MON ORDI RAME

bonjour
mon ordi rame anormalement quand je suis sur internet
pouvez vous m'aider
merci

53 réponses

Résumé de la discussion

Le problème décrit concerne un ordinateur fonctionnant sous Windows XP avec Firefox 3.5.9 qui rame significativement lors de la navigation sur Internet et pose des questions d'ordre sécurité et performances. Plusieurs réponses suggèrent d'analyser l'usage des ressources pendant la navigation sur Internet via le gestionnaire des tâches et l'onglet Performance, et de nettoyer le système avec CCleaner, et de vérifier l'absence de malwares. D'autres proposent d'examiner le matériel et l'historique du système, telles que la défragmentation, le nettoyage des disques et les éventuels antécédents de formatage, puis d'observer l'impact des données temporaires sur les performances.

Bobot (l’IA à votre service)
  1. oui, j'ai la même lenteur, avec internet explorer
    je t'enverrai une demande dans ta boite mail pour savoir ce que t'enpenses
    1. JE suis absent pendant 15JOURS, je me permettrai de te recontacter dans 15J,
      merci
      1. Contributeur sécurité
        derniere question

        avec le navigateur internet explorer, as tu les mêmes soucis de lenteur ?
    2. .text ntkrnlpa.exe!FsRtlCheckLockForReadAccess 804E9FA0 5 Bytes JMP F43B74DC \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)
      .text ntkrnlpa.exe!IoIsOperationSynchronous 804EE87E 5 Bytes JMP F43B78B6 \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)
      .text ntkrnlpa.exe!ZwCallbackReturn + 2434 80501C6C 16 Bytes [4E, 23, 3C, F4, C6, 3F, 3C, ...]
      .text ntkrnlpa.exe!ZwCallbackReturn + 24F0 80501D28 12 Bytes [8C, 56, 3C, F4, 12, 14, 3C, ...] {MOV WORD [ESI+0x3c], SS; HLT ; ADC DL, [ESP+EDI]; HLT ; AND AL, 0x14; CMP AL, 0xf4}
      .text ntkrnlpa.exe!ZwCallbackReturn + 266C 80501EA4 16 Bytes [0E, 1B, 3C, F4, B0, 12, 3C, ...]
      .text ntkrnlpa.exe!ZwCallbackReturn + 2760 80501F98 12 Bytes [F8, 61, 3C, F4, 20, 63, 3C, ...]
      .text ntkrnlpa.exe!ZwCallbackReturn + 27C0 80501FF8 4 Bytes JMP 44F43C29
      .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF6DE1360, 0x221CFD, 0xE8000020]
      ? C:\DOCUME~1\GLEYSES\LOCALS~1\Temp\mbr.sys Le fichier spécifié est introuvable. !

      ---- Kernel IAT/EAT - GMER 1.0.15 ----

      IAT \SystemRoot\system32\DRIVERS\tcpip.sys[TDI.SYS!TdiRegisterDeviceObject] [F3E9D820] \??\C:\WINDOWS\system32\drivers\kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
      IAT \SystemRoot\system32\DRIVERS\netbt.sys[TDI.SYS!TdiRegisterDeviceObject] [F3E9D820] \??\C:\WINDOWS\system32\drivers\kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
      IAT \SystemRoot\system32\DRIVERS\tcpip6.sys[TDI.SYS!TdiRegisterDeviceObject] [F3E9D820] \??\C:\WINDOWS\system32\drivers\kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
      IAT \SystemRoot\system32\DRIVERS\nwlnkipx.sys[TDI.SYS!TdiRegisterDeviceObject] [F3E9D820] \??\C:\WINDOWS\system32\drivers\kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
      IAT \SystemRoot\system32\DRIVERS\nwlnknb.sys[TDI.SYS!TdiRegisterDeviceObject] [F3E9D820] \??\C:\WINDOWS\system32\drivers\kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
      IAT \SystemRoot\system32\DRIVERS\nwlnkspx.sys[TDI.SYS!TdiRegisterDeviceObject] [F3E9D820] \??\C:\WINDOWS\system32\drivers\kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)

      ---- Devices - GMER 1.0.15 ----

      AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
      AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
      AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
      AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)

      Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)

      AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

      ---- Registry - GMER 1.0.15 ----

      Reg HKLM\SOFTWARE\Classes\CLSID\{11B5C8DC-3FEA-1682-D4F0355518481497}\{414E0745-768E-27E6-1A22BEEA50FFC306}\{0F77990A-A8C5-E83C-A2DEB9098A2A23DE}
      Reg HKLM\SOFTWARE\Classes\CLSID\{11B5C8DC-3FEA-1682-D4F0355518481497}\{414E0745-768E-27E6-1A22BEEA50FFC306}\{0F77990A-A8C5-E83C-A2DEB9098A2A23DE}@WVZENWCHWFKXMRXM1FQWBAYGMD1 0x01 0x00 0x01 0x00 ...
      Reg HKLM\SOFTWARE\Classes\CLSID\{66D2B6B0-0AC3-1D5E-AFE4FCFC2DBC1E0D}\{D0054572-6CDD-7E67-D144F5B82EF8A509}\{800AEEDD-FDE9-D9F6-54124DEBF6D799D2}
      Reg HKLM\SOFTWARE\Classes\CLSID\{66D2B6B0-0AC3-1D5E-AFE4FCFC2DBC1E0D}\{D0054572-6CDD-7E67-D144F5B82EF8A509}\{800AEEDD-FDE9-D9F6-54124DEBF6D799D2}@WVZENWCHWFKXMRXM1FQWBAYGMD1 0x01 0x00 0x01 0x00 ...

      ---- EOF - GMER 1.0.15 ----
      1. GMER 1.0.15.15281 - http://www.gmer.net
        Rootkit scan 2010-04-18 13:38:00
        Windows 5.1.2600 Service Pack 3
        Running: gmer.exe; Driver: C:\DOCUME~1\GLEYSES\LOCALS~1\Temp\pwldyfod.sys

        ---- System - GMER 1.0.15 ----

        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0xF43C258C]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwClose [0xF43C2E0C]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwConnectPort [0xF43C3922]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateEvent [0xF43C3E94]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateFile [0xF43C30EE]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateKey [0xF43C1436]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateMutant [0xF43C3D6C]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0xF43C2192]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreatePort [0xF43C3C28]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSection [0xF43C234E]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSemaphore [0xF43C3FC6]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xF43C5C08]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateThread [0xF43C2AAA]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateWaitablePort [0xF43C3CCA]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDebugActiveProcess [0xF43C55FA]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteKey [0xF43C19FA]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteValueKey [0xF43C1D88]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeviceIoControlFile [0xF43C3576]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDuplicateObject [0xF43C65CA]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateKey [0xF43C1ECA]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateValueKey [0xF43C1F74]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwFsControlFile [0xF43C3382]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadDriver [0xF43C568C]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey [0xF43C1412]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey2 [0xF43C1424]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwMapViewOfSection [0xF43C5CBC]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwNotifyChangeKey [0xF43C20C0]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenEvent [0xF43C3F36]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenFile [0xF43C2E8E]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenKey [0xF43C15DC]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenMutant [0xF43C3E04]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenProcess [0xF43C2792]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSection [0xF43C5C32]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSemaphore [0xF43C4068]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenThread [0xF43C26B6]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryKey [0xF43C201E]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryMultipleValueKey [0xF43C1C46]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQuerySection [0xF43C5FD4]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryValueKey [0xF43C1896]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueueApcThread [0xF43C5922]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRenameKey [0xF43C1B0E]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplaceKey [0xF43C12B0]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyPort [0xF43C43F2]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0xF43C42B8]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0xF43C539A]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRestoreKey [0xF43C8E2C]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwResumeThread [0xF43C64AC]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSaveKey [0xF43C1248]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSecureConnectPort [0xF43C365C]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetContextThread [0xF43C2CC8]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetInformationToken [0xF43C4C4A]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSecurityObject [0xF43C5786]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSystemInformation [0xF43C6114]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetValueKey [0xF43C171E]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendProcess [0xF43C61F8]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendThread [0xF43C6320]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSystemDebugControl [0xF43C5526]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateProcess [0xF43C290A]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateThread [0xF43C2860]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0xF43C5E8A]
        SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0xF43C29EA]

        Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) FsRtlCheckLockForReadAccess
        Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) IoIsOperationSynchronous

