Probleme ordinateur packard bell

Bonsoir, j'ai un probleme avec mon ordinateur packard bell carte graphique nvidia geforce GO 6100.
Je ne sais pas si c'est a cause d'un virus ou quoi que ce soit mais l'ordinateur 'rame' il met longtemps a s'allumer, a s'éteindre, a ouvrir une page internet...
Il y a beaucoup de musiques sur cet ordinateur, environ 5 Giga de mémoire rien qu'en musiques, enfin je ne sais pas a quoi c'est due...
En éspérant de l'aide, a bientot.
cordialement.
Configuration: Windows Vista Internet Explorer 7.0

27 réponses

Résumé de la discussion

Le problème concerne un PC Packard Bell sous Windows Vista doté d'une carte graphique Nvidia GeForce GO 6100 présentant un ralentissement généralisé et une accumulation de fichiers musicaux d'environ 5 Go. Des rapports UsbFix et navilog signalent des éléments malveillants et des entrées Run persistantes, laissant penser à une infection et à la nécessité d'un nettoyage avant toute défragmentation. La meilleure réponse suggère d'utiliser Malwarebytes Anti-Malware pour un scan complet, de supprimer les objets détectés et de redémarrer, puis de partager le rapport pour une aide complémentaire. D'autres échanges soulignent la nécessité de vérifier les entrées Run et les fichiers signalés par les rapports, afin d'éviter de supprimer des éléments légitimes et d'évaluer systématiquement les causes du ralentissement.

Bobot (l’IA à votre service)
  1. ok, je ferai ça cette aprém midi... merci ^^
    0
    1. Contributeur sécurité
      bonjour, le rapport de navilog ne me semble pas complet tu as bien fais l'option 1 car vu ce que toolbar nous montre comme autres infection, cela navilog aurait du le supprimer
      --------------------\\ Recherche d'autres infections 
      
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
      "wgcuuu"="c:\\users\\julie\\appdata\\local\\wgcuuu.exe wgcuuu" 
      
      C:\Windows\System32\nvs2.inf 
      
      C:\Users\Julie\AppData\Local\wgcuuu.dat 
      C:\Users\Julie\AppData\Local\wgcuuu_nav.dat 
      C:\Users\Julie\AppData\Local\wgcuuu_navps.dat 
      C:\Users\Julie\AppData\Local\wgcuuu_navup.dat 
      [b]==> EGDACCESS <==/b 
      


      tu peux regarder dans ton disque dure C si tu ne retrouve pas le rapport de navilog il porte le nom de cleannavi.txt tu le postes en entier , merci

      et puis tu passeras malwarebytes il devrait lui aussi le virer cette merde de wgcuuu

      Télécharge Malwarebytes' Anti-Malware: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

      . sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
      . enregistres le sur le bureau
      . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
      . si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
      . rend-toi dans l'onglet, Recherche
      . Sélectionnes Exécuter un examen complet
      . Cliques sur Rechercher
      . Le scan démarre.
      . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
      . Cliques sur Ok pour poursuivre.
      . Si des malwares ont été détectés, cliques sur Afficher les résultats
      . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
      . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
      . redemarre le pc si il le fait pas lui même
      . une fois redémarré double-cliques sur malwarebytes
      . rends toi dans l'onglet rapport/log
      . tu cliques dessus pour l'afficher une fois affiché
      . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
      . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
      . tu cliques droit dans le cadre de la reponse et coller

      Si tu as besoin d'aide regarde ce tutoriel :
      https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
      0
      1. voila j'ai tout posté dans l'ordre et j'attend tes réponses ^^, en tout cas merci pour toutes tes réponses, mais pour l'instant aucun changement, il rame toujours autant...
        0
        1. Logfile of random's system information tool 1.06 (written by random/random)
          Run by Julie at 2009-09-15 21:46:18
          Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
          System drive C: has 60 GB (57%) free of 106 GB
          Total RAM: 895 MB (23% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 21:46:57, on 15/09/2009
          Platform: Windows Vista SP1 (WinNT 6.00.1905)
          MSIE: Internet Explorer v7.00 (7.00.6001.18294)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\conime.exe
          C:\Windows\explorer.exe
          C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
          C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Windows Live\Toolbar\wltuser.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Users\Julie\Desktop\RSIT.exe
          C:\Program Files\trend micro\Julie.exe

