
Je vous fait par d'un scan d'un ordi d'un collègue à moi qui à une lenteur exceptionnelle

Voici le rapport : http://ww60me.dl4free.com/
Je vous remercie

![]() ![]() ![]() ![]() ![]() ![]() ![]() |
[HKLM\Software\Classes\TypeLib\{2D5E2D34-BED5-4B9F-9793-A31E26E6806E}]
[HKLM\Software\Classes\CLSID\{E49F0B41-3322-11D4-AEFE-00C04F61025C}]
[HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{32099aac-c132-4136-9e9a-4e364a424e17}
C:\Program Files\DAEMON Tools Toolbar
O4 - HKLM\..\Run: [KernelFaultCheck] Clé orpheline
O47 - AAKE:Key Export SP - "C:\Program Files\RemoteDesktopServer\RemoteDesktopServer.exe" [Enabled] .(...) -- C:\Program Files\RemoteDesktopServer\RemoteDesktopServer.exe (.not file.) =
O47 - AAKE:Key Export SP - "C:\Documents and Settings\eleve\Bureau\Jeux\Counter Strike Source 2010\hl2.exe" [Enabled] .(...) -- C:\Documents and Settings\eleve\Bureau\Jeux\Counter Strike Source 2010\hl2.exe (.not file.)
O47 - AAKE:Key Export SP - "C:\Documents and Settings\eleve\Bureau\Jeux\UrbanTerror\ioUrTded.exe" [Enabled] .(...) -- C:\Documents and Settings\eleve\Bureau\Jeux\UrbanTerror\ioUrTded.exe (.not file.)
O47 - AAKE:Key Export SP - "E:\Portal 2\portal2.exe" [Enabled] .(...) -- E:\Portal 2\portal2.exe (.not file.)
O47 - AAKE:Key Export SP - "C:\Documents and Settings\eleve\Bureau\Jeux\Portal 2\portal2.exe" [Enabled] .(...) -- C:\Documents and Settings\eleve\Bureau\Jeux\Portal 2\portal2.exe (.not file.)
O51 - MPSK:{0eaa7863-326d-11df-ab15-001d09a422e2}\AutoRun\command. (...) -- C:\WINDOWS\system32\copy.exe (.not file.)
O51 - MPSK:{3e9431e0-19b5-11e1-ae3f-001e4cb364d8}\AutoRun\command - Clé orpheline
O51 - MPSK:{92952dc8-ea60-11e0-adac-001e4cb364d8}\AutoRun\command - Clé orpheline
FirewallRaz
O4 - HKLM\..\Run: [Apoint] . (.Alps Electric Co., Ltd. - Alps Pointing-device Driver.) -- C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] . (.SigmaTel, Inc. - Sigmatel Audio system tray application.) -- C:\WINDOWS\stsystra.exe
O4 - HKLM\..\Run: [Document Manager] . (...) -- C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
O4 - HKLM\..\Run: [SecureUpgrade] . (.Wave Systems Corp. - Check For Later Product Line.) -- C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] . (.Dell Inc. - Dell Wireless WLAN Card Wireless Network Tr.) -- C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] . (.Logitech Inc. - Logitech KHAL Main Process.) -- C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.exe
O4 - HKLM\..\Run: [KADxMain] . (.Knowles Acoustics - IntelliSonic Systray Control (KADxMain).) -- C:\WINDOWS\system32\KADxMain.exe
O4 - HKLM\..\Run: [ISUSPM Startup] . (.InstallShield Software Corporation - InstallShield Update Service Update Manager.) -- C:\Program Files\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe
O4 - HKLM\..\Run: [ISUSScheduler] . (.InstallShield Software Corporation - InstallShield Update Service Scheduler.) -- C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
O4 - HKLM\..\Run: [HP Software Update] . (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files\HP\HP Software Update\hpwuschd2.exe
O4 - HKLM\..\Run: [IRIScan 2 button manager] . (.Pas de propriétaire - Button Manager for IRISCAN 2.) -- C:\Program Files\iriscn2i\bmanm12.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] . (.Microsoft Corporation - ActiveSync Connection Manager.) -- C:\Program Files\Microsoft ActiveSync\wcescomm.exe
O4 - HKCU\..\Run: [SuperCopier2.exe] . (.SFX TEAM - SuperCopier 2 (explorer file copy replaceme.) -- C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-3133144714-2041869446-3642991958-1005\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-3133144714-2041869446-3642991958-1005\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-21-3133144714-2041869446-3642991958-1005\..\Run: [H/PC Connection Agent] . (.Microsoft Corporation - ActiveSync Connection Manager.) -- C:\Program Files\Microsoft ActiveSync\wcescomm.exe
O4 - HKUS\S-1-5-21-3133144714-2041869446-3642991958-1005\..\Run: [SuperCopier2.exe] . (.SFX TEAM - SuperCopier 2 (explorer file copy replaceme.) -- C:\Program Files\SuperCopier2\SuperCopier2.exe
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 172.16.*;<local>
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.0.1:3128
RogueKiller V6.2.0 [12/12/2011] par Tigzy
mail: tigzyRK<at>gmail<dot>com
Remontees: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
Blog: http://tigzyrk.blogspot.com
