ça recommence

Bonjour,
Voila, ça recommence... Je m'explique : comme au mois de Mars, mon ordi est redevenu d'une lenteur excesive surtout en navigant sur le net. A l'epoque l'aide de "JPLJPL" m'a été precieuse. Mais cette fois, qui veut bien m'aider..? Merci a vous
Configuration: Windows XP Internet Explorer 7.0

4 réponses

  1. Ccleaner http://www.commentcamarche.net/telecharger/telechargement 168 ccleaner
    tu fait le nettoyage
    Fichiers temporaires de Windows
    Cookies, cache, historique d'Internet Explorer, Opera et Firefox
    Documents récents de Windows
    et ensuite reparation de la base de registre.

    puis
    si tu a des soucies
    télécharge hijackthis http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
    -> enregistre la cible sous .... "le bureau" renomme HJTInstall.exe en par exemple HJT.exe

    -> Fais un double-clic sur "HJT.exe" afin de lancer l'installation

    -> Clique sur Install ensuite sur "I Accept"

    -> Clique sur" Do a scan system and save log file"

    -> Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse

    http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm

    0
    1. Bonjour, merci pour ton aide,
      voila le rapport:
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 12:56:53, on 28/05/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\PhnxCDSvr.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Canon\CAL\CALMAIN.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\VIA\RAID\raid_tool.exe
      C:\WINDOWS\system32\VTtrayp.exe
      C:\WINDOWS\system32\VTTimer.exe
      C:\Program Files\VIAudioi\SBADeck\ADeck.exe
      C:\WINDOWS\system32\LVCOMSX.EXE
      C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
      C:\DOCUME~1\florent\LOCALS~1\Temp\Rar$EX01.437\rav.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dartybox.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
      O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
      O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
      O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
      O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
      O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-21-2767137411-2969763777-3073499316-1007\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User '?')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\508\G2AWinLogon.dll
      O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
      O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
      O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
      O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\508\g2aservice.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Phoenix VCD Service (PhnxVCDService) - Phoenix Technologies Ltd. - C:\WINDOWS\system32\PhnxCDSvr.exe
      0
      1. Voila le rapport:
        SUPERAntiSpyware Scan Log
        https://www.superantispyware.com/

        Generated 05/28/2009 at 02:16 PM

        Application Version : 4.26.1004

        Core Rules Database Version : 3913
        Trace Rules Database Version: 1857

        Scan type : Complete Scan
        Total Scan Time : 00:43:46

        Memory items scanned : 533
        Memory threats detected : 0
        Registry items scanned : 6116
        Registry threats detected : 0
        File items scanned : 21193
        File threats detected : 44

        Adware.Tracking Cookie
        C:\Documents and Settings\florent\Cookies\florent@www.laverie-discount[2].txt
        C:\Documents and Settings\florent\Cookies\florent@advertising[1].txt
        C:\Documents and Settings\florent\Cookies\florent@smartadserver[1].txt
        C:\Documents and Settings\florent\Cookies\florent@samsung.solution.weborama[2].txt
        C:\Documents and Settings\florent\Cookies\florent@CAHN2ZY5.txt
        C:\Documents and Settings\florent\Cookies\florent@tradedoubler[2].txt
        C:\Documents and Settings\florent\Cookies\florent@tacoda[1].txt
        C:\Documents and Settings\florent\Cookies\florent@bluestreak[1].txt
        C:\Documents and Settings\florent\Cookies\florent@weborama[1].txt
        C:\Documents and Settings\florent\Cookies\florent@smartadserver[2].txt
        C:\Documents and Settings\florent\Cookies\florent@fl01.ct2.comclick[1].txt
        C:\Documents and Settings\florent\Cookies\florent@doubleclick[1].txt
        C:\Documents and Settings\florent\Cookies\florent@xiti[1].txt
        C:\Documents and Settings\florent\Cookies\florent@advertising[2].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@atdmt[2].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@ad.zanox[2].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@2o7[1].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@clickintext[1].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@sextv2424[1].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@canoe.112.2o7[2].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@webo.solution.weborama[2].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@weborama[1].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@mediaplex[2].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@fr.classic.clickintext[1].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@cetelem.solution.weborama[2].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@xiti[1].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@doubleclick[2].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@bluestreak[1].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@guigoz.solution.weborama[2].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@tradedoubler[2].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@fl01.ct2.comclick[1].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@aimfar.solution.weborama[1].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@yatahonga.sexy.easyrencontre[2].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@track.effiliation[1].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@advertstream[1].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@624.stats.stats[1].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@adultfriendfinder[2].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@apmebf[1].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@advertising[2].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@3635.stats.misstrends[2].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@yourmedia[1].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@ads.pointroll[1].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@adtech[1].txt
        C:\Documents and Settings\gwenael\Cookies\gwenael@tracking.publicidees[2].txt

        J'ai supprimer ces 44 fichiers, ça patine toujours autan..
        0