Un fort ralentissement de windows

Résolu
Bonsoir , voilà j'ai un problème , sans doute un virus ou quelques choses comme cela . Mon ordinateur ralentit beaucoup de fois , voir tous le temps... Lorsque je veux fermer une fenêtre , elle met 5 min a se fermé , lorsque je veux lire une musique pareil 5min le temps qu'elle charge , quand je veux ouvrir "mes documents" ca fait beaucoup de temps et quand je veux ouvrir poste de travail , ca charge en me mettant une sorte d'ampoule rouge qui se déplace , sinon quand j'écris là , bah ca rame tèlement que je voie même pas ce que j'écris . Pourtant j'ai tout fermé , là j'ai que mozilla et ca rame , j'ai 1.5 GO de ram , j'ai windows xp , service pack 3 . J'aimerais que quelqu'un voit mon rapport et me dise s'il y a un virus ou autres , merci de votre aide .

p.s : Il y a une semaine , même voir 2 , mon ordinateur fonctionnait très bien et je n'ai rien installé depuis .

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:23:29, on 29/01/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZSTC09.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZENG09.exe
C:\Program Files\HP\Digital Imaging\bin\Hpqdirec.exe
C:\Program Files\eMule\eMule.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\geffray\Mes documents\Téléchargements\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe

--
End of file - 5070 bytes
Configuration: Windows XP
Firefox 3.5.7

33 réponses

Résumé de la discussion

Un ralentissement important et constant sur Windows XP SP3 avec 1,5 Go de RAM, incluant des retards à fermer les fenêtres, lire de la musique et ouvrir les documents. Des solutions et analyses ont été proposées, notamment des rapports de sécurité et l'utilisation d'outils de suppression et de diagnostic pour détecter virus, adware ou rootkit. Parmi les approches discutées, l'exécution d'ad-remover et d'autres outils (RSIT, GMER) est suggérée après désactivation temporaire des protections, afin d'obtenir des rapports détaillés et cibler les éléments démarrés. Enfin, la discussion souligne l'importance de partager ces rapports pour orienter le nettoyage et d'enquêter sur les programmes comme eMule et les composants Java, afin de prévenir de futures infections.

Bobot (l’IA à votre service)
  1. salut commence déjà par faire un scan complet de ton ordi
    0
    1. C:\Program Files\eMule\eMule.exe

      pour moi ça veut tout dire

      eMule = VIRUS
      0
      1. je ne suis pas contre les logiciels de téléchargements mais je suis contre ceux qui sont illégaux (en gros presque tous ...)
        0
        1. J'ai déjà tout fais , adware se pro , ccleaner , regcleaner , avast , et encore d'autre . Sinon emule je l'ai depuis + de 1 ans donc tu es sur que ca vient de ca ?
          0
          1. Contributeur sécurité
            bonsoir

            • Télécharge Random's System Information Tool (RSIT) de Random/Random.

            (outil de diagnostic)

            http://images.malwareremoval.com/random/RSIT.exe

            • Enregistre le sur ton Bureau.

            • Double clique sur RSIT.exe pour lancer l'outil.

            • Clique sur "Continue" à l'écran Disclaimer.

            • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

            et tu devras accepter la licence.

            • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

            Les rapports se trouvent à cet endroit:
            C:\rsit\info.txt
            C:\rsit\log.txt
            0
            1. info.txt logfile of random's system information tool 1.06 2010-01-30 13:44:13