        ---- Kernel code sections - GMER 1.0.15 ----
        1. Contributeur sécurité
          (sourire)

          n'étant pas chez moi, je ne pourrai le récuprer de suite...

          s'il n'est pas trop long postes le en deux fois stp
          1. je t'ai envoyé le rapport sur ta messagerie
            car ici , ça ne passe pas visiblement
            1. Contributeur sécurité
              je ne vois toujours pas plus d'infection

              /!\ Il faut impérativement désactiver tous tes logiciels de protection pour utiliser ce programme/!\

              ? Télécharge : Gmer (by Przemyslaw Gmerek)

              http://www.gmer.net/

              ? Dezippe gmer ,cliques sur l'onglet rootkit,lances le scan,des lignes rouges vont apparaitre.

              ? Les lignes rouges indiquent la presence d'un rootkit.Postes moi le rapport gmer (cliques sur copy,puis vas dans demarrer ,puis ouvres le bloc note,vas dans edition et cliques sur coller,le rapport gmer va apparaitre,postes moi le)

              1. Contributeur sécurité
                envoies le moi à l'adresse mail indiquée sur mon profil
                1. j'ai essayé mais quand je clique sur creer le lien la page se charge indefiniment
                  je patiente encore
                  1. je t'adresse le rapport du clean avec kill'em
                    Kill'em by g3n-h@ckm@n 1.7.1.1

                    User : GLEYSES (Administrateurs)
                    Update on 17/04/2010 by g3n-h@ckm@n ::::: 17.10
                    Start at: 10:25:24 | 18/04/2010

                    Mobile AMD Sempron(tm) Processor 3400+
                    Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                    Internet Explorer 7.0.5730.11
                    Windows Firewall Status : Disabled
                    AV : Kaspersky Internet Security 9.0.0.736 [ Enabled | Updated ]
                    FW : Kaspersky Internet Security[ Enabled ]9.0.0.736

                    C:\ -> Disque fixe local | 65,74 Go (49,9 Go free) | NTFS
                    D:\ -> Disque fixe local | 43,69 Go (43,69 Go free) | FAT32
                    E:\ -> Disque CD-ROM

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                    ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                    Quarantined & Deleted !! : C:\WINDOWS\002895_.tmp

                    Quarantined & Deleted !! : C:\WINDOWS\System32\SynSvc_.exe
                    Quarantined & Deleted !! : C:\WINDOWS\TEMP\scs1.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\TEMP\scs2.tmp
                    Quarantined & Deleted !! : C:\Documents and Settings\GLEYSES\Application Data\wklnhst.dat
                    Quarantined & Deleted !! : C:\Documents and Settings\GLEYSES\Local Settings\Temp\87B.tmp
                    Quarantined & Deleted !! : C:\Documents and Settings\GLEYSES\Local Settings\Temp\87C.tmp
                    Deleted !! : C:\RECYCLED\Dc258.exe

                    ==============
                    host file OK !
                    ==============

                    ========
                    Registry
                    ========

                    Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Run\msconfig
                    Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                    Deleted : HKCU\Software\Microsoft\Internet Explorer\New Windows\Allow\host-domain-lookup.com
                    Deleted : HKCU\Software\Microsoft\Internet Explorer\New Windows\Allow\www.host-domain-lookup.com
                    Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                    Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
                    Deleted : HKCR\OutlookAddin.Addin
                    Deleted : HKCR\OutlookAddin.Addin.1
                    Deleted : HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\OutlookAddin.Addin
                    Deleted : HKLM\SYSTEM\ControlSet001\Enum\Root\Legacy_Irmon
                    Deleted : HKLM\SYSTEM\ControlSet001\Services\Irmon
                    Deleted : HKLM\SYSTEM\ControlSet002\Enum\Root\Legacy_Irmon
                    Deleted : HKLM\SYSTEM\ControlSet002\Services\Irmon
                    =================
                    Internet Explorer
                    =================

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                    Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                    Local Page REG_SZ C:\WINDOWS\system32\blank.htm
                    Default_Search_URL REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    Default_Page_URL REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                    Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                    Start Page REG_SZ https://www.google.com/?gws_rd=ssl
                    Local Page REG_SZ C:\WINDOWS\system32\blank.htm
                    Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

                    ===============
                    Security Center
                    ===============

