Aide au rapport hijackthis

Bonjour,ayant des problemes de lenteur sur internet j ai donc fait lancer un scan avec hijackthis et j aurais besoin de vous pour l analyser mercci
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:38:15, on 02/09/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\s3trayp.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\On Demand Distribution\OD2 Music Manager\OD2MediaBar_VistaFileManager.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Program Files\eMule\emule.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VistaADeck\HDAudioCPL.exe 1
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [MediaBarFileManager] C:\Program Files\On Demand Distribution\OD2 Music Manager\OD2MediaBar_VistaFileManager.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\Windows\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - https://www.systemrequirementslab.com/cyri
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9866 bytes
Configuration: Windows Vista
Internet Explorer 7.0

36 réponses

Résumé de la discussion

Problème de lenteur sur Internet et demande d’analyse d’un rapport HijackThis suite à un scan effectué sur un PC sous Windows Vista, afin d’identifier des éléments potentiellement problématiques. Les réponses suggèrent des pistes variées: privilégier d’autres antivirus comme Antivir plutôt qu’ Avast, et proposer des outils de nettoyage comme ComboFix après analyse du rapport HijackThis, tout en avertissant sur les risques et les consignes. D'autres questions portent sur ce qui a précédé l’apparition du ralentissement et soulignent l’importance d’éviter les méthodes non publiques de désinfection et les diagnostics réalisés hors cadre sécurisé.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonjour,

    je viens de voir ton topic.

    Je vais suivre la discussion.
    0
    1. Contributeur sécurité
      Re,

      je crois que c'est au-delà de mes compétences.

      Je te propose de poster sur le forum Internet.

      Il faudra que tu donnes des précisions sur la manière dont tu es connecté (box, modem, câble, ...).

      Tu peux faire référence à ce topic et à mon conseil.
      0
      1. Contributeur sécurité
        Re,

        non, les rapports ne montrent rien.

        Essaye de réparer la connexion.
        0
        1. TA rien trouver de louche sur le rapport que je t ai poster
          0
          1. C EST Exactement pareil mais vu que cette icone clignote sur mon ordi qui ne fonctionne pas normalement pr internet je pense que ca montre une instabilite de la connexion
            0
            1. Contributeur sécurité
              Re,

              quelle différence avec le clic droit sur l'icône de l'ordi qui fonctionne bien ?
              0
              1. ba c l icone connexion dc ya plein d onglet ya deconnexion du resau ...
                0
                1. Contributeur sécurité
                  Re,

                  quand tu fais un clic droit sur l'icône, tu obtiens quoi ?
                  0
                  1. wi exactement le meme pb avec firefox mais je pense que la solution viendra de cette put.. d icone qui clignote ca doit bien vouloir dire quelque chose
                    0
                    1. voila le rapport

                      Running on: Windows VISTA , Service Pack 1 (6001.6.0)
                      System directory: C:\Windows
                      SystemScan file: C:\Users\kevin\sys87041.exe
                      Running in: User mode
                      Date: 03/09/2008
                      Time: 18:57:05

                      Output limited to:
                      -Recent files
                      -Scheduled jobs
                      -Suspicious Files

                      ===================== RECENT FILES =====================

                      Showing files newer than 30 days

                      ----- recent files in C:\
                      28/08/2008 20:59:14 (DIR) 0 byte 6 days old -- ProgramData
                      02/09/2008 12:40:49 (DIR) 0 byte 1 days old -- fixwareout
                      02/09/2008 13:42:06 (DIR) 0 byte 1 days old -- Program Files
                      02/09/2008 13:42:11 (DIR) 0 byte 1 days old -- Windows
                      03/09/2008 11:20:19 (DIR)1117544448 byte 0 days old -- pagefile.sys
                      03/09/2008 11:20:21 (DIR)803717120 byte 0 days old -- hiberfil.sys
                      03/09/2008 14:39:14 (DIR) 0 byte 0 days old -- System Volume Information