              ======Uninstall list======

              -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
              Ad-Aware SE Personal-->C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
              Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
              ATI Control Panel-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
              ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
              avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
              CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
              C-Media WDM Audio Driver-->C:\WINDOWS\system32\cmirmdrv.exe
              Code de la route-->"C:\Program Files\Anuman Interactive\Code de la route - Evaluation\unins000.exe"
              DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
              eMule-->"C:\Program Files\eMule\Uninstall.exe"
              HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
              HP Image Zone 3.5-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
              HP PSC & OfficeJet 3.5-->"C:\Program Files\HP\Digital Imaging\{0FABD3D7-3036-4e78-B29D-58957ADB0A12}\setup\hpzscr01.exe" -datfile hposcr03.dat
              HP Software Update-->MsiExec.exe /X{34957B51-9676-41CE-9E52-44AE91B73F1C}
              Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
              Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
              Java(TM) 6 Update 16-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
              Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
              Language pack for Ad-Aware SE-->C:\PROGRA~1\Lavasoft\AD-AWA~1\Plugins\Langs\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\Plugins\Langs\INSTALL.LOG
              Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
              LimeWire 5.3.6-->"C:\Program Files\LimeWire\uninstall.exe"
              livebox-->C:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe -runfromtemp -l0x040c -removeonly
              Logiciel d'archivage WinRAR-->C:\Program Files\WinRAR\uninstall.exe
              Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
              Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
              Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
              Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
              Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{72AD53CC-CCC0-3757-8480-9EE176866A7C}
              Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
              Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{0BD83598-C2EF-3343-847B-7D2E84599128}
              Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
              Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
              Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
              Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
              Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB974455)-->"C:\WINDOWS\ie7updates\KB974455-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB976325)-->"C:\WINDOWS\ie7updates\KB976325-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB978207)-->"C:\WINDOWS\ie7updates\KB978207-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
              Mise à jour pour Windows Internet Explorer 7 (KB976749)-->"C:\WINDOWS\ie7updates\KB976749-IE7\spuninst\spuninst.exe"
              Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
              Mozilla Firefox (3.5.7)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
              MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
              MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
              MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
              Nero OEM-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
              OpenOffice.org 3.1-->MsiExec.exe /I{0FA44E79-CD7D-4E8D-A2EE-26FE05F509B6}
              Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
              TuneUp Utilities 2009-->MsiExec.exe /I{55A29068-F2CE-456C-9148-C869879E2357}
              Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
              WarRock-->C:\Program Files\InstallShield Installation Information\{00D15456-F679-4AD4-8BD2-56450D4C3F72}\setup.exe -runfromtemp -l0x0009 -removeonly
              Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
              Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
              Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
              Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
              Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
              Windows Live OneCare safety scanner-->RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
              Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll

              ======Security center information======

              AV: avast! antivirus 4.8.1368 [VPS 100130-0]

              ======System event log======

              Computer Name: GEFFRAY-JJBY9W0
              Event Code: 7035
              Message: Un contrôle Démarrer a correctement été envoyé au service aswRdr.

              Record Number: 2447
              Source Name: Service Control Manager
              Time Written: 20091224165705.000000+060
              Event Type: Informations
              User: AUTORITE NT\SYSTEM

              Computer Name: GEFFRAY-JJBY9W0
              Event Code: 7036
              Message: Le service Téléphonie est entré dans l'état : en cours d'exécution.

              Record Number: 2446
              Source Name: Service Control Manager
              Time Written: 20091224165705.000000+060
              Event Type: Informations
              User:

              Computer Name: GEFFRAY-JJBY9W0
              Event Code: 7035
              Message: Un contrôle Démarrer a correctement été envoyé au service Service de découvertes SSDP.

              Record Number: 2445
              Source Name: Service Control Manager
              Time Written: 20091224165704.000000+060
              Event Type: Informations
              User: AUTORITE NT\SYSTEM

              Computer Name: GEFFRAY-JJBY9W0
              Event Code: 7036
              Message: Le service NLA (Network Location Awareness) est entré dans l'état : en cours d'exécution.

              Record Number: 2444
              Source Name: Service Control Manager
              Time Written: 20091224165704.000000+060
              Event Type: Informations
              User:

              Computer Name: GEFFRAY-JJBY9W0
              Event Code: 7035
              Message: Un contrôle Démarrer a correctement été envoyé au service NLA (Network Location Awareness).

              Record Number: 2443
              Source Name: Service Control Manager
              Time Written: 20091224165704.000000+060
              Event Type: Informations
              User: AUTORITE NT\SYSTEM

              =====Application event log=====

              Computer Name: GEFFRAY-JJBY9W0
              Event Code: 1000
              Message: Les compteurs de performances pour le service ContentIndex (ContentIndex) ont été chargés.
              Les données d'enregistrement contiennent les nouvelles valeurs d'index
              assignées à ce service.

