!salut NickW!
merci d'abord pour ton aide....
1/ Réponse à tes questions:
Mes ralentissements se déroulent avec ou sans connexion
internet.
J'en avais précédemment mais j'étais infecté... par des malwares, J'ai tout désinfecté (enfin je pense avoir fais le nécessaire...
Ils ont donc réapparu dernièrement et l'
antivirus, A2, Adware,Spybot,Etc, ne trouve plus rien...
Au niveau des mises à jour,J'ai télécharger pas mal d'utilitaire (antispyware+ maj, CCleaner,Regcleaner,...) + maj automatique Windows SP2 .
2/ petite question:
Sur mon log hijack,
j'ai 2 fois la ligne:
system 32\svchost.exe
estce normal????
3/ mon log dss:
Deckard's System Scanner v20071014.68
Run by Crousaud Emilie on 2008-06-13 16:37:05
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
9: 2008-06-13 14:37:10 UTC - RP267 - Deckard's System Scanner Restore Point
8: 2008-06-12 20:20:27 UTC - RP266 - Opération de restauration
7: 2008-06-11 15:52:38 UTC - RP265 - Removed Windows Defender
6: 2008-06-11 15:49:54 UTC - RP264 - ok
5: 2008-06-11 13:05:53 UTC - RP263 - Software Distribution Service 3.0
-- First Restore Point --
1: 2008-06-01 13:15:39 UTC - RP259 - Opération de restauration
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Crousaud Emilie.exe) -------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:37:49, on 13/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE:
Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Crousaud Emilie\Bureau\dss.exe
C:\DOCUME~1\CROUSA~1\Bureau\Crousaud Emilie.exe
R0 - HKCU\Software\Microsoft\
Internet Explorer\Main,Start Page =
http://www.google.fr/
R0 - HKCU\Software\Microsoft\
Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall
BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} -
http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partne ... nicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) -
http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/resourc ... oscan8.cab
O16 - DPF: {6531D99C-0D0E-4293-B3CB-A3E1D0D41847} (AhnASP Control) -
http://aspglobal.ahnlab.com/asp/cab/AhnASP.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} -
http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Me ... b56907.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Avira AntiVir Personal – Free
Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free
Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cycling Manager 2007 Drivers Auto Removal (pr2akt6c) (pr2akt6c) - Cyanide - C:\WINDOWS\system32\pr2akt6c.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TrueVector
Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 7306 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 prohlp02 (StarForce Protection Helper Driver v2) - c:\windows\system32\drivers\prohlp02.sys <Not>
R0 prosync1 (StarForce Protection Synchronization Driver v1) - c:\windows\system32\drivers\prosync1.sys <Not>
R0 sfhlp01 (StarForce Protection Helper Driver) - c:\windows\system32\drivers\sfhlp01.sys <Not>
R0 sisidex - c:\windows\system32\drivers\sisidex.sys <Not>
R0 SiSRaid - c:\windows\system32\drivers\sisraid.sys <Not>
R1 prodrv06 (StarForce Protection Environment Driver v6) - c:\windows\system32\drivers\prodrv06.sys <Not>
R1 sp_rsdrv2 (Spyware Terminator Driver 2) - c:\windows\system32\drivers\sp_rsdrv2.sys
S3 AgereSoftModem (Olitec Soft Modem) - c:\windows\system32\drivers\agrsm.sys <Not>
S3 DCamUSBSQTECH (Dual-Mode DSC(2770)) - c:\windows\system32\drivers\sqcaptur.sys <Not>
S3 driverhardwarev2 - c:\program files\ma-config.com\drivers\driverhardwarev2.sys <Not>
S3 e4usbaw (USB ADSL2 WAN Adapter) - c:\windows\system32\drivers\e4usbaw.sys <Not>
S3 PCAMPR5 (PCAMPR5 NDIS Protocol Driver) - c:\windows\system32\pcampr5.sys (file missing)
S3 PCANDIS5 (PCANDIS5 NDIS Protocol Driver) - c:\windows\system32\pcandis5.sys <Not>