                      ----- recent files in C:\Windows\
                      07/08/2008 13:46:24 41856 byte 27 days old -- setupact.log
                      13/08/2008 00:40:59 101665215 byte 21 days old -- MEMORY.DMP
                      13/08/2008 00:41:20 (DIR) 0 byte 21 days old -- Minidump
                      14/08/2008 11:14:13 (DIR) 0 byte 20 days old -- AppPatch
                      15/08/2008 01:37:27 (DIR) 0 byte 19 days old -- winsxs
                      15/08/2008 01:46:18 (DIR) 0 byte 19 days old -- rescache
                      01/09/2008 12:13:01 (DIR) 0 byte 2 days old -- inf
                      02/09/2008 00:19:29 69904 byte 1 days old -- PFRO.log
                      02/09/2008 13:42:04 (DIR) 0 byte 1 days old -- System32
                      02/09/2008 13:54:16 (DIR) 0 byte 1 days old -- Installer
                      02/09/2008 18:23:23 (DIR) 0 byte 1 days old -- Downloaded Program Files
                      03/09/2008 11:20:25 67584 byte 0 days old -- bootstat.dat
                      03/09/2008 11:47:10 1609991 byte 0 days old -- WindowsUpdate.log
                      03/09/2008 18:54:49 (DIR) 0 byte 0 days old -- Temp
                      03/09/2008 18:54:55 (DIR) 0 byte 0 days old -- Prefetch

                      ----- recent files in C:\Windows\Downloaded Program Files\

                      ----- recent files in C:\Windows\system\

                      ----- recent files in C:\Windows\system32\
                      05/08/2008 20:11:01 15888504 byte 29 days old -- mrt.exe
                      06/08/2008 18:33:47 (DIR) 0 byte 28 days old -- Adobe
                      14/08/2008 11:14:13 (DIR) 0 byte 20 days old -- migration
                      14/08/2008 11:14:14 (DIR) 0 byte 20 days old -- fr-FR
                      25/08/2008 16:48:08 (DIR) 0 byte 9 days old -- WDI
                      29/08/2008 01:36:42 (DIR) 0 byte 5 days old -- catroot2
                      29/08/2008 13:59:22 (DIR) 0 byte 5 days old -- catroot
                      29/08/2008 15:05:13 2577 byte 5 days old -- config.nt
                      01/09/2008 12:13:01 123556 byte 2 days old -- perfc00C.dat
                      01/09/2008 12:13:01 587178 byte 2 days old -- perfh009.dat
                      01/09/2008 12:13:01 669566 byte 2 days old -- perfh00C.dat
                      01/09/2008 12:13:01 1470810 byte 2 days old -- PerfStringBackup.INI
                      01/09/2008 12:13:01 101250 byte 2 days old -- perfc009.dat
                      02/09/2008 13:42:05 (DIR) 0 byte 1 days old -- drivers
                      03/09/2008 17:20:46 3296 byte 0 days old -- 7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
                      03/09/2008 17:20:46 3296 byte 0 days old -- 7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0

                      ----- recent files in C:\Windows\system32\drivers\
                      17/08/2008 15:05:22 17144 byte 17 days old -- mbam.sys
                      17/08/2008 15:05:26 38472 byte 17 days old -- mbamswissarmy.sys

                      ----- recent files in C:\Windows\temp\
                      06/08/2008 11:53:48 524288 byte 28 days old -- TMP000000549700853B40606940
                      24/08/2008 19:38:31 (DIR) 0 byte 10 days old -- MPTelemetrySubmit
                      25/08/2008 00:38:24 524288 byte 9 days old -- TMP000000543D171BD2399B9B12
                      25/08/2008 11:15:29 229902 byte 9 days old -- SilverlightMSI.log
                      25/08/2008 11:15:29 1230 byte 9 days old -- Silverlight0.log
                      29/08/2008 12:34:24 120 byte 5 days old -- fwtsqmfile09.sqm
                      29/08/2008 12:34:26 120 byte 5 days old -- fwtsqmfile10.sqm
                      29/08/2008 12:34:45 120 byte 5 days old -- fwtsqmfile11.sqm
                      29/08/2008 12:34:57 120 byte 5 days old -- fwtsqmfile12.sqm
                      29/08/2008 12:35:19 120 byte 5 days old -- fwtsqmfile13.sqm
                      29/08/2008 12:35:36 120 byte 5 days old -- fwtsqmfile14.sqm
                      29/08/2008 12:35:54 120 byte 5 days old -- fwtsqmfile15.sqm
                      29/08/2008 12:36:06 120 byte 5 days old -- fwtsqmfile16.sqm
                      29/08/2008 12:36:23 120 byte 5 days old -- fwtsqmfile17.sqm
                      29/08/2008 12:36:26 120 byte 5 days old -- fwtsqmfile18.sqm
                      29/08/2008 12:36:40 120 byte 5 days old -- fwtsqmfile19.sqm
                      29/08/2008 14:52:39 632 byte 5 days old -- fwtsqmfile00.sqm
                      29/08/2008 14:52:42 120 byte 5 days old -- fwtsqmfile01.sqm
                      29/08/2008 14:56:27 120 byte 5 days old -- fwtsqmfile02.sqm
                      31/08/2008 21:37:50 632 byte 3 days old -- fwtsqmfile03.sqm
                      31/08/2008 21:59:04 120 byte 3 days old -- fwtsqmfile04.sqm
                      02/09/2008 00:18:18 632 byte 1 days old -- fwtsqmfile05.sqm
                      02/09/2008 15:55:02 632 byte 1 days old -- fwtsqmfile06.sqm
                      03/09/2008 01:20:14 120 byte 0 days old -- fwtsqmfile07.sqm
                      03/09/2008 11:33:38 463648 byte 0 days old -- MpSigStub.log
                      03/09/2008 11:47:10 230840 byte 0 days old -- MpCmdRun.log
                      03/09/2008 17:49:41 632 byte 0 days old -- fwtsqmfile08.sqm
                      03/09/2008 18:54:35 (DIR) 0 byte 0 days old -- _avast4_