              Record Number: 5
              Source Name: LoadPerf
              Time Written: 20091129132727.000000+060
              Event Type: Informations
              User:

              Computer Name: GEFFRAY-JJBY9W0
              Event Code: 1000
              Message: Les compteurs de performances pour le service TermService (Services Terminal Server) ont été chargés.
              Les données d'enregistrement contiennent les nouvelles valeurs d'index
              assignées à ce service.

              Record Number: 4
              Source Name: LoadPerf
              Time Written: 20091129132725.000000+060
              Event Type: Informations
              User:

              Computer Name: GEFFRAY-JJBY9W0
              Event Code: 1000
              Message: Les compteurs de performances pour le service RemoteAccess (Routage et accès distant) ont été chargés.
              Les données d'enregistrement contiennent les nouvelles valeurs d'index
              assignées à ce service.

              Record Number: 3
              Source Name: LoadPerf
              Time Written: 20091129132620.000000+060
              Event Type: Informations
              User:

              Computer Name: GEFFRAY-JJBY9W0
              Event Code: 1000
              Message: Les compteurs de performances pour le service PSched (PSched) ont été chargés.
              Les données d'enregistrement contiennent les nouvelles valeurs d'index
              assignées à ce service.

              Record Number: 2
              Source Name: LoadPerf
              Time Written: 20091129132609.000000+060
              Event Type: Informations
              User:

              Computer Name: GEFFRAY-JJBY9W0
              Event Code: 1000
              Message: Les compteurs de performances pour le service RSVP (QoS RSVP) ont été chargés.
              Les données d'enregistrement contiennent les nouvelles valeurs d'index
              assignées à ce service.

              Record Number: 1
              Source Name: LoadPerf
              Time Written: 20091129132609.000000+060
              Event Type: Informations
              User:

              ======Environment variables======

              "ComSpec"=%SystemRoot%\system32\cmd.exe
              "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\ATI-CPanel
              "windir"=%SystemRoot%
              "OS"=Windows_NT
              "PROCESSOR_ARCHITECTURE"=x86
              "PROCESSOR_LEVEL"=6
              "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 8 Stepping 1, AuthenticAMD
              "PROCESSOR_REVISION"=0801
              "NUMBER_OF_PROCESSORS"=1
              "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
              "TEMP"=%SystemRoot%\TEMP
              "TMP"=%SystemRoot%\TEMP
              "FP_NO_HOST_CHECK"=NO

              -----------------EOF-----------------
              0
              1. Logfile of random's system information tool 1.06 (written by random/random)
                Run by geffray at 2010-01-30 13:42:36
                Microsoft Windows XP Édition familiale Service Pack 3
                System drive C: has 25 GB (61%) free of 41 GB
                Total RAM: 1279 MB (27% free)

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 13:43:19, on 30/01/2010
                Platform: Windows XP SP3 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16981)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Java\jre6\bin\jqs.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\System32\TUProgSt.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                C:\Program Files\Java\jre6\bin\jusched.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZSTC09.exe
                C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZENG09.exe
                C:\Program Files\HP\Digital Imaging\bin\Hpqdirec.exe
                C:\Program Files\eMule\emule.exe
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                C:\Program Files\Windows Live\Contacts\wlcomm.exe
                C:\Program Files\Alwil Software\Avast4\setup\avast.setup
                C:\Program Files\Mozilla Firefox\firefox.exe
                C:\Documents and Settings\geffray\Mes documents\Téléchargements\RSIT.exe
                C:\Program Files\trend micro\geffray.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
                O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
                O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
                0
                1. Contributeur sécurité
                  rien d'apparent dans ces rapports

                  Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

                  ▶ Télécharge et installe List&Kill'em et enregistre le sur ton bureau
                  http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

                  double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

                  coche la case "creer une icone sur le bureau"

                  une fois terminée , clic sur "terminer" et le programme se lancer seul

                  choisis la langue puis choisis l'option 1 = Mode Recherche

                  ▶ laisse travailler l'outil

                  à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

                  un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

                  ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

                  tu peux supprimer le rapport catchme.log de ton bureau maintenant.

