PC anormalement lent - Rapports

Bonsoir,

ça va faire quelques jours que mon pc rame, plus de 4 minutes pour s'allumer, pas moyen d'écouter de la musique ou de regarder un film sans que ça saccade et jouer est devenu quasiment impossible.

D'ou pourrait venir le problème ? J'ai essayé de défragmenter le disque, d'optimiser le boot avec Bootvis, aucune amélioration.

Ma machine commence à dater, achetée en 2002 je n'avais jamais rencontré de problèmes majeurs, là elle se met à ramer du jour au lendemain. Avant d'en acheter une nouvelle je préfèrerais avoir votre avis.

Pour info je tourne avec un processeur intel pentium 4, 2Ghz et 768 Mo de ram

Voici les rapports AVG anti-spyware/Bitdefender scan online/ HiJackThis.

---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 16:39:55 05.10.2007

+ Résultat de l'analyse:

C:\Documents and Settings\Catherine\Cookies\catherine@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\Céline\Cookies\céline@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.

Fin du rapport

---------------------------------------------------------
BitDefender Online Scanner
---------------------------------------------------------

Scan report generated at: Fri, Oct 05, 2007 - 19:06:14

Scan path: C:\;D:\;E:\;F:\;G:\;

No virus found.

---------------------------------------------------------
HiJackThis
---------------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:33:22, on 05.10.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\David\Bureau\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ch/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [kis] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunOnce: [KB926239] rundll32.exe apphelp.dll,ShimFlushCache
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Ajouter à Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\\ie_banner_deny.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ch\msntabres.dll.mui/229?2ec9f251c7dd4ac5837934e4b026080c
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ch\msntabres.dll.mui/230?2ec9f251c7dd4ac5837934e4b026080c
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O20 - AppInit_DLLs: c:\progra~2\kasper~1\kasper~1.0\adialhk.dll MsgPlusLoader.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 8301 bytes

J'ai fait un peu le ménage avec CCleaner avant de faire ces scans.

Mici ;)
Configuration: Windows XP
Internet Explorer 6.0

36 réponses

Résumé de la discussion

Le problème central est un PC ancien qui rame fortement, avec un démarrage long et des saccades en lecture multimédia, ce qui rend les jeux et les vidéos quasi impraticables. Les essais logiciels, comme la défragmentation, l’optimisation du boot et les scans AVG/BitDefender/HiJackThis, n’apportent pas d’amélioration et ne révèlent pas de menace, malgré une certaine activité système. Des indices matériels apparaissent, notamment des bruits importants du disque dur et l’ancienneté de la machine, tandis que l’espace libre reste de 85 Go sur 120 Go, ce qui pourrait favoriser les lenteurs. Pour la suite, il serait utile d’évaluer l’état SMART du disque et de limiter les programmes en démarrage lourds, voire envisager une mise à niveau matérielle pour un système moderne.

Bobot (l’IA à votre service)
  1. je te proposerai bien de faire une restauration du système mais je ne suis pas convaicu
    que ça résoudra ton problème
    0
    1. Merci pour le lien

      Vieux, bah plutot oui, acheté en 2002 j'ai pas changé grand chose depuis (juste ajouté 512 mo de ram et changé de disque dur).
      0
      1. ton pc est t'il vieux?
        pour la restauration regarde ici
        http://perso.orange.fr/jesses/Docs/Bases/CreerRestaur.htm
        garde ce lien si tu peut de temps en temps prend le temps de lire un peu tu apprendras beaucoup de chose
        0
        1. Ben en fait les pb de lenteur ont commencés au premier plantage que j'avais eu après ces bruits bizarres du DD. Et euh une restauration non, je sais même pas ce que c'est :x
          0
          1. ok en effet il te reste de quoi faire
            donc pas de soucis à ce niveau
            au début de ton poste tu dis que tu as des soucis
            depuis deux jours
            donc à compter du 05.09
            que c'est t'il passé à ce moment là
            as tu essayer une restauration ?
            0
            1. reste 85 Go de libre sur 120, j'ai deja tenté plusieurs défragmentations qui n'avaient rien changé. mais vu les bruits bizarres que mon DD a tendance à faire j'imagine que le pb vient de la.
              0
              1. bon apparemment plus d'infection
                tu as toujours tes problème de lenteur
                et je ne voit plus quoi faire
                ton disque est-il plein
                quel capacité lui reste t'il
                fait tu des défragmentations
                fait tu des nettoyages de disques
                0
                1. BitDefender Online Scanner - Real Time Virus Report