S3 SANDRA - c:\program files\sisoftware\sisoftware sandra lite xii.sp2c\wnt500x86\sandra.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 AntiVirScheduler (Avira AntiVir Personal – Free
Antivirus Scheduler) - "c:\program files\avira\antivir personaledition classic\sched.exe" <Not>
R2 sp_rssrv (Spyware Terminator Realtime Shield Service) - "c:\program files\spyware terminator\sp_rsser.exe" <Not>
S4 AgereModemAudio (Agere Modem Call Progress Audio) - c:\windows\system32\agrsmsvc.exe <Not>
S4 Apple Mobile Device - "c:\program files\fichiers communs\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not>
S4 FTRTSVC (France Telecom Routing Table Service) - c:\windows\system32\ftrtsvc.exe (file missing)
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-05-17 15:35:03 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-05-13 and 2008-06-13 -----------------------------
2008-06-12 22:20:54 0 d-------- C:\Program Files\Windows Defender
2008-06-02 17:18:03 0 d-------- C:\Documents and Settings\Crousaud Emilie\Application Data\Pro Cycling Manager 2007
2008-06-01 15:55:41 0 d--h----- C:\WINDOWS\Copie de $NtUninstallKB835732$
2008-06-01 15:55:41 0 d--h----- C:\WINDOWS\Copie de $NtUninstallKB835409$
2008-06-01 15:55:40 0 d--h----- C:\WINDOWS\Copie de $NtUninstallKB822603$
2008-06-01 15:55:40 0 d--h----- C:\WINDOWS\Copie de $NtServicePackUninstallNLSDownlevelMapping$
2008-06-01 15:55:39 0 d--h----- C:\WINDOWS\Copie de $NtUninstallKB873339_0$
2008-06-01 15:55:39 0 d--h----- C:\WINDOWS\Copie de $NtServicePackUninstallIDNMitigationAPIs$
2008-06-01 15:26:35 0 dr-h----- C:\Documents and Settings\Crousaud Emilie\Recent
2008-05-31 23:58:32 0 d-------- C:\Program Files\Microsoft Hardware
2008-05-31 23:56:48 0 d-------- C:\Program Files\Microsoft IntelliPoint 4.12
2008-05-31 23:56:25 7507968 --a------ C:\Documents and Settings\Crousaud Emilie\ntuser.dat
2008-05-28 15:29:58 0 d-------- C:\Program Files\uTorrent
2008-05-28 15:29:50 0 d-------- C:\Documents and Settings\Crousaud Emilie\Application Data\uTorrent
2008-05-26 21:25:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Azureus
2008-05-26 21:25:44 0 d-------- C:\Documents and Settings\Crousaud Emilie\Application Data\Azureus
2008-05-26 21:04:13 0 d-------- C:\Program Files\a-squared Free
2008-05-26 19:52:12 10199072 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-26 19:44:55 0 d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-05-26 19:44:48 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-05-26 19:44:36 11264 --a------ C:\WINDOWS\system32\SpOrder.dll <Not>
2008-05-26 19:44:20 0 d-------- C:\WINDOWS\system32\ZoneLabs
2008-05-26 19:41:38 0 d-------- C:\WINDOWS\
Internet Logs
2008-05-26 17:56:27 0 d-------- C:\Program Files\RegCleaner
2008-05-24 22:13:19 0 dr-h----- C:\Documents and Settings\LocalService\Recent
2008-05-24 08:44:57 1409024 --a------ C:\Documents and Settings\LocalService\ntuser.dat
2008-05-23 23:07:24 0 d-------- C:\Program Files\Agnitum
2008-05-23 22:09:09 0 d-------- C:\Program Files\Fichiers communs\Java
2008-05-23 19:18:24 66048 --a------ C:\WINDOWS\ieResetIcons.exe <Not>
2008-05-23 19:02:37 0 d-------- C:\Documents and Settings\Crousaud Emilie\Application Data\Talkback
2008-05-22 22:16:20 141312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-05-22 22:16:17 0 d-------- C:\Documents and Settings\Crousaud Emilie\Application Data\Spyware Terminator
2008-05-22 22:16:17 0 d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-05-22 22:16:12 0 d-------- C:\Program Files\Spyware Terminator
2008-05-21 22:21:07 0 d-------- C:\Program Files\Enigma Software Group
2008-05-21 21:46:06 0 d-------- C:\WINDOWS\system32\MyFirewall
2008-05-21 21:27:07 70528 --a------ C:\WINDOWS\system32\drivers\ahnsze.sys <Not>
2008-05-21 21:16:30 0 d-------- C:\Program Files\
AhnLab