                  0
                  1. List'em by g3n-h@ckm@n 1.2.1.2
                    User : geffray (Administrateurs)
                    Update on 29/01/2010 by g3n-h@ckm@n ::::: 11:50
                    Start at: 14:19:38 | 30/01/2010
                    Contact : g3n-h@ckm@n sur CCM

                    AMD Athlon(tm) XP 1900+
                    Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                    Internet Explorer 7.0.5730.13
                    Windows Firewall Status : Enabled
                    AV : avast! antivirus 4.8.1368 [VPS 100130-0] 4.8.1368 [ (!) Disabled | Updated ]

                    C:\ -> Disque fixe local | 40 Go (24,34 Go free) | NTFS
                    D:\ -> Disque fixe local | 109,04 Go (105,85 Go free) [Travail] | NTFS
                    E:\ -> Disque CD-ROM
                    F:\ -> Disque CD-ROM
                    G:\ -> Disque amovible | 1,92 Go (1,86 Go free) | FAT

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\csrss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Java\jre6\bin\jqs.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\System32\TUProgSt.exe
                    C:\WINDOWS\System32\alg.exe
                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    C:\Program Files\Java\jre6\bin\jusched.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZSTC09.exe
                    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZENG09.exe
                    C:\Program Files\HP\Digital Imaging\bin\Hpqdirec.exe
                    C:\Program Files\eMule\emule.exe
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                    C:\Program Files\Windows Live\Contacts\wlcomm.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\WINDOWS\system32\wscntfy.exe
                    C:\Program Files\List_Kill'em\List_Kill'em.scr
                    C:\WINDOWS\system32\cmd.exe
                    C:\WINDOWS\system32\wbem\wmiprvse.exe
                    C:\Documents and Settings\geffray\Local Settings\Temp\1DE.tmp\pv.exe

                    ======================
                    Keys "Run"
                    ======================
                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    SunJavaUpdateSched REG_SZ C:\Program Files\Java\jre6\bin\jusched.exe

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                    =====================
                    Other Keys
                    =====================
                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                    dontdisplaylastusername REG_DWORD 0 (0x0)
                    legalnoticecaption REG_SZ
                    legalnoticetext REG_SZ
                    shutdownwithoutlogon REG_DWORD 1 (0x1)
                    undockwithoutlogon REG_DWORD 1 (0x1)

                    ===============
                    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                    NoDriveTypeAutoRun REG_DWORD 145 (0x91)

                    ===============
                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                    HonorAutoRunSetting REG_DWORD 1 (0x1)

                    ===============
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                    AppInit_DLLS REG_SZ

                    ===============
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

                    ===============
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                    {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

                    ===============
                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                    %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                    C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                    %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
                    C:\Program Files\LimeWire\LimeWire.exe REG_SZ C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
                    C:\Program Files\eMule\emule.exe REG_SZ C:\Program Files\eMule\emule.exe:*:Enabled:eMule
                    D:\Documents Fabien\Xfire\Xfire.exe REG_SZ D:\Documents Fabien\Xfire\Xfire.exe:*:Enabled:Xfire

                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                    %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                    C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                    %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000

                    ===============
                    ActivX controls
                    ===============
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5ED80217-570B-4DA9-BF44-BE107C0EC166}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6414512B-B978-451D-A0D8-FCFDF33E833C}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}

                    ===============
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{411EDCF7-755D-414E-A74B-3DCD6583F589}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5056b317-8d4c-43ee-8543-b9d1e234b8f4}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{72AD53CC-CCC0-3757-8480-9EE176866A7C}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9A394342-4A68-4EBA-85A6-55B559F4E700}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{eddbec60-89cb-44ef-8291-0850fd28ff6a}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{F5776D81-AE53-4935-8E84-B0B283D8BCEF}

                    ==============
                    BHO :
                    ======
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

                    ================
                    Internet Explorer :
                    ================
                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                    Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                    Start Page REG_SZ https://www.google.fr/?gws_rd=ssl

                    ========
                    Services
                    ========
                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                    Ndisuio : 0x3
                    EapHost : 0x3
                    SharedAccess : 0x2
                    wuauserv : 0x2