          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - Default URLSearchHook is missing
          O1 - Hosts: ::1 localhost
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
          O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
          O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
          O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [MediaBarFileManager] C:\Program Files\On Demand Distribution\OD2 Music Manager\OD2MediaBar_VistaFileManager.exe
          O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\windows sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [wgcuuu] c:\users\julie\appdata\local\wgcuuu.exe wgcuuu
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
          O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
          O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Julie\Program Files\DNA\btdna.exe"
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')
          O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
          O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
          O4 - Global Startup: OFFICE One Startup v7.lnk = ?
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
          O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
          O13 - Gopher Prefix:
          O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
          O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
          O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\Windows\system32\CTsvcCDA.exe
          O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
          O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
          O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
          O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkSrv.exe
          O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
          0
          1. ############################## | UsbFix V6.033 |

            User : Julie (Administrateurs) # PC-DE-JULIE
            Update on 14/09/2009 by Chiquitine29, C_XX & Chimay8
            Start at: 21:27:16 | 15/09/2009
            Website : http://pagesperso-orange.fr/NosTools/index.html

            AMD Turion(tm) 64 X2 Mobile Technology TL-50
            Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
            Internet Explorer 7.0.6001.18000
            Windows Firewall Status : Enabled
            AV : avast! antivirus 4.8.1201 [VPS 090914-0] 4.8.1201 [ Enabled | Updated ]

            C:\ -> Disque fixe local # 103,78 Go (58,33 Go free) [HDD] # NTFS

            ############################## | Processus actifs |

            C:\Windows\System32\smss.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\SLsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\ATK Hotkey\ASLDRSrv.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\Program Files\ATK Hotkey\Hcontrol.exe
            C:\Windows\system32\Dwm.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\ATK Hotkey\ATKOSD.exe
            C:\Windows\System32\spoolsv.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\CTsvcCDA.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\StkSrv.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\SearchIndexer.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Windows\system32\runonce.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
            C:\Windows\system32\PresentationSettings.exe
            C:\Windows\system32\conime.exe
            C:\Windows\system32\wbem\wmiprvse.exe
            C:\Windows\system32\WerCon.exe

            ################## | Fichiers # Dossiers infectieux |

            ################## | Registre # Clés Run infectieuses |

            ################## | Registre # Mountpoints2 |

            Supprimé ! HKCU\...\Explorer\MountPoints2\F\Shell\AutoRun\Command
            Supprimé ! HKCU\...\Explorer\MountPoints2\{95514afd-69b7-11dc-8192-00038a000015}\Shell\AutoRun\Command
            Supprimé ! HKCU\...\Explorer\MountPoints2\{a4097e6f-38fa-11dc-af8f-00038a000015}\Shell\AutoRun\Command
            Supprimé ! HKCU\...\Explorer\MountPoints2\{f1cf69f1-b273-11dd-a006-00038a000015}\Shell\Auto\Command

            ################## | Listing des fichiers présent |

            [18/09/2006 23:43|--a------|24] C:\autoexec.bat
            [19/01/2008 09:45|-rahs----|333203] C:\bootmgr
            [23/04/2007 22:26|-ra-s----|8192] C:\BOOTSECT.BAK
            [15/09/2009 20:38|--a------|734] C:\cleannavi.txt
            [18/09/2006 23:43|--a------|10] C:\config.sys
            [15/09/2009 20:38|--a------|8] C:\fixnavi.txt
            [23/04/2007 13:26|--ah-----|1785] C:\IPH.PH
            [?|?|?] C:\pagefile.sys
            [23/04/2007 13:10|--a------|335] C:\RHDSetup.log
            [15/09/2009 21:14|--a------|2172] C:\TB.txt
            [15/09/2009 21:40|--a------|3440] C:\UsbFix.txt