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                    FirstRunDisabled REG_DWORD 1 (0x1)
                    AntiVirusDisableNotify REG_DWORD 0 (0x0)
                    FirewallDisableNotify REG_DWORD 0 (0x0)
                    UpdatesDisableNotify REG_DWORD 0 (0x0)
                    AntiVirusOverride REG_DWORD 1 (0x1)
                    FirewallOverride REG_DWORD 1 (0x1)

                    ========
                    Services
                    =========

                    Ndisuio : Start = 3
                    EapHost : Start = 2
                    Ip6Fw : Start = 2
                    SharedAccess : Start = 2
                    wuauserv : Start = 2
                    wscsvc : Start = 2

                    ============
                    Disk Cleaned
                    ============

                    =================
                    anti-ver blaster : OK !!
                    =================

                    ================
                    Prefetch cleaned
                    ================

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                    1. je vais faire ce que tu me dis
                      merci beaucoup pour ta patience que je salue
                      1. Contributeur sécurité
                        pas grand chose de visible justifiant la lenteur internet...

                        1)

                        Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
                        mais cette fois-ci :

                        choisis l'option CLEAN
                        ton PC va redemarrer,

                        laisse travailler l'outil.

                        en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

                        colle le contenu dans ta reponse

                        Tu peux le désinstaller ensuite

                        .................................

                        2)

                        Télécharge ZHPDiag ( de Nicolas coolman ).
                        https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

                        (outil de diagnostic)

                        Double clique sur le fichier d'installation, puis installe le avec les paramètres par défaut ( N'oublie pas de cocher " Créer une icône sur le bureau " )

                        Lance ZHPDiag en double cliquant sur l'icône présente sur ton bureau (Clique droit -> Executer en tant qu'admin pour vista )

                        Clique sur la loupe en haut à gauche, puis laisse l'outil scanner.

                        Une fois le scan terminé, clique sur l'icône en forme de disquette et enregistre le fichier sur ton bureau.

                        Rend toi sur Cjoint : http://www.cijoint.fr/

                        Clique sur "Parcourir " dans la partie " Joindre un fichier[...] "

                        Sélectionne le rapport ZHPdiag.txt qui se trouve sur ton bureau

                        Clique ensuite sur "Cliquez ici pour déposer le fichier " et copie/colle le lien dans ton prochain message

                        1. List'em by g3n-h@ckm@n 1.7.1.1

                          User : GLEYSES (Administrateurs)
                          Update on 17/04/2010 by g3n-h@ckm@n ::::: 17.10
                          Start at: 22:19:51 | 17/04/2010

                          Mobile AMD Sempron(tm) Processor 3400+
                          Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                          Internet Explorer 7.0.5730.11
                          Windows Firewall Status : Disabled
                          AV : Kaspersky Internet Security 9.0.0.736 [ Enabled | Updated ]
                          FW : Kaspersky Internet Security[ Enabled ]9.0.0.736

                          C:\ -> Disque fixe local | 65,74 Go (50,9 Go free) | NTFS
                          D:\ -> Disque fixe local | 43,69 Go (43,69 Go free) | FAT32
                          E:\ -> Disque CD-ROM

                          Boot: Safeboot

                          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\wbem\wmiprvse.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
                          C:\Program Files\List_Kill'em\List_Kill'em.exe
                          C:\WINDOWS\system32\cmd.exe
                          C:\Program Files\List_Kill'em\pv.exe

                          ======================
                          Keys "Run"
                          ======================

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
                          MSMSGS REG_SZ "C:\Program Files\Messenger\msmsgs.exe" /background
                          swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          SSBkgdUpdate REG_SZ "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                          PaperPort PTD REG_SZ C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                          IndexSearch REG_SZ C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
                          BrMfcWnd REG_SZ C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
                          Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                          avp REG_SZ "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
                          MSConfig REG_SZ C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                          =====================
                          Other Keys
                          =====================

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                          dontdisplaylastusername REG_DWORD 0 (0x0)
                          legalnoticecaption REG_SZ
                          legalnoticetext REG_SZ
                          shutdownwithoutlogon REG_DWORD 1 (0x1)
                          undockwithoutlogon REG_DWORD 1 (0x1)

                          ===============

                          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                          NoDriveTypeAutoRun REG_DWORD 145 (0x91)

                          ===============

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                          HonorAutoRunSetting REG_DWORD 1 (0x1)