                    =========
                    Atapi.sys
                    =========

                    %%%% HASHDEEP-1.0
                    %%%% size,md5,sha256,filename
                    ## Invoked from: C:\Documents and Settings\geffray\Local Settings\Temp\1DE.tmp
                    ## C:\> hashdeep C:\WINDOWS\System32\Drivers\atapi.sys
                    ##
                    96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\System32\Drivers\atapi.sys

                    Sources
                    =======

                    C:\WINDOWS\ServicePackFiles\i386\atapi.sys
                    C:\WINDOWS\system32\drivers\atapi.sys

                    Référence :
                    ==========

                    Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                    Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                    Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                    Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                    Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                    Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                    Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

                    =======
                    Drive :
                    =======

                    D‚fragmenteur de disque Windows
                    Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

                    Rapport d'analyse
                    40,00 Go total, 26,97 Go libre (67%), 19% fragment‚ (fragmentation du fichier 38%)

                    Vous devriez d‚fragmenter ce volume.

                    ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                    Present !! : C:\WINDOWS\002303_.tmp
                    Present !! : C:\WINDOWS\005047_.tmp
                    Present !! : C:\WINDOWS\SET3.tmp
                    Present !! : C:\WINDOWS\SET7.tmp
                    Present !! : C:\WINDOWS\config.ini
                    Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
                    Present !! : C:\WINDOWS\System32\drivers\oreans32.sys
                    Present !! : C:\WINDOWS\System32\reboot.txt
                    Present !! : C:\WINDOWS\System32\SET9B.tmp
                    Present !! : C:\WINDOWS\System32\SET9F.tmp
                    Present !! : C:\WINDOWS\System32\SETA7.tmp

                    ¤¤¤¤¤¤¤¤¤¤ Keys :

                    Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                    Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                    Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
                    Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File execution Options\taskmgr.exe"
                    Present !! : HKLM\SYSTEM\ControlSet001\Enum\Root\Legacy_OREANS32
                    Present !! : HKLM\SYSTEM\ControlSet001\Services\oreans32
                    Present !! : HKLM\SYSTEM\ControlSet002\Enum\Root\Legacy_OREANS32
                    Present !! : HKLM\SYSTEM\ControlSet002\Services\oreans32
                    Present !! : HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_OREANS32
                    Present !! : HKLM\SYSTEM\CurrentControlSet\Services\oreans32
                    Present !! : HKLM\SYSTEM\CurrentControlSet\Services\oreans32\Security
                    Present !! : HKLM\SYSTEM\CurrentControlSet\Services\oreans32\Enum

                    ============

                    catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2010-01-30 15:50:37
                    Windows 5.1.2600 Service Pack 3 NTFS

                    scanning hidden processes ...

                    scanning hidden services & system hive ...

                    scanning hidden registry entries ...

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
                    "TracesProcessed"=dword:000035b8

                    scanning hidden files ...

                    scan completed successfully
                    hidden processes: 0
                    hidden services: 0
                    hidden files: 0

                    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                    device: opened successfully
                    user: MBR read successfully
                    kernel: MBR read successfully
                    user & kernel MBR OK

                    ==========
                    Programs
                    ==========

                    Ahead
                    Alwil Software
                    Anuman Interactive
                    CCleaner
                    Common Files
                    ComPlus Applications
                    DVD Shrink
                    eMule
                    Fichiers communs
                    HP
                    InstallShield Installation Information
                    Internet Explorer
                    Java
                    JRE
                    Lavasoft
                    LimeWire
                    List_Kill'em
                    Malwarebytes' Anti-Malware
                    Messenger
                    Microsoft
                    microsoft frontpage
                    Movie Maker
                    Mozilla Firefox
                    MSBuild
                    MSN
                    MSN Gaming Zone
                    MSXML 4.0
                    Navilog1
                    NetMeeting
                    OpenOffice.org 3
                    Outlook Express
                    Reference Assemblies
                    RegCleaner
                    SAGEM
                    Securitoo
                    Services en ligne
                    trend micro
                    TuneUp Utilities 2009
                    Uninstall Information
                    WarRock
                    Windows Live
                    Windows Live Safety Center
                    Windows Live SkyDrive
                    Windows Media Connect 2
                    Windows Media Player
                    Windows NT
                    WindowsUpdate
                    WinRAR
                    xerox