            ################## | ! Fin du rapport # UsbFix V6.033 ! |
            0
            1. ############################## | UsbFix V6.033 |

              User : Julie (Administrateurs) # PC-DE-JULIE
              Update on 14/09/2009 by Chiquitine29, C_XX & Chimay8
              Start at: 21:18:31 | 15/09/2009
              Website : http://pagesperso-orange.fr/NosTools/index.html

              AMD Turion(tm) 64 X2 Mobile Technology TL-50
              Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
              Internet Explorer 7.0.6001.18000
              Windows Firewall Status : Enabled
              AV : avast! antivirus 4.8.1201 [VPS 090914-0] 4.8.1201 [ Enabled | Updated ]

              C:\ -> Disque fixe local # 103,78 Go (58,41 Go free) [HDD] # NTFS

              ############################## | Processus actifs |

              C:\Windows\System32\smss.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\ATK Hotkey\ASLDRSrv.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\ATK Hotkey\Hcontrol.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Program Files\ATK Hotkey\ATKOSD.exe
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              C:\Windows\RtHDVCpl.exe
              C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\System32\spoolsv.exe
              C:\Program Files\Alwil Software\Avast4\ashDisp.exe
              C:\Program Files\On Demand Distribution\OD2 Music Manager\OD2MediaBar_VistaFileManager.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\Picasa2\PicasaMediaDetector.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Windows\ehome\ehtray.exe
              C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\Users\Julie\Program Files\DNA\btdna.exe
              C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
              C:\Windows\System32\rundll32.exe
              C:\Windows\system32\CTsvcCDA.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
              C:\Windows\ehome\ehmsas.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\StkSrv.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\SearchIndexer.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
              C:\Windows\system32\conime.exe
              C:\Windows\system32\wuauclt.exe
              C:\Program Files\Java\jre6\bin\jucheck.exe
              C:\Program Files\Internet Explorer\ieuser.exe
              C:\Program Files\Windows Live\Toolbar\wltuser.exe
              C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
              C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
              C:\Windows\system32\wbem\wmiprvse.exe

              ################## | Fichiers # Dossiers infectieux |

              ################## | Registre # Clés Run infectieuses |

              ################## | Registre # Mountpoints2 |

              HKCU\..\..\Explorer\MountPoints2\F
              shell\AutoRun\command =F:\LaunchU3.exe -a

              HKCU\..\..\Explorer\MountPoints2\{95514afd-69b7-11dc-8192-00038a000015}
              shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs

              HKCU\..\..\Explorer\MountPoints2\{a4097e6f-38fa-11dc-af8f-00038a000015}
              shell\AutoRun\command =F:\LaunchU3.exe -a

              HKCU\..\..\Explorer\MountPoints2\{f1cf69f1-b273-11dd-a006-00038a000015}
              shell\Auto\command =AdobeR.exe e
              shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL E:\

              ################## | ! Fin du rapport # UsbFix V6.033 ! |
              0
              1. 2éme rapport de toolbar :

                -----------\\ ToolBar S&D 1.2.9 XP/Vista

                Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                X86-based PC ( Multiprocessor Free : AMD Turion(tm) 64 X2 Mobile Technology TL-50 )
                BIOS : Default System BIOS
                USER : Julie ( Administrator )
                BOOT : Normal boot
                Antivirus : avast! antivirus 4.8.1201 [VPS 090914-0] 4.8.1201 (Activated)
                C:\ (Local Disk) - NTFS - Total:103 Go (Free:58 Go)

                "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
                Option : [2] ( 15/09/2009|21:11 )

                [ UAC => 1 ]

                -----------\\ SUPPRESSION

                Supprime! - C:\Program Files\AskBarDis\bar
                Supprime! - C:\Program Files\AskBarDis\unins000.dat
                Supprime! - C:\Program Files\AskBarDis\unins000.exe
                Supprime! - C:\Users\Julie\AppData\Local\Temp\nsc2484.tmp
                Supprime! - C:\Program Files\AskBarDis

                -----------\\ Recherche de Fichiers / Dossiers ...