                  Generated at: Sat, Oct 13, 2007 - 18:53:15

                  --------------------------------------------------------------------------------

                  Scan Info

                  Scanned Files
                  347687

                  Infected Files
                  0

                  Virus Detected

                  No virus found.

                  --------------------------------------------------------------------------------

                  This summary of the scan process will be used by the BitDefender Antivirus Lab to create agregate statistics about virus activity around the world.
                  0
                  1. Hello, voilou

                    ComboFix 07-10-12.4 - David 2007-10-13 15:08:28.1 - NTFSx86
                    Microsoft Windows XP dition familiale 5.1.2600.2.1252.1.1036.18.402 [GMT 2:00]
                    Running from: C:\Documents and Settings\David\Bureau\ComboFix.exe
                    * Created a new restore point
                    .

                    ((((((((((((((((((((((((((((( Fichiers créés 2007-09-13 to 2007-10-13 ))))))))))))))))))))))))))))))))))))
                    .

                    2007-10-13 15:04 51,200 --a------ C:\WINDOWS\NirCmd.exe
                    2007-10-11 15:55 <REP> d-------- C:\Program Files\Lavalys
                    2007-10-10 15:50 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
                    2007-10-05 20:18 <REP> d-------- C:\Program Files\Navilog1
                    2007-10-05 16:41 <REP> d-------- C:\WINDOWS\BDOSCAN8
                    2007-10-05 12:13 <REP> d-------- C:\Documents and Settings\Catherine\Application Data\Grisoft
                    2007-10-03 15:44 <REP> d-------- C:\Documents and Settings\David\Application Data\Grisoft
                    2007-10-03 15:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
                    2007-10-03 15:43 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
                    2007-10-03 15:30 <REP> d-------- C:\Program Files\CCleaner
                    2007-10-03 14:19 <REP> d-------- C:\WINDOWS\pss
                    2007-10-02 00:41 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                    2007-09-29 11:05 <REP> d-------- C:\CourrierType
                    2007-09-29 11:04 <REP> d-------- C:\Program Files\Fichiers communs\PC SOFT
                    2007-09-29 11:04 <REP> d-------- C:\Program Files\Agenda-xp
                    2007-09-29 10:56 <REP> d-------- C:\Program Files\Pense-bete
                    2007-09-26 15:10 <REP> d-------- C:\Program Files\Alcohol Soft
                    2007-09-26 15:10 160,640 --a------ C:\WINDOWS\system32\drivers\a347bus.sys
                    2007-09-26 15:10 5,248 --a------ C:\WINDOWS\system32\drivers\a347scsi.sys
                    2007-09-17 15:54 <REP> d-------- C:\Program Files\LimeWire