                    ============
                    Drive C:
                    ============

                    $CTJTMP
                    AddOn
                    ATI-CPanel
                    AUTOEXEC.BAT
                    boot.ini
                    Bootfont.bin
                    CONFIG.SYS
                    CTJINI.INI
                    Documentation en ligne
                    Documents and Settings
                    drvpnp.dat
                    IO.SYS
                    Kill'em
                    List'em.txt
                    MSDOS.SYS
                    NTDETECT.COM
                    ntldr
                    pagefile.sys
                    pnpID.dat
                    Program Files
                    RECYCLER
                    rsit
                    Setup.log
                    System Volume Information
                    WINDOWS

                    ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                    0
                    1. Contributeur sécurité
                      ▶ Relance List&Kill'em avec le raccourci sur ton bureau ,

                      mais cette fois-ci :

                      ▶ choisis l'option 2 = Mode Suppression

                      laisse travailler l'outil.

                      en fin de scan un rapport s'ouvre

                      ▶ colle le contenu dans ta reponse

                      Tu peux le désinstaller ensuite
                      0
                      1. Kill'em by g3n-h@ckm@n 1.2.1.2

                        User : geffray (Administrateurs)
                        Update on 29/01/2010 by g3n-h@ckm@n ::::: 11:50
                        Start at: 19:34:14 | 30/01/2010
                        Contact : g3n-h@ckm@n sur CCM

                        AMD Athlon(tm) XP 1900+
                        Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                        Internet Explorer 7.0.5730.13
                        Windows Firewall Status : Enabled
                        AV : avast! antivirus 4.8.1368 [VPS 100130-0] 4.8.1368 [ Enabled | Updated ]

                        C:\ -> Disque fixe local | 40 Go (26,83 Go free) | NTFS
                        D:\ -> Disque fixe local | 109,04 Go (105,85 Go free) [Travail] | NTFS
                        E:\ -> Disque CD-ROM
                        F:\ -> Disque CD-ROM | 629,8 Mo (0 Mo free) [EURO2] | CDFS

                        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\csrss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Java\jre6\bin\jqs.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\System32\TUProgSt.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\WINDOWS\System32\alg.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\DOCUME~1\geffray\LOCALS~1\Temp\HPZscr01.exe
                        C:\WINDOWS\system32\msiexec.exe
                        C:\Program Files\List_Kill'em\List_Kill'em.scr
                        C:\WINDOWS\system32\cmd.exe
                        C:\WINDOWS\system32\wbem\wmiprvse.exe
                        C:\Documents and Settings\geffray\Local Settings\Temp\30.tmp\ERUNT.EXE
                        C:\Documents and Settings\geffray\Local Settings\Temp\30.tmp\pv.exe

                        Detections :
                        ==========

                        ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                        Quarantined & Deleted !! : C:\WINDOWS\002303_.tmp
                        Quarantined & Deleted !! : C:\WINDOWS\005047_.tmp
                        Quarantined & Deleted !! : C:\WINDOWS\SET3.tmp
                        Quarantined & Deleted !! : C:\WINDOWS\SET7.tmp
                        Quarantined & Deleted !! : C:\WINDOWS\config.ini

                        Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
                        Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\oreans32.sys
                        Quarantined & Deleted !! : C:\WINDOWS\System32\reboot.txt
                        Quarantined & Deleted !! : C:\WINDOWS\System32\SET9B.tmp
                        Quarantined & Deleted !! : C:\WINDOWS\System32\SET9F.tmp
                        Quarantined & Deleted !! : C:\WINDOWS\System32\SETA7.tmp
                        Quarantined & Deleted !! : C:\Documents and Settings\geffray\LOCAL Settings\Temp\hpzmsi01.exe
                        Quarantined & Deleted !! : C:\Documents and Settings\geffray\LOCAL Settings\Temp\HPZscr01.exe

                        ==============
                        host file OK !
                        ==============

