/defender.htm
                0
                1. toujours les memes souci je fais un bit defender!! sinon mon hitajick il est ok ou pas ?
                  0
                  1. Contributeur sécurité
                    il y aura 2 lignes inutiles à virer mais on ne voit rien d'autre

                    fait le scan bitdefender

                    0
                    1. oki c entrain de se faire a plus tard si tu es couché!! bonne nuit en cas ou et merci a toi
                      0
                      1. Contributeur sécurité
                        ok la suite très certainement demain suivant la durée de ton scan

                        je serais là demain soir
                        0
                        1. je poste le sacn bit defender je pense demain matin!! je serais de retour que ds 1 semaines!!! pour prendre la suite car vacances oblige!!! merci qd meme et je te dis a dans une semaine..tchoussss
                          0
                          1. Contributeur sécurité
                            ok bonnes vacances alors
                            0
                            1. Voila j'ai posté il me trouve rien c pas normale lollllll merci qd meme j'attends de tes news tchoussss

                              BitDefender Online Scanner

                              Rapport d'analyse généré à: Thu, Dec 27, 2007 - 00:55:37

                              Voie d'analyse: C:\;D:\;E:\;F:\;G:\;H:\;I:\;J:\;K:\;L:\;

                              Statistiques

                              Secteurs de boot

                              6

                              Archives

                              21640

                              Paquets programmes

                              35656

                              Résultats

                              Virus identifiés

                              0

                              Fichiers infectés

                              0

                              Fichiers suspects

                              0

                              Avertissements

                              0

                              Désinfectés

                              0

                              Fichiers effacés

                              0

                              Info sur les moteurs

                              Définition virus

                              884350

                              Version des moteurs

                              AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

                              Analyse des plugins

                              14

                              Archive des plugins

                              38

                              Unpack des plugins

                              7

                              E-mail plugins

                              6

                              Système plugins

                              1

                              Paramètres d'analyse

                              Première action

                              Désinfecté

                              Seconde Action

                              Supprimé

                              Heuristique

                              Oui

                              Acceptez les avertissements

                              Oui

                              Extensions analysées

                              *;

                              Excludez les extensions

                              Analyse d'emails

                              Oui

                              Analyse des Archives

                              Oui

                              Analyser paquets programmes

                              Oui

                              Analyse des fichiers

                              Oui

                              Analyse de boot

                              Oui

                              Fichier analysé

                              Statut

                              Aucun virus trouvé.
                              0
                              1. Contributeur sécurité
                                bonsoir,

                                donc ras dans ce rapport. Je pense que côté infectieux c'est bon maintenant il faudrait creuser, peut être voir à faire un défrag si tu trouves ton pc lent.
                                Combien de mémoire de ram as tu ?

                                * lance hijackthis "do a system scan only" puis coche ces lignes :

                                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
                                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                O20 - Winlogon Notify: tapiperf32 - tapiperf32.dll (file missing)

                                * toutes applications fermées et HORS CONNEXION, clique sur FIX CHECKED

                                tu n'es pas à jour avec ADOBE READER

                                Acrobat Reader 8.1.1 :
                                https://supportdownloads.adobe.com/thankyou.jsp?ftpID=3806&fileID=3534
                                Décocher Téléchargez également :Adobe Photoshop® Album Édition
                                Dans Ajout/Suppression des programmes tu supprimes toutes les autres versions.
                                Tu peux aussi le remplacer par :
                                https://www.foxitsoftware.com/pdf-reader/
                                Dans Ajout/Suppression des programmes, supprime toutes les autres versions.

                                0
                                1. merci de ta reponse et bonne annee a toi et a vous tous!!!
                                  je vais faire ce que tu m'as dis et essayer de faire une defrag!!!
                                  j'ai des soucis avec explorer et se ferme regulierement apres avoir eu une erreur!!!
                                  sinon une autre question si je peux me permettre pour retrouver sa base de registre en "configuration d'usine" comment fais t'on ??
                                  MERCI
                                  0
                                  1. Contributeur sécurité
                                    bonsoir, et bonne année à toi également

                                    pour explorer qui se ferme, il faut voir dans le forum xp, ce n'est pas mon domaine, et il peut y avoir pas mal de raisons (en tout cas pas infectieuse) c'est un peu la "chienlit" d'ailleurs. Préfère ne pas m'y aventurer
                                    pour la config d'origine uniquement pour la BDR....suis pas certaine que ce soit possible il faut retourner à la case départ pour tout à mon avis, mais à demander sur XP aussi.

                                    0
                                    1. re
                                      merci de tes conseils je vais aller voir pour me renseigner bonne journee et a la prochaine et encore merci. tchousssssssssss
                                      0
                                      1. Contributeur sécurité
                                        ok, bonne journée
                                        0