                -----------\\ [..\Internet Explorer\Main]

                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                "Local Page"="C:\\Windows\\system32\\blank.htm"
                "Search Page"="https://www.google.com/?gws_rd=ssl"
                "Start Page"="https://www.google.fr/?gws_rd=ssl"
                "Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
                "Url"="https://www.msn.com/fr-fr/actualite/"

                [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                "Start Page"="https://www.msn.com/fr-fr/"
                "Default_Page_URL"="https://www.google.com/?gws_rd=ssl"
                "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

                --------------------\\ Recherche d'autres infections

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "wgcuuu"="c:\\users\\julie\\appdata\\local\\wgcuuu.exe wgcuuu"

                C:\Windows\System32\nvs2.inf

                C:\Users\Julie\AppData\Local\wgcuuu.dat
                C:\Users\Julie\AppData\Local\wgcuuu_nav.dat
                C:\Users\Julie\AppData\Local\wgcuuu_navps.dat
                C:\Users\Julie\AppData\Local\wgcuuu_navup.dat
                [b]==> EGDACCESS <==/b

                [ UAC => 1 ]

                1 - "C:\ToolBar SD\TB_1.txt" - 15/09/2009|21:14 - Option : [2]

                -----------\\ Fin du rapport a 21:14:31,92
                0
                1. voila pour le 2éme rapport de toolbart :
                  -----------\\ ToolBar S&D 1.2.9 XP/Vista

                  Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                  X86-based PC ( Multiprocessor Free : AMD Turion(tm) 64 X2 Mobile Technology TL-50 )
                  BIOS : Default System BIOS
                  USER : Julie ( Administrator )
                  BOOT : Normal boot
                  Antivirus : avast! antivirus 4.8.1201 [VPS 090914-0] 4.8.1201 (Activated)
                  C:\ (Local Disk) - NTFS - Total:103 Go (Free:58 Go)

                  "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
                  Option : [1] ( 15/09/2009|21:08 )

                  [ UAC => 1 ]

                  -----------\\ Recherche de Fichiers / Dossiers ...

                  C:\Program Files\AskBarDis
                  C:\Program Files\AskBarDis\bar
                  C:\Program Files\AskBarDis\unins000.dat
                  C:\Program Files\AskBarDis\unins000.exe
                  C:\Program Files\AskBarDis\bar\bin
                  C:\Program Files\AskBarDis\bar\Settings
                  C:\Program Files\AskBarDis\bar\bin\askBar.dll
                  C:\Program Files\AskBarDis\bar\bin\askPopStp.dll
                  C:\Program Files\AskBarDis\bar\bin\psvince.dll
                  C:\Program Files\AskBarDis\bar\Settings\config.dat
                  C:\Program Files\AskBarDis\bar\Settings\config.dat.bak
                  C:\Users\Julie\AppData\Local\Temp\nsc2484.tmp

                  -----------\\ [..\Internet Explorer\Main]

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                  "Local Page"="C:\\Windows\\system32\\blank.htm"
                  "Search Page"="https://www.google.com/?gws_rd=ssl"
                  "Start Page"="https://www.google.fr/?gws_rd=ssl"
                  "Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
                  "Url"="https://www.msn.com/fr-fr/actualite/"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                  "Start Page"="https://www.google.com/?gws_rd=ssl"
                  "Default_Page_URL"="https://www.google.com/?gws_rd=ssl"
                  "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                  "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

                  --------------------\\ Recherche d'autres infections

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "wgcuuu"="c:\\users\\julie\\appdata\\local\\wgcuuu.exe wgcuuu"

                  C:\Windows\System32\nvs2.inf
                  0
                  1. pour le 1er raport :
                    Fix Navipromo version 4.0.2 commencé le 15/09/2009 20:38:14,92

                    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                    !!! Postez ce rapport sur le forum pour le faire analyser !!!