                        ========
                        Registry
                        ========
                        Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}

                        ============
                        Disk Cleaned
                        ============

                        ================
                        Prefetch cleaned
                        ================

                        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                        0
                        1. Quelques questions :
                          - D'où venait mon problème ?
                          - Es ce qu'il est résolue ? Mon ordi a l'air d'avancé plus vite même s'il rame encore un peu
                          - Es ce que avast est un bon anti-virus ? J'ai entendu parlé de Microsoft Security Essential , est-il bien ?
                          0
                          1. Contributeur sécurité
                            reposes tes questions à la fin (j'aurais oublé d'ici là)

                            Téléchargez MalwareByte's Anti-Malware

                            http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                            . Enregistres le sur le bureau
                            . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
                            . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
                            . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
                            . Une fois la mise à jour terminé
                            . Rend-toi dans l'onglet, Recherche
                            . Sélectionnes Exécuter un examen complet (examen assez long)
                            . Cliques sur Rechercher
                            . Le scan démarre.
                            . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
                            . Cliques sur Ok pour poursuivre.
                            . Si des malwares ont été détectés, clique sur Afficher les résultats
                            . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                            . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                            . Rends toi dans l'onglet rapport/log
                            . Tu cliques dessus pour l'afficher, une fois affiché
                            . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
                            . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
                            . tu cliques droit dans le cadre de la reponse et coller

                            Si tu as besoin d'aide regarde ces tutoriels :
                            Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                            http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam
                            0
                            1. Malwarebytes' Anti-Malware 1.44
                              Version de la base de données: 3663
                              Windows 5.1.2600 Service Pack 3
                              Internet Explorer 7.0.5730.13

                              30/01/2010 21:47:48
                              mbam-log-2010-01-30 (21-47-48).txt

                              Type de recherche: Examen complet (C:\|D:\|)
                              Eléments examinés: 177446
                              Temps écoulé: 41 minute(s), 48 second(s)

                              Processus mémoire infecté(s): 0
                              Module(s) mémoire infecté(s): 0
                              Clé(s) du Registre infectée(s): 0
                              Valeur(s) du Registre infectée(s): 0
                              Elément(s) de données du Registre infecté(s): 0
                              Dossier(s) infecté(s): 0
                              Fichier(s) infecté(s): 0

                              Processus mémoire infecté(s):
                              (Aucun élément nuisible détecté)

                              Module(s) mémoire infecté(s):
                              (Aucun élément nuisible détecté)

                              Clé(s) du Registre infectée(s):
                              (Aucun élément nuisible détecté)

                              Valeur(s) du Registre infectée(s):
                              (Aucun élément nuisible détecté)

                              Elément(s) de données du Registre infecté(s):
                              (Aucun élément nuisible détecté)

                              Dossier(s) infecté(s):
                              (Aucun élément nuisible détecté)

                              Fichier(s) infecté(s):
                              (Aucun élément nuisible détecté)
                              0
                              1. Contributeur sécurité
                                puisqu'il rame encore un peu dis tu

                                fais ceci

                                1)
                                Téléchargez et enregistrez le fichier d installation sur le bureau
                                http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe

                                Double cliquez sur le fichier d'installation de AD-Remover, le programme s'installera automatiquement.
                                Sous Vista : clic droit sur AD-Remover et sélectionner "Exécuter en tant qu'administrateur"
                                Au menu principal choisir Option L Lancer le nettoyage
                                et tapez sur [entrée] .
                                Laissez travailler l'outil et ne touchez à rien ...
                                Postez le rapport qui apparait à la fin.

                                ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

                                (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                Note :Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                                Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                                Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                                .......................

                                2)
                                /!\ Il faut impérativement désactiver tous tes logiciels de protection pour utiliser ce programme/!\

                                ▶ Télécharge : Gmer (by Przemyslaw Gmerek)

                                http://www.gmer.net/

                                ▶ Dezippe gmer ,cliques sur l'onglet rootkit,lances le scan,des lignes rouges vont apparaitre.