                    .
                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    2007-10-13 13:15 28,181,024 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
                    2007-10-13 13:13 1,668,896 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
                    2007-10-13 01:15 377,972 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
                    2007-10-13 01:15 157,388 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
                    2007-10-08 16:31 --------- d-----w C:\Program Files\Java
                    2007-10-08 15:24 3,145,728 ---ha-w C:\Documents and Settings\Céline\NTUSER.DAT
                    2007-10-05 19:22 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
                    2007-10-01 22:15 --------- d-----w C:\Program Files\Fichiers communs\Adobe
                    2007-09-30 13:16 --------- d-----w C:\Program Files\iTunes
                    2007-09-30 13:16 --------- d-----w C:\Program Files\iPod
                    2007-09-21 19:10 --------- d-----w C:\Program Files\Apple Software Update
                    2007-09-13 12:12 --------- d-----w C:\Program Files\GUILD WARS
                    2007-09-10 09:53 --------- d-----w C:\Program Files\NCSoft
                    2007-09-10 09:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
                    2007-09-10 09:38 --------- d-----w C:\Documents and Settings\David\Application Data\InstallShield
                    2007-08-30 09:53 --------- d-----w C:\Program Files\Windows Live Toolbar
                    2007-08-30 09:53 --------- d-----w C:\Program Files\Windows Live Favorites
                    2007-08-30 09:51 --------- d-----w C:\Program Files\MSN Messenger
                    2007-08-21 06:17 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
                    2007-08-19 18:27 65,024 ----a-w C:\WINDOWS\IFinst26.exe
                    2007-08-19 18:27 --------- d-----w C:\Program Files\Lame MP3 Codec
                    2007-08-19 18:26 --------- d-----w C:\Program Files\XviD
                    2007-08-19 18:26 --------- d-----w C:\Program Files\MarkAny
                    2007-08-19 18:25 --------- d-----w C:\Program Files\Samsung
                    2007-08-19 18:25 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
                    2007-08-13 14:55 --------- d-----w C:\Documents and Settings\Catherine\Application Data\PC Suite
                    2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
                    2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
                    2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
                    2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
                    2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
                    2007-07-30 17:19 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
                    2007-07-30 17:19 207,736 ----a-w C:\WINDOWS\system32\muweb.dll
                    2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
                    2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
                    2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
                    .

                    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    .
                    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "kis"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" [2006-03-24 20:09]

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 17:09]
                    "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55]

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                    "appinit_dlls"=c:\progra~2\kasper~1\kasper~1.0\adialhk.dll MsgPlusLoader.dll

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
                    "C:\Program Files\Messenger\msmsgs.exe" /background

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
                    "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayNC Launcher]
                    C:\program files\ncsoft\launcher\NCLauncher.exe /Minimized

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shareaza]
                    "C:\Program Files\Shareaza\Shareaza.exe" -tray

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSTray]
                    C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe

                    S3 dump_wmimmc;dump_wmimmc;\??\C:\WINDOWS\system32\drivers\dump_wmimmc.sys

                    *Newly Created Service* - CATCHME
                    .
                    Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
                    "2007-09-21 19:10:07 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
                    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
                    "2007-10-13 12:54:46 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
                    .
                    **************************************************************************

                    catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2007-10-13 15:14:18
                    Windows 5.1.2600 Service Pack 2 NTFS

                    scanning hidden processes ...

                    scanning hidden autostart entries ...

                    scanning hidden files ...

                    scan completed successfully
                    hidden files: 0

                    **************************************************************************
                    .
                    Completion time: 2007-10-13 15:17:31
                    .
                    --- E O F ---
                    0
                    1. Bonjour David01

                      Télécharge Combofix sUBs : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                      et sauvegarde le sur ton bureau et pas ailleurs!

                      Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider.
                      Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.
                      0
                      1. Re bonsoir, ok bah j'ai fais ça et ça m'a donné ce rapport.

                        Clean Navipromo version 3.2.1 commencé le 12.10.2007 à 23:24:19.17

                        Fix lancé depuis C:\Program Files\navilog1
                        Mise a jour le 03.10.2007 a 20h00 by IL-MAFIOSO

                        Microsoft Windows XP [version 5.1.2600]
                        Internet Explorer : 6.0.2900.2180

                        Mode suppression automatique

                        *** fsbl1.txt non trouvé ***
                        (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                        *** Suppression avec Backups résultats GenericNaviSearch ***