                    Outil exécuté depuis C:\Program Files\navilog1

                    Mise à jour le 27.08.2009 à 11h00 par IL-MAFIOSO

                    Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                    X86-based PC ( Multiprocessor Free : AMD Turion(tm) 64 X2 Mobile Technology TL-50 )
                    BIOS : Default System BIOS
                    USER : Julie ( Administrator )
                    BOOT : Normal boot

                    Antivirus : avast! antivirus 4.8.1201 [VPS 090914-0] 4.8.1201 (Activated)

                    C:\ (Local Disk) - NTFS - Total:103 Go (Free:58 Go)

                    Recherche executée en mode normal

                    désolé si je suis long mais bon je fais comme je peux je fini de travailler assez tard...
                    sinon je ne suis pas bouch ^^ je te suis toi tkt !
                    0
                    1. Contributeur sécurité
                      blaireau c'est toi qui est arrivé avec ta tronche en fariné si tu reprends la chronologie des discutions
                      https://forums.commentcamarche.net/forum/affich-14369852-probleme-ordinateur-packard-bell#1
                      tu arrives que avec le message 5 ??? https://forums.commentcamarche.net/forum/affich-14369852-probleme-ordinateur-packard-bell#5

                      bon pas de problème si tu te sens de tailles pour faire la désinfection je te laisse ma place tu vois cela avec masterblack si il te suit ou pas sur ce bonne nuit
                      0
                      1. merci pour ces réponses je fais un bout ce soir, mais je continuerai ton 'programme de débugage ^^' demain... je posterai les rapports demain aussi
                        0
                        1. Contributeur sécurité
                          le bouch soit tu sais ou tu cherche moi non plus j'ai pas de vista à la maison et pourtant 8 pc et quand je sais pas je recherche pour aider : http://blogs.developpeur.org/...
                          0
                          1. ecoute j essaye de l aider avant de me traiter de (baireau) je suppose blaireau vas voir sur un forum de politesse et apprent a dire bonsoir quant tu t introduit dans une conversation
                            0
                            1. Contributeur sécurité
                              le baireau " bouch " même après une défragmentations et ccleaner tu fais quoi de cela :

                              O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                              O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                              O4 - HKCU\..\Run: [wgcuuu] c:\users\julie\appdata\local\wgcuuu.exe wgcuuu
                              AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-09-29 325000]
                              {3041d03e-fd4b-44e0-b742-2d9b88305f98} - Ask Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-09-29 325000]
                              shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs
                              shell\Auto\command - AdobeR.exe e

                              [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
                              [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
                              [-HKEY_CLASSES_ROOT\CLSID\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
                              [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                              "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"=-
                              [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                              "wgcuuu"=-

                              c:\program files\askbardis\bar\bin\askbar.dll
                              c:\users\julie\appdata\local\wgcuuu.exe
                              c:\windows\system32\rundll32.exe
                              0
                              1. sous vista je connait pas trop mais tu vas suur l icone de vista en bas a gauche sur ton bureau puis si tu as tu fait tout les programmes apres accessoires puis outils systeme et defragmentation t inquiete pas ca ne t enleveras aucun dossiers ca sert juste a bien les ranger sur ton disque dur comme ca apres ca vas plus vite pour les ouvrir
                                0
                                1. Contributeur sécurité
                                  bon tu as du monde sur ton pc !!!

                                  tu as avast sur ton pc et norton 2 anti-virus c'est pas bon pour le pc et en plus les plus mauvais , mais bon c'est ton pc

                                  si tu n'utilises plus norton passes cet outil car il est pas désinstaller convenablement http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924

                                  et après tu passeras les 3 outils qui suivent c'est à dire navilog, toolbar S&D et usbfix et tu posteras un nouveau RSIT pour faire le point , Merci

                                  ps: tu postes les différents rapport au fure et à mesure , Merci

                                  1) pour navilog

                                  Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                                  - Va dans démarrer puis panneau de configuration
                                  - Double Clique sur l'icône "Comptes d'utilisateurs"
                                  - Clique ensuite sur désactiver et valide.