                      ----- recent files in C:\Program Files\
                      14/08/2008 11:14:13 (DIR) 0 byte 20 days old -- Windows Mail
                      25/08/2008 11:15:25 (DIR) 0 byte 9 days old -- Microsoft Silverlight
                      30/08/2008 23:13:12 (DIR) 0 byte 4 days old -- TubeMaster
                      31/08/2008 12:00:27 (DIR) 0 byte 3 days old -- Adobe
                      01/09/2008 19:53:18 (DIR) 0 byte 2 days old -- Malwarebytes' Anti-Malware
                      02/09/2008 00:47:49 (DIR) 0 byte 1 days old -- Spybot - Search & Destroy
                      02/09/2008 13:42:11 (DIR) 0 byte 1 days old -- Common Files

                      ----- recent files in C:\Program Files\Common Files\

                      ----- recent files in C:\Users\kevin\AppData\Roaming\
                      26/08/2008 17:40:00 (DIR) 0 byte 8 days old -- Mozilla
                      28/08/2008 21:00:19 (DIR) 0 byte 6 days old -- Malwarebytes

                      ----- recent files in C:\Users\kevin\AppData\Local\Temp\
                      31/08/2008 11:57:40 (DIR) 0 byte 3 days old -- ~nsu.tmp
                      01/09/2008 17:38:02 (DIR) 0 byte 2 days old -- _avast4_
                      02/09/2008 00:29:07 (DIR) 0 byte 1 days old -- is-H03G1.tmp
                      02/09/2008 00:29:07 (DIR) 0 byte 1 days old -- isp2C59.tmp
                      02/09/2008 00:29:29 (DIR) 0 byte 1 days old -- testnsis
                      02/09/2008 00:29:29 (DIR) 0 byte 1 days old -- ocd
                      02/09/2008 00:29:29 (DIR) 0 byte 1 days old -- ~rnsetup
                      02/09/2008 00:35:51 (DIR) 0 byte 1 days old -- WLTB Custom Button Feeds
                      02/09/2008 12:00:59 1930 byte 1 days old -- wmplog00.sqm
                      02/09/2008 12:23:48 651940 byte 1 days old -- MSI2f3d0.LOG
                      02/09/2008 12:47:08 (DIR) 0 byte 1 days old -- {822a0455-5735-4808-b550-c2eab7cfef8c}
                      02/09/2008 13:42:11 380274 byte 1 days old -- MSIc180e.LOG
                      02/09/2008 13:54:16 440 byte 1 days old -- MSI942c9.LOG
                      02/09/2008 15:05:17 (DIR) 0 byte 1 days old -- {36ef2885-287f-4b95-a095-c4a9b8d8ceba}
                      02/09/2008 21:35:44 114688 byte 1 days old -- ~DFD7D6.tmp
                      03/09/2008 11:22:45 (DIR) 0 byte 0 days old -- WPDNSE
                      03/09/2008 11:26:11 519 byte 0 days old -- jusched.log
                      03/09/2008 11:27:02 (DIR) 0 byte 0 days old -- Low
                      03/09/2008 12:51:55 31832 byte 0 days old -- kevin.bmp
                      03/09/2008 17:38:11 (DIR) 0 byte 0 days old -- MessengerCache
                      03/09/2008 18:51:59 512 byte 0 days old -- ~DF649F.tmp
                      03/09/2008 18:51:59 327680 byte 0 days old -- ~DF6346.tmp
                      03/09/2008 18:52:09 327680 byte 0 days old -- ~DF7FF0.tmp
                      03/09/2008 18:52:09 512 byte 0 days old -- ~DF816C.tmp
                      03/09/2008 18:53:42 49152 byte 0 days old -- ~DFFF5A.tmp
                      03/09/2008 18:54:45 27 byte 0 days old -- systemscan.ini
                      03/09/2008 18:54:46 (DIR) 0 byte 0 days old -- nsv5240.tmp
                      03/09/2008 18:54:46 16384 byte 0 days old -- ~DFF456.tmp

