Mon pc se bloque - Page 3

Résolu
Précédent
  • 1
  • 2
  • 3
  1. lilya
     
    re;
    ou se trouve process: explorer.exe desolè
    0
  2. ric025
     
    Tu n'as pas à chercher le processus. Tu copies la liste en entier. Tu ouvres OtMoveIt et tu copies la liste à l'endroit indiqué.

    ++
    0
  3. lilya
     
    re
    je suis vraiment desolè au premier j'ouvre otmove et ensuite queceque je fais par etape expliquez moi doucement svp parceque j'ai pas bien compri excusez moi merci
    0
  4. ric025
     
    * Copie la liste en gras que je t'ai écrit deux fois dans les précédents messages.

    * Ouvre OtMoveIt.

    * Colle la liste complète dans le cadre de gauche de OTMoveIt sous Paste List of Files/Folders to move.

    * Clique sur MoveIt! pour lancer la suppression.

    * Le résultat apparaitra dans le cadre "Results".

    * Clique sur Exit pour fermer.

    * Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

    ++

    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. lilya
     
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:47:55, on 18/05/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Documents and Settings\sun\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\VDOWNLOADER\VDownloader.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\trend micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - Default URLSearchHook is missing
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll (file missing)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (file missing)
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe" -atboottime
    O4 - HKLM\..\RunOnce: [OTMoveIt] C:\Documents and Settings\sun\Bureau\OTMoveIt3.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\sun\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game04.zylom.com/activex/zylomgamesplayer.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{6B244744-AA50-43DB-9D7C-F124376E58E5}: NameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C813CD7F-584C-41E5-BB74-79928A602499}: NameServer = 41.221.20.4 193.251.169.165
    O17 - HKLM\System\CS1\Services\Tcpip\..\{6B244744-AA50-43DB-9D7C-F124376E58E5}: NameServer = 192.168.1.1
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    0
  7. ric025
     
    Tu n'as pas eu de rapport pour OtMoveIt ?

    Sinon, tu peux le trouver ici :

    C:\_OTMoveIt\MovedFiles
    0
  8. lilya
     
    ========== PROCESSES ==========
    Process explorer.exe killed successfully.
    ========== FILES ==========
    C:\Program Files\BearShare Applications\BearShare MediaBar moved successfully.
    C:\Program Files\BearShare Applications moved successfully.
    ========== COMMANDS ==========
    User's Temp folder emptied.
    User's Internet Explorer cache folder emptied.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\XHFOHB73\default[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\XHFOHB73\HistoryFrame_13.3.0218.0429[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\XHFOHB73\InboxLight[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\XHFOHB73\MsgrConfig[1].asmx scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VVFZFSIO\default[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VVFZFSIO\default[2].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VVFZFSIO\InboxLight[2].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VVFZFSIO\InboxLight[3].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VVFZFSIO\pub-haut2[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VVFZFSIO\ToastFull[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VVFZFSIO\ToastFull[2].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VVFZFSIO\ToastFull[3].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VVFZFSIO\ToastMini[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VVFZFSIO\ToastMini[2].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VVFZFSIO\ToastMini[3].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VVFZFSIO\youtube_com[1].txt scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VAVJDG9U\ads-carre2[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VAVJDG9U\ajout[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VAVJDG9U\ajout[2].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VAVJDG9U\autopromo[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VAVJDG9U\im[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VAVJDG9U\im[2].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VAVJDG9U\pub[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\VAVJDG9U\wimpy.sql[1].php scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\RQ5PDK21\ajout[2].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\RQ5PDK21\im[3].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\RQ5PDK21\show_ads[1].js scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\KO68WVAV\ads-carre3[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\KO68WVAV\ajout[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\KO68WVAV\autopromo[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\KO68WVAV\default[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\KO68WVAV\douniaclip_com[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\KO68WVAV\hijackthis[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\KO68WVAV\im[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\KO68WVAV\InboxLight[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\KO68WVAV\pub-haut3[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\KO68WVAV\pub[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\KO68WVAV\pub[2].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\KO68WVAV\Rai-2009[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\KO68WVAV\ToastFull[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\KO68WVAV\ToastMini[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\C880M5LR\ToastFull[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\C880M5LR\ToastMini[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\C880M5LR\topdepart[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\C2ZSNXR9\ads-carre2[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\C2ZSNXR9\ads-carre3[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\C2ZSNXR9\ajout[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\C2ZSNXR9\default[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\C2ZSNXR9\GP31089739d5ba49[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\C2ZSNXR9\im[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\C2ZSNXR9\Rai-2009[1].htm scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\C2ZSNXR9\wimpy.sql[1].php scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\sun\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat scheduled to be deleted on reboot.
    User's Temporary Internet Files folder emptied.
    Local Service Temp folder emptied.
    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    Local Service Temporary Internet Files folder emptied.
    Network Service Temp folder emptied.
    Network Service Temporary Internet Files folder emptied.
    File delete failed. C:\WINDOWS\temp\_avast4_\unp71626033.tmp scheduled to be deleted on reboot.
    File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
    File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_478.dat scheduled to be deleted on reboot.
    Windows Temp folder emptied.
    Temp folders emptied.
    Explorer started successfully

    OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05182009_173948
    0
  9. ric025
     
    Parfait !