2008-05-21 19:12:22 0 d-------- C:\WINDOWS\BDOSCAN8
2008-05-21 19:02:03 0 d-------- C:\Program Files\Panda
Security
2008-05-21 07:57:30 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-21 07:57:29 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-20 23:39:55 0 d-------- C:\Documents and Settings\Crousaud Emilie\.housecall6.6
2008-05-20 15:56:10 0 d--h----- C:\WINDOWS\msdownld.tmp
2008-05-20 15:37:01 0 d-------- C:\ae5f184a5af4c90393698c450fdef9
2008-05-18 22:01:30 0 d-------- C:\Program Files\Lavasoft
2008-05-18 22:00:50 0 d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
-- Find3M Report ---------------------------------------------------------------
2008-06-13 16:36:11 0 d-------- C:\Program Files\Wanadoo
2008-06-13 16:28:47 0 d-------- C:\Program Files\Mozilla Firefox 3 Beta 2
2008-06-03 21:11:32 0 d-------- C:\Program Files\OpenOffice.org1.1.0
2008-06-02 17:37:11 0 d-------- C:\Program Files\Micro Application
2008-06-02 17:01:51 0 d-------- C:\Program Files\Cyanide
2008-05-29 21:55:32 0 d-------- C:\Program Files\Shareaza
2008-05-26 17:37:08 0 d-------- C:\Program Files\Fichiers communs
2008-05-23 22:11:09 0 d-------- C:\Program Files\Java
2008-05-23 17:35:14 0 d-------- C:\Documents and Settings\Crousaud Emilie\Application Data\Mozilla
2008-05-15 17:09:04 0 d-------- C:\Program Files\CCleaner
2008-05-14 15:14:34 474316 --a------ C:\WINDOWS\system32\perfh00C.dat
2008-05-14 15:14:34 77038 --a------ C:\WINDOWS\system32\perfc00C.dat
2008-05-05 12:58:05 0 d-------- C:\Program Files\Alwil Software
2008-04-28 22:24:00 1964 --a------ C:\WINDOWS\system32\fsyoeop_navps.dat
2008-04-28 22:23:33 8473 --a------ C:\WINDOWS\system32\fsyoeop.dat
2008-04-27 09:05:26 0 d-------- C:\Program Files\Avira
2008-04-26 08:25:33 327680 --a------ C:\WINDOWS\system32\fsyoeop.exe
2008-04-25 07:33:40 420034 --a------ C:\WINDOWS\system32\fsyoeop_nav.dat
2008-04-24 20:28:11 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-04-22 18:52:35 0 d-------- C:\Program Files\Yahoo!
2008-04-22 18:41:31 0 d-------- C:\Program Files\EPSON
2008-04-22 18:41:10 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-21 19:38:08 0 d-------- C:\Program Files\Fichiers communs\Symantec Shared
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [12/02/2008 10:06]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [02/04/2008 21:07]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [05/12/2007 01:41]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [28/01/2008 12:43]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [05/08/2004 14:00]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Démarrage rapide du logiciel HP Image Zone.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Démarrage rapide du logiciel HP Image Zone.lnk
backup=C:\WINDOWS\pss\Démarrage rapide du logiciel HP Image Zone.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lightsurf.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lightsurf.lnk
backup=C:\WINDOWS\pss\Lightsurf.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Crousaud Emilie^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 1.1.0.lnk]
path=C:\Documents and Settings\Crousaud Emilie\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 1.1.0.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 1.1.0.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
"C:\Program Files\Windows Defender\MSASCui.exe" -hide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOKIT]
C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3 (0x3)
"gusvc"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"Pml Driver HPZ12"=2 (0x2)
"LVSrvLauncher"=2 (0x2)
"LVCOMSer"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"AgereModemAudio"=2 (0x2)
"FTRTSVC"=2 (0x2)
-- End of Deckard's System Scanner: finished at 2008-06-13 16:38:46 ------------
la suite après......