                      ===================== SCHEDULED JOBS =====================

                      jobs found in C:\Windows:

                      03/09/2008 01:20:12 32588 byte 0 days old -- C:\Windows\tasks\SCHEDLGU.TXT
                      03/09/2008 11:20:38 6 byte 0 days old -- C:\Windows\tasks\SA.DAT
                      03/09/2008 17:23:40 418 byte 0 days old -- C:\Windows\tasks\User_Feed_Synchronization-{3EAC1D4D-09E8-407F-A9C1-2FF444FAAF27}.job
                      03/09/2008 18:11:32 254 byte 0 days old -- C:\Windows\tasks\Vérifier les mises à jour de Windows Live Toolbar.job
                      ~~~~~~~~~~~~~~~~~~~~~
                      Active jobs:

                      ~~~~~~~~~~~~~~~~~~~~~
                      Most recent (50) lines in jobs scheduled log:

                      ===================== SUSPICIOUS FILES =====================
                      EXE and DLL files packed with runtime packers, found in: C:\; C:\Windows\; C:\Windows\system32\

                      C:\Windows\zipinst.exe --> is compressed with UPX

                      ==========================================
                      Scan completed in 0,7 minutes
                      End of report

                      ~~~~~~~~~~~~~~~~~~~~~-----CREDITS-----~~~~~~~~~~~~~~~~~~~~~
                      SystemScan uses some freeware tools that remain property of their authors:

                      * SteelWerX Registry Console Tool, Who Am I (Bobby Flekman: www.xs4all.nl/~fstaal01) --> "Registry scan", "PC accounts "
                      * dumphive (Markus Stephany)--> "Registry scan"
                      * Listdlls (M.Russinovich, B.Cogswell: www.sysinternals.com) --> "Loaded modules"
                      * Catchme & MBR Rootkit detector (gmer: www.gmer.net) --> "Hidden objects", "Alternate Data Streams" & "Master Boot Record"
                      ---> NOTE: SystemScan integrates "The Avenger" from Swandog46 (http://swandog46.geekstogo.com) to allow you to remove malwares found in this log

                      Thanks to all of them for their hard work
                      0
                      1. Contributeur sécurité
                        Re,

                        on va essayer de voir plus avant de l'utiliser.

                        Télécharge ce programme puis double clic dessus (ferme ton antivirus s'il te détecte quoi que ce soit)
                        http://www.suspectfile.com/systemscan/

                        Clique sur Unselect all

                        * Coche uniquement ces cases, décoche tout le reste :

                        - Recent Files, 30 days

                        - Scheduled jobs

                        - Suspicious files

                        Puis clic sur scan now, sois patient.
                        Une fois le scan terminé, un rapport va s'ouvrir, copie et colle son contenu ici et vérifie qu'il soit bien en entier, si besoin crée deux messages
                        0
                        1. ca fait une semaine que ce probleme est apparu.Pour le programme que tu ma conseillé j ai eter voir le tuto et cela me fait un peur car j ai appris que ca pouvait comporter un certain nombre de risque
                          0
                          1. Contributeur sécurité
                            Bonjour,

                            de quand date ton ralentissement ?

                            Télécharge combofix (par sUBs) ici :

                            http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                            et enregistre le sur le bureau.

                            Déconnecte toi d'internet et ferme toutes tes applications.

                            Désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

                            Double-clique sur combofix.exe et suis les instructions

                            A la fin, il va produire un rapport C:\ComboFix.txt

                            Réactive ton parefeu, ton antivirus, la garde de ton antispyware

                            copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

                            Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

                            Tu as un tutoriel complet ici :

                            http://www.bleepingcomputer.com/combofix/f...iliser-combofix
                            0
                            • 1
                            • 2