    Télécharge CCleaner, version Slim, sans toolbar:

    CCLEANER

    Va dans "Options">>"Avancé". Décoche la première ligne.

    Va dans la section "Nettoyeur". Lance l'analyse. La liste créée, lance le nettoyage deux fois de suite afin d'obtenir 0bytes supprimé!

    Ensuite dans "Registre", lance une recherche des erreurs. La liste créée, fais-les réparer.

    /!\ A ce moment CCleaner te demande normalement de sauvegarder le registre, fais-le. /!\

    Recommence ensuite le cycle Recherche/Réparation des erreurs jusqu'à n'en trouver aucune lors de la recherche.

    =========================

    Redémarre le pc et poste un nouveau rapport Hijackthis.

    ++
    0
  10. lilya
     
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:08:52, on 18/05/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Documents and Settings\sun\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\trend micro\HijackThis\HijackThis.exe
    C:\Program Files\Alwil Software\Avast4\setup\avast.setup

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - Default URLSearchHook is missing
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: (no name) - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O3 - Toolbar: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - (no file)
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\sun\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game04.zylom.com/activex/zylomgamesplayer.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{6B244744-AA50-43DB-9D7C-F124376E58E5}: NameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C813CD7F-584C-41E5-BB74-79928A602499}: NameServer = 41.221.20.4 193.251.169.165
    O17 - HKLM\System\CS1\Services\Tcpip\..\{6B244744-AA50-43DB-9D7C-F124376E58E5}: NameServer = 192.168.1.1
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    0
  11. ric025
     
    Parfait, c'est mieux ! ;)

    Relance Hijackthis, mais choisis cette fois l'option "Do a System Scan Only". La liste créée, à gauche de chaque ligne tu trouveras un petit carré blanc. Si tu cliques dessus, tu "cocheras" la ligne. Coche les lignes suivantes :

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
    
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/fr/ 
    
    R3 - Default URLSearchHook is missing
    
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    
    O2 - BHO: (no name) - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - (no file)
    
    O3 - Toolbar: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - (no file)
    
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName 
    
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe" -atboottime
    
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 
    
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    
    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game04.zylom.com/activex/zylomgamesplayer.cab


    Clique ensuite sur "Fix Checked".

    ============================

    Redémarre le pc. Si tout est ok, fais la suite :

    Télécharge OTCleanIt sur ton Bureau :

    http://www.geekstogo.com/...

    * Clique droit sur OTCleanIt et choisis Exécuter en tant qu'administrateur.
    * Clique sur CleanUp! puis clique sur Yes à la fenêtre Confirm.
    * Redémarre ton PC comme demandé.

    ==============================

    Dis-moi si tout va bien, on pourras finaliser.

    ++
    0
  12. lilya
     
    slt; j'ai desinstallet avast et j'ai installer avira antivir mais quand je voulè supprimer les anciens points de restauration mais moi j'ai pas vista dit moi queceque je fais? svp
    0
  13. ric025
     
    Salut !

    Excuse-moi, je faisais deux désinfections en même temps, j'ai cru que tu avais Vista.

    Je te remets la procédure sous XP :

    !! Très Important !!

    Supprimer les anciens points de restauration:

    * Cliquer "démarrer", "panneau de configuration", performance et maintenance" puis système".
    * Cliquer sur l'onglet "Restauration du système".
    * Cocher la case "Désactiver la restauration...", puis "Appliquer" et valider par "OK".
    * Redémarrer le pc.

    * Cliquer "démarrer", "panneau de configuration", "performance et maintenance" puis "système".
    * Cliquer sur l'onglet "Restauration du système".
    * Redécocher la case "Désactiver la restauration...", puis "Appliquer" et valider par "OK".

    Les points sont supprimés.

    Création d'un nouveau point:

    * Cliquer "démarrer", "panneau de configuration", "performance et maintenance" puis "restauration du système" (en haut à gauche).
    * Dans la nouvelle fenêtre, cocher la case "Créer un point de restauration".
    * Cliquer sur "Suivant".
    * Entrer un nom pour le point de restauration : ce nom doit être assez évocateur (comme: "Après désinfection...")
    * Cliquer sur "Créer" et le point de restauration se créé automatiquement.

    A++ Encore désolé ! ;)
    0
  14. lilya
     
    bonsoir ; et vraiment desolè pour ce derongement j'ai supprimer les anciens points mais jè pas trouvè la case "creè un point de restauration" merci
    0
  15. ric025
     
    A droite, tu as deux choix, "Restaurer mon ordinateur à une date antérieure" ou "Créer un point de restauration". Clique dans le rond à gauche de la deuxième phrase, puis "Suivant".

    ++
    0
  16. lilya
     
    bonjour ; j'ai pas trouvè cette case "crèer un point de restauration" j'ai le tableau "restauration du système" et il ya cette ecriture: la restauration du système peut suivre et annuler les modifications prèjudiciables pour votre ordinateur. et il ya la case dèsactiver la restauration c'est tout merci.
    0
  17. lilya
     
    slt; j'ai ouvrè lle panneau de configuration mais il ya pas "performance et maintenance" j'ai directement système et dans "système" il ya "restauration du système" et "dèsectiver la restauration" c tout
    merci.
    0
  18. ric025
     
    Salut lilya !

    Ravi que ce soit ok !

    Bon surf, soit prudente sur le net !

    ++
    0
Précédent
  • 1
  • 2
  • 3