                        * Scan C:\WINDOWS\system32 *

                        * Scan C:\DOCUME~1\David\LOCALS~1\APPLIC~1 *

                        *** Suppression dossiers dans C:\WINDOWS ***

                        *** Suppression dossiers dans C:\Program Files ***

                        *** Suppression dossiers dans C:\Documents and Settings\All Users\Application Data ***

                        *** Suppression dossiers dans C:\Documents and Settings\David\Application Data ***

                        *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

                        *** Suppression fichiers ***

                        *** Suppression fichiers temporaires ***

                        Nettoyage contenu C:\WINDOWS\Temp effectué !
                        Nettoyage contenu C:\Documents and Settings\David\Local Settings\Temp effectué !

                        *** Traitement Recherche complémentaire ***
                        (Recherche fichiers spécifiques)

                        1)Recherche fichiers connus:

                        2)Recherche et Suppression Heuristique :

                        *** Sauvegarde du registre vers dossier Backupnavi ***

                        sauvegarde du registre réalise avec succès !

                        *** Nettoyage registre ***

                        Nettoyage registre Ok

                        *** Certificats ***

                        Certificat Egroup absent !

                        *** Nettoyage termine le 12.10.2007 à 23:32:10.23 ***

                        Pas d'amélioration en tout cas.
                        0
                        1. je ne sais pas trop
                          par contre je ne vois pas d'infection dans ton rapport
                          mais je peux me tromper
                          il y a juste ça qui me chagrine C:\DOCUME~1\David\LOCALS~1\APPLIC~1
                          mise à part faire navilog option 2 je ne vois pas
                          0
                          1. Toujours, toujours

                            t'es sûr que c'est pas un problème de matériel ?
                            0
                            1. Salut

                              ce ne sont que des cookies
                              encore des problème de lenteur?
                              0
                              1. Bonjour, voila

                                ---------------------------------------------------------
                                AVG Anti-Spyware - Rapport d'analyse
                                ---------------------------------------------------------

                                + Créé à: 01:44:03 12.10.2007

                                + Résultat de l'analyse:

                                :mozilla.35:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\a8rmymfn.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
                                C:\Documents and Settings\Catherine\Cookies\catherine@2o7[2].txt -> TrackingCookie.2o7 : Nettoyé.
                                C:\Documents and Settings\Catherine\Cookies\catherine@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
                                C:\Documents and Settings\David\Cookies\david@advertising[1].txt -> TrackingCookie.Advertising : Nettoyé.
                                C:\Documents and Settings\Céline\Cookies\céline@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
                                C:\Documents and Settings\David\Cookies\david@casalemedia[1].txt -> TrackingCookie.Casalemedia : Nettoyé.
                                C:\Documents and Settings\Catherine\Cookies\catherine@doubleclick[1].txt -> TrackingCookie.Doubleclick : Nettoyé.
                                :mozilla.166:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\a8rmymfn.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
                                :mozilla.167:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\a8rmymfn.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
                                C:\Documents and Settings\Céline\Cookies\céline@search.live[2].txt -> TrackingCookie.Live : Nettoyé.
                                :mozilla.128:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\a8rmymfn.default\cookies.txt -> TrackingCookie.Liveperson : Nettoyé.
                                C:\Documents and Settings\Catherine\Cookies\catherine@auto.search.msn[1].txt -> TrackingCookie.Msn : Nettoyé.
                                C:\Documents and Settings\Céline\Cookies\céline@auto.search.msn[1].txt -> TrackingCookie.Msn : Nettoyé.
                                :mozilla.10:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\a8rmymfn.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
                                :mozilla.11:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\a8rmymfn.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
                                :mozilla.12:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\a8rmymfn.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
                                :mozilla.13:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\a8rmymfn.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
                                :mozilla.14:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\a8rmymfn.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
                                :mozilla.15:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\a8rmymfn.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
                                :mozilla.131:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\a8rmymfn.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
                                :mozilla.146:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\a8rmymfn.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
                                :mozilla.24:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\a8rmymfn.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
                                C:\Documents and Settings\Céline\Cookies\céline@statcounter[1].txt -> TrackingCookie.Statcounter : Nettoyé.
                                C:\Documents and Settings\Catherine\Cookies\catherine@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Nettoyé.
                                :mozilla.119:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\a8rmymfn.default\cookies.txt -> TrackingCookie.Webtrendslive : Nettoyé.
                                :mozilla.120:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\a8rmymfn.default\cookies.txt -> TrackingCookie.Webtrendslive : Nettoyé.