Systeme d'exploitation: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Demarrage : Mode normal
Utilisateur: eleve [Droits d'admin]
Mode: Suppression -- Date : 14/12/2011 11:03:30
¤¤¤ Processus malicieux: 0 ¤¤¤
¤¤¤ Entrees de registre: 5 ¤¤¤
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (172.16.0.1:3128) -> NOT REMOVED, USE PROXYFIX
[HJ] HKLM\[...]\SystemRestore : DisableSR (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[HJ] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[HJ] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ Fichier HOSTS: ¤¤¤
127.0.0.1 localhost
¤¤¤ MBR Verif: ¤¤¤
--- User ---
[MBR] 5e7c78608594bffe02908c70f22ef588
[BSP] 3329334a3c2bf778d333cb41b65e7d57 : MBR Code unknown
Partition table:
0 - [XXXXXX] FAT16 [HIDDEN!] Offset (sectors): 63 | Size: 164 Mo
1 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 321300 | Size: 59838 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Termine : << RKreport[1].txt >>
RKreport[1].txt
RogueKiller V6.2.0 [12/12/2011] par Tigzy
mail: tigzyRK<at>gmail<dot>com
Remontees: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
Blog: http://tigzyrk.blogspot.com
Systeme d'exploitation: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Demarrage : Mode normal
Utilisateur: eleve [Droits d'admin]
Mode: Raccourcis RAZ -- Date : 14/12/2011 11:06:10
¤¤¤ Processus malicieux: 0 ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
Attributs de fichiers restaures:
Bureau: Success 16 / Fail 0
Lancement rapide: Success 0 / Fail 0
Programmes: Success 7 / Fail 0
Menu demarrer: Success 0 / Fail 0
Dossier utilisateur: Success 187 / Fail 0
Mes documents: Success 34 / Fail 0
Mes favoris: Success 0 / Fail 0
Mes images: Success 0 / Fail 0
Ma musique: Success 0 / Fail 0
Mes videos: Success 0 / Fail 0
Disques locaux: Success 782 / Fail 0
Sauvegarde: [NOT FOUND]
Lecteurs:
[C:] \Device\HarddiskVolume2 -- 0x3 --> Restored
[D:] \Device\CdRom0 -- 0x5 --> Skipped
[E:] \Device\Harddisk1\DP(1)0-0+18 -- 0x2 --> Restored
¤¤¤ Infection : ¤¤¤
Termine : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
Rapport de ZHPFix 1.12.3374 par Nicolas Coolman, Update du 05/12/2011
Fichier d'export Registre : C:\ZHP\ZHPExportRegistry-14-12-2011-11-07-19.txt
Run by eleve at 14/12/2011 11:07:19
Windows XP Professional Service Pack 3 (Build 2600)
Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
========== Clé(s) du Registre ==========
SUPPRIME Key: HKLM\Software\Classes\TypeLib\{2D5E2D34-BED5-4B9F-9793-A31E26E6806E}
SUPPRIME Key: HKLM\Software\Classes\CLSID\{E49F0B41-3322-11D4-AEFE-00C04F61025C}
SUPPRIME CLSID MPSK: {0eaa7863-326d-11df-ab15-001d09a422e2}
SUPPRIME CLSID MPSK: {3e9431e0-19b5-11e1-ae3f-001e4cb364d8}
SUPPRIME CLSID MPSK: {92952dc8-ea60-11e0-adac-001e4cb364d8}
========== Valeur(s) du Registre ==========
SUPPRIME [HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{32099aac-c132-4136-9e9a-4e364a424e17}
ABSENT RunValue: KernelFaultCheck
SUPPRIME AAKE KeyValue: C:\Program Files\RemoteDesktopServer\RemoteDesktopServer.exe
SUPPRIME AAKE KeyValue: C:\Documents and Settings\eleve\Bureau\Jeux\Counter Strike Source 2010\hl2.exe
SUPPRIME AAKE KeyValue: C:\Documents and Settings\eleve\Bureau\Jeux\UrbanTerror\ioUrTded.exe
SUPPRIME AAKE KeyValue: E:\Portal 2\portal2.exe
SUPPRIME AAKE KeyValue: C:\Documents and Settings\eleve\Bureau\Jeux\Portal 2\portal2.exe
SUPPRIME FirewallRaz (SP) : D:\setup\HPZNET01.EXE
SUPPRIME FirewallRaz (SP) : D:\setup\HPONICIFS01.EXE
Aucune valeur présente dans la clé d'exception du registre (FirewallRaz)
========== Dossier(s) ==========
SUPPRIME Folder: c:\program files\daemon tools toolbar
========== Fichier(s) ==========
ABSENT File: c:\program files\remotedesktopserver\remotedesktopserver.exe
ABSENT File: c:\documents and settings\eleve\bureau\jeux\counter strike source 2010\hl2.exe
ABSENT File: c:\documents and settings\eleve\bureau\jeux\urbanterror\iourtded.exe
ABSENT File: e:\portal 2\portal2.exe
ABSENT File: c:\documents and settings\eleve\bureau\jeux\portal 2\portal2.exe
========== Récapitulatif ==========
5 : Clé(s) du Registre
10 : Valeur(s) du Registre
1 : Dossier(s)
5 : Fichier(s)
End of clean in 00mn 02s
========== Chemin de fichier rapport ==========
C:\ZHP\ZHPFix[R1].txt - 14/12/2011 11:07:19 [2152]
Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 9 invités
![]() .: Nous contacter :: Flux RSS :: Données personnelles :. ![]() |