                          ===============

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                          AppInit_DLLS REG_SZ C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll,C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~2\kloehk.dll

                          ===============

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                          AutoRestartShell REG_DWORD 1 (0x1)
                          DefaultUserName REG_SZ GLEYSES
                          LegalNoticeCaption REG_SZ
                          LegalNoticeText REG_SZ
                          PowerdownAfterShutdown REG_SZ 0
                          ReportBootOk REG_SZ 1
                          Shell REG_SZ Explorer.exe
                          ShutdownWithoutLogon REG_SZ 0
                          System REG_SZ
                          Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
                          VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                          SfcQuota REG_DWORD -1 (0xffffffff)
                          allocatecdroms REG_SZ 0
                          allocatedasd REG_SZ 0
                          allocatefloppies REG_SZ 0
                          cachedlogonscount REG_SZ 10
                          forceunlocklogon REG_DWORD 0 (0x0)
                          passwordexpirywarning REG_DWORD 14 (0xe)
                          scremoveoption REG_SZ 0
                          AllowMultipleTSSessions REG_DWORD 1 (0x1)
                          UIHost REG_EXPAND_SZ logonui.exe
                          LogonType REG_DWORD 0 (0x0)
                          Background REG_SZ 0 0 0
                          DefaultPassword REG_SZ
                          DebugServerCommand REG_SZ no
                          SFCDisable REG_DWORD 0 (0x0)
                          WinStationsDisabled REG_SZ 0
                          HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
                          ShowLogonOptions REG_DWORD 1 (0x1)
                          AltDefaultUserName REG_SZ GLEYSES
                          AltDefaultDomainName REG_SZ PC-GLEYSES
                          DefaultDomainName REG_SZ PC-GLEYSES
                          GpNetworkStartTimeoutPolicyValue REG_DWORD 0 (0x0)
                          ChangePasswordUseKerberos REG_DWORD 1 (0x1)

                          ===============

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\klogon]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

                          ===============

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                          {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

                          ===============

                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                          %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                          %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
                          C:\Program Files\Messenger\MSMSGS.EXE REG_SZ C:\Program Files\Messenger\MSMSGS.EXE:*:Enabled:Windows Messenger
                          E:\setup.exe REG_SZ E:\setup.exe:*:Enabled:Programme d'installation de Kaspersky Internet Security 2009
                          C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\AVP.EXE REG_SZ C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\AVP.EXE:*:Enabled:Kaspersky Anti-Virus

                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                          %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                          %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000

                          ===============
                          ActivX controls
                          ===============

                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6414512B-B978-451D-A0D8-FCFDF33E833C}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}]

                          ===============
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1BC46932-21B2-4130-86E0-B4EB4F7A7A7B}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{233C1507-6A77-46A4-9443-F871F945D258}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA851-CC51-11CF-AAFA-00AA00B6015C}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5056b317-8d4c-43ee-8543-b9d1e234b8f4}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{BDE0FA43-6952-4BA8-8C58-09AF690F88E1}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E8EA5BD6-D931-4001-ABF6-81BAA500360A}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EA29D410-CE41-4953-A862-2DE706A1DAD7}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{FDC11A6F-17D1-48f9-9EA3-9051954BAA24}]

                          ==============
                          BHO :
                          ======

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E33CF602-D945-461A-83F0-819F76A199F8}]

                          ===
                          DNS
                          ===

                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{8B8E13E8-0352-41CD-88D7-C3964C592D88}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{8B8E13E8-0352-41CD-88D7-C3964C592D88}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS2\Services\Tcpip\..\{8B8E13E8-0352-41CD-88D7-C3964C592D88}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                          ================
                          Internet Explorer :
                          ================

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                          Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                          Local Page REG_EXPAND_SZ %SystemRoot%\system32\blank.htm
                          Default_Search_URL REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                          Default_Page_URL REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                          Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                          Start Page REG_SZ https://www.sfr.fr/
                          Local Page REG_SZ C:\WINDOWS\system32\blank.htm
                          Search Page REG_SZ https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fintl%2fbr%2faccess%2fallinone.asp%3f

                          ========
                          Services
                          ========

                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                          Ndisuio : 0x3 ( OK = 3 )
                          EapHost : 0x3 ( OK = 2 )
                          SharedAccess : 0x2 ( OK = 2 )
                          wuauserv : 0x2 ( OK = 2 )

                          ========
                          Safemode
                          ========

                          HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot : OK !!
                          HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal : OK !!
                          HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network : OK !!