                                Fin du rapport

                                Par contre, j'ai bien mis "Quarantaine" dans paramètre mais à la fin de l'analyse les actions étaient de supprimer...normal ?

                                Quant à MSNfix apparemment il m'a rien trouvé "Nettoyage en cours 3/3"
                                0
                                1. un doute
                                  faire ceci

                                  Télécharge:
                                  http://www.grisoft.cz/filedir/inst/avgas-setup-7.5.1.43.exe AVG-AntiSpyware
                                  = Installer
                                  = Le lancer
                                  = Clic : Mise à jour
                                  ------
                                  = Redémarre en mode Sans Échec (le démarrage peut prendre plusieurs minutes)
                                  Attention, pas d’accès à internet dans ce mode. Enregistre ou imprime les consignes.

                                  Relance le Pc et tapote la touche F8 ( ou F5 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
                                  Avec les touches « flèches », sélectionne Mode sans échec ==> entrée ==>nom utilisateur habituel
                                  -------
                                  = Dans ANALYSE ( en forme de loupe )
                                  ==> Paramètres ==> sous COMMENT REAGIR==>clic sur Actions recommandées ==>Quarantaine
                                  ==> Clic : Analyse complète du système
                                  En fin de scan ( qui est assez long)
                                  ==> Clic Appliquer toutes les actions <== ceci Très important
                                  ==> Clic Sauvegarder rapport puis Enregistrer sous et choisir bureau
                                  -------
                                  En mode normal
                                  colle le rapport
                                  -------------

                                  Télécharge sur le bureau
                                  [url=http://sosvirus.changelog.fr/MSNFix.zip]MSNfix[/url]
                                  = Clic-Droit sur MSNFix.zip
                                  = Extraire ici ( ou extraire sans confirmation ou tout ou unzip)
                                  = Double-Clic sur le dossier MSNfix qui vient de se créer
                                  = Double-Clic MSNfix ==> Symbole roue dentée
                                  = Choisir R
                                  = Choisir ensuite N ( si infection)
                                  = Enregistre le rapport
                                  redémarre le PC et relancer MSN tu sauras ainsi si tout est supprimé
                                  0
                                  1. Bonsoir, voila

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 21:14:19, on 11.10.2007
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\HPZipm12.exe
                                    C:\Program Files\MSN Messenger\usnsvc.exe
                                    C:\Program Files\iPod\bin\iPodService.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
                                    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
                                    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
                                    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                    C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                    C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
                                    C:\Program Files\Windows Live Toolbar\msn_sl.exe
                                    C:\Documents and Settings\David\Bureau\HiJackThis\HijackThis.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ch/?gws_rd=ssl
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                    O4 - HKLM\..\Run: [kis] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
                                    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
                                    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                    O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
                                    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                                    O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
                                    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                                    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                    O8 - Extra context menu item: Ajouter à Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\\ie_banner_deny.htm
                                    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ch\msntabres.dll.mui/229?2ec9f251c7dd4ac5837934e4b026080c
                                    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ch\msntabres.dll.mui/230?2ec9f251c7dd4ac5837934e4b026080c
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                    O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
                                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
                                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                    O20 - AppInit_DLLs: c:\progra~2\kasper~1\kasper~1.0\adialhk.dll MsgPlusLoader.dll
                                    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                                    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                                    0
                                    • 1
                                    • 2