                                ▶ Les lignes rouges indiquent la presence d'un rootkit.Postes moi le rapport gmer (cliques sur copy,puis vas dans demarrer ,puis ouvres le bloc note,vas dans edition et cliques sur coller,le rapport gmer va apparaitre,postes moi le)

                                Ensuite

                                ▶ sur les lignes rouge:

                                ▶ Services:cliques droit delete service
                                ▶ Process:cliques droit kill process
                                ▶ Adl ,file:cliques droit delete files

                                1
                                1. .
                                  ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
                                  .
                                  Mis à jour par C_XX le 29.01.2010 à 16:43
                                  Contact: AdRemover.contact@gmail.com
                                  Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                                  .
                                  Lancé à: 22:22:03, 30/01/2010 | Mode Normal | Option: CLEAN
                                  Exécuté de: C:\Ad-Remover\
                                  Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
                                  Nom du PC: GEFFRAY-JJBY9W0 | Utilisateur actuel: geffray
                                  .
                                  ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                                  .

                                  (!) -- Fichiers temporaires supprimés.

                                  .
                                  HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                                  .
                                  ============== Scan additionnel ==============
                                  .
                                  .
                                  * Mozilla FireFox Version 3.5.7 [fr] *
                                  .
                                  Nom du profil: ipye5b18.default (geffray)
                                  .
                                  (geffray, prefs.js) Browser.download.lastDir, C:\Documents and Settings\geffray\Bureau
                                  (geffray, prefs.js) Extensions.enabledItems, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1,{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16,jqs@sun.com:1.0,{20a82645-c095-46ed-80e3-08825760534b}:0.0.0,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.7
                                  .
                                  .
                                  .
                                  * Internet Explorer Version 7.0.5730.13 *
                                  .
                                  [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                                  .
                                  Do404Search: 01000000
                                  Local Page: C:\WINDOWS\system32\blank.htm
                                  Show_ToolBar: yes
                                  Start Page: hxxp://fr.msn.com/
                                  Enable Browser Extensions: yes
                                  Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                  Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                  Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                                  .
                                  [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                                  .
                                  Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                  Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                  Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                  Delete_Temp_Files_On_Exit: yes
                                  Local Page: %SystemRoot%\system32\blank.htm
                                  Start Page: hxxp://fr.msn.com/
                                  Search Bar: hxxp://search.msn.com/spbasic.htm
                                  .
                                  [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                                  .
                                  Tabs: res://ieframe.dll/tabswelcome.htm
                                  .
                                  ===================================
                                  .
                                  2215 Octet(s) - C:\Ad-Report-CLEAN[1].log
                                  .
                                  248 Fichier(s) - C:\DOCUME~1\geffray\LOCALS~1\Temp
                                  16 Fichier(s) - C:\WINDOWS\Temp
                                  9 Fichier(s) - C:\WINDOWS\Prefetch
                                  .
                                  18 Fichier(s) - C:\Ad-Remover\BACKUP
                                  0 Fichier(s) - C:\Ad-Remover\QUARANTINE
                                  .
                                  Fin à: 22:25:37 | 30/01/2010 - CLEAN[1]
                                  .
                                  ============== E.O.F ==============
                                  .
                                  0
                                  1. Contributeur sécurité
                                    vu

                                    ==> GMER
                                    0
                                    1. Et pour l'autre analyse , après 6h d'analyse , mon ordinateur c'est éteint . Es ce normal ?
                                      0
                                      1. Je suis entrain de refaire le scan...
                                        Quelques indications sur la fenêtre :
                                        - Il y a des onglets , processes , modules , services , fils , registry , rootkit , autostart , CMD
                                        - Sur la coté droit , il y a des cases coché , system , sections , IAT/EAT , Dervices , module , processes , threads , libraries , service , registry , fils . En dessous ya C:\ de coché mais D:\ n'est pas coché , ensuite en dessous y a ADS qui est coché , et enfin en dessous y a stop , copy , save ...

                                        Sinon quand je lance l'analyse , je ne voie pas de lignes rouges , enfin pas encore .
                                        0
                                        1. Contributeur sécurité
                                          ok

                                          essayons d'aller jusqu'au bout du scan

                                          si ca coince encore, dis le
                                          0
                                          • 1
                                          • 2