                          =========
                          Atapi.sys
                          =========

                          C:\WINDOWS\$NtServicePackUninstall$\atapi.sys :
                          MD5 :: [cdfe4411a69c224bd1d11b2da92dac51]
                          SHA256 :: [0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d]

                          C:\WINDOWS\ServicePackFiles\i386\atapi.sys :
                          MD5 :: [9f3a2f5aa6875c72bf062c712cfa2674]
                          SHA256 :: [b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9]

                          C:\WINDOWS\system32\drivers\atapi.sys :
                          MD5 :: [9f3a2f5aa6875c72bf062c712cfa2674]
                          SHA256 :: [b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9]

                          Référence :
                          ==========

                          Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
                          Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
                          Win XP_32b : a64013e98426e1877cb653685c5c0009
                          Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                          Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                          Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                          Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                          Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                          Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                          Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                          Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
                          Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e

                          =======
                          Drive :
                          =======

                          D'fragmenteur de disque Windows
                          Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

                          Rapport d'analyse
                          65,74 Go total, 50,90 Go libre (77%), 6% fragment' (fragmentation du fichier 12%)

                          Il ne vous est pas n'cessaire de d'fragmenter ce volume.

                          ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                          Present !! : C:\WINDOWS\002895_.tmp
                          Present !! : C:\WINDOWS\System32\*_.exe
                          Present !! : C:\WINDOWS\TEMP\scs1.tmp
                          Present !! : C:\WINDOWS\TEMP\scs2.tmp
                          Present !! : C:\Documents and Settings\GLEYSES\Application Data\wklnhst.dat
                          Present !! : C:\Documents and Settings\GLEYSES\Application Data\wklnhst.dat
                          Present !! : C:\Documents and Settings\GLEYSES\Local Settings\Temp\87B.tmp
                          Present !! : C:\Documents and Settings\GLEYSES\Local Settings\Temp\87C.tmp

                          ¤¤¤¤¤¤¤¤¤¤ Keys :

                          Present !! : HKLM\Software\Microsoft\Windows\CurrentVersion\Run\msconfig
                          Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                          Present !! : HKCU\Software\Microsoft\Internet Explorer\New Windows\Allow\host-domain-lookup.com
                          Present !! : HKCU\Software\Microsoft\Internet Explorer\New Windows\Allow\www.host-domain-lookup.com
                          Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                          Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
                          Present !! : HKCR\OutlookAddin.Addin
                          Present !! : HKCR\OutlookAddin.Addin.1
                          Present !! : HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\OutlookAddin.Addin
                          Present !! : HKLM\SYSTEM\ControlSet001\Enum\Root\Legacy_Irmon
                          Present !! : HKLM\SYSTEM\ControlSet001\Services\Irmon
                          Present !! : HKLM\SYSTEM\ControlSet002\Enum\Root\Legacy_Irmon
                          Present !! : HKLM\SYSTEM\ControlSet002\Services\Irmon
                          Present !! : HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_Irmon
                          Present !! : HKLM\SYSTEM\CurrentControlSet\Services\Irmon

                          ============

                          catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2010-04-17 22:26:14
                          Windows 5.1.2600 Service Pack 3 FAT NTAPI

                          scanning hidden processes ...

                          scanning hidden services ...

                          scanning hidden autostart entries ...

                          scanning hidden files ...

                          scan completed successfully
                          hidden processes: 0
                          hidden services: 0
                          hidden files: 0

                          Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                          device: opened successfully
                          user: MBR read successfully
                          called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
                          kernel: MBR read successfully
                          user & kernel MBR OK

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                          FirstRunDisabled REG_DWORD 1 (0x1)
                          AntiVirusDisableNotify REG_DWORD 0 (0x0)
                          FirewallDisableNotify REG_DWORD 0 (0x0)
                          UpdatesDisableNotify REG_DWORD 0 (0x0)
                          AntiVirusOverride REG_DWORD 1 (0x1)
                          FirewallOverride REG_DWORD 0 (0x0)

                          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                          End of scan : 22:26:14,93
                          • 1
                          • 2
                          • 3