                                  Télécharge maintenant Navilog1 depuis-ce lien :

                                  http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

                                  Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
                                  Ensuite double clique sur navilog1.exe pour lancer l'installation.
                                  Une fois l'installation terminée, Fais un Clic-droit sur le raccourci Navilog1 présent sur ton bureau et choisis "Exécuter

                                  en tant qu'administrateur".

                                  Au menu principal, Fais le choix 1
                                  Laisse toi guider et patiente.
                                  Patiente jusqu'au message :
                                  *** Analyse Termine le ..... ***
                                  Appuie sur une touche le blocnote va s'ouvrir.
                                  Copie-colle l'intégralité du rapport dans une réponse.
                                  Referme le blocnote
                                  Le rapport cleannavi.txt est en outre sauvegardé dans C:(cleannavi.txt)

                                  pour comprendre: http://www.malekal.com/Adware.Magic_Control.php

                                  2) pour toolbar S&D

                                  Télécharge ToolBar-S&D ( Merci à Eric_71, Angeldark, Sham_Rock et XmichouX )
                                  https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cpVobGk5bHnxrhQ4yaoEUDJvOYNnEGyYjgqHZz5GqZLfutR3fMFPlsC3-CGIilfupPAguYATNyua3csodN_frdMK8sSzUpit10Yac-QJCOkMqJKkbdKcP6ySs8trWPgoNVIq4TGGWCe6o0txXQv-ZueJF9vZzw3RXsGwFYIqN2lvF2LPdQzS8mE1d5kWOVOz6EMzQuE5-lClSJM869uq3oc7-t7yg%3D%3D&attredirects=3

                                  Lances l'installation du programme en exécutant le fichier téléchargé.
                                  Double-clique maintenant sur le raccourci de Toolbar-S&D.
                                  Sélectionnes la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
                                  Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
                                  Postes le rapport généré. (C:\TB.txt)

                                  Suppression option 2

                                  Relance Toolbar-S&D en double-cliquant sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".
                                  ! Ne ferme pas la fenêtre lors de la suppression !
                                  Un rapport sera généré, poste son contenu ici.

                                  NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
                                  Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
                                  Tape explorer puis valide.

                                  Aide en images: https://sites.google.com/site/toolbarsd/aideenimages

                                  3) passes Usbfix

                                  • Telecharge et install http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe UsbFix de C_XX & Chiquitine29

                                  (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                                  • Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisis "éxécuter en tant qu'administrateur" .

                                  • Choisis l'option 1 ( Recherche )

                                  • Laisse travailler l outil.

                                  • Ensuite post le rapport UsbFix.txt qui apparaitra.

                                  • Note : Le rapport UsbFix.txt est sauvegardé à la racine du disque. ( C:\UsbFix.txt )

                                  ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                  • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                                  Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                                  Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                                  • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

                                  ##################### | Vista _ Suppression | ########################

                                  (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectées sans les ouvrir

                                  • Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisis "éxécuter en tant qu'administrateur" .

                                  • choisi l'option 2 ( Suppression )

                                  • Ton bureau disparaitra et le pc redémarrera .

                                  • Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

                                  • Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

                                  • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                                  ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                  .UsbFix te proposera d'uploader un dossier compressé à cette adresse : https://www.androidworld.fr/

                                  Ce dossier a été créé par UsbFix et est enregistré sur ton bureau.

                                  Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

                                  Merci d'avance pour ta contribution !!

                                  ##################### | Vista _ Désinstallation | QU'UNE FOIS LES RAPPORTS POSTER

                                  • Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisi "éxécuter en tant qu'administrateur" .

                                  • Choisis l'option 5 ( Désinstaller ) ....

                                  4) relances RSIT et postes le log.txt
                                  0
                                  1. je ne m'y connait pas trop en informatique, comment font-on une défragmentation ? suivis de ce que tu a dis... et la défragementation permet quand même de garder mes musiques et tout mes fichiers ?
                                    0
                                    1. fait un defragmentation puis nettoie acec c cleanner
                                      0
                                      • 1
                                      • 2