ça recommence

la poisse du 89 Messages postés 14 Statut Membre -  
la poisse du 89 Messages postés 14 Statut Membre -
Bonjour,
Voila, ça recommence... Je m'explique : comme au mois de Mars, mon ordi est redevenu d'une lenteur excesive surtout en navigant sur le net. A l'epoque l'aide de "JPLJPL" m'a été precieuse. Mais cette fois, qui veut bien m'aider..? Merci a vous
Configuration: Windows XP Internet Explorer 7.0

4 réponses

  1. sherred Messages postés 8605 Statut Membre 351
     
    Ccleaner http://www.commentcamarche.net/telecharger/telechargement 168 ccleaner
    tu fait le nettoyage
    Fichiers temporaires de Windows
    Cookies, cache, historique d'Internet Explorer, Opera et Firefox
    Documents récents de Windows
    et ensuite reparation de la base de registre.

    puis
    si tu a des soucies
    télécharge hijackthis http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
    -> enregistre la cible sous .... "le bureau" renomme HJTInstall.exe en par exemple HJT.exe

    -> Fais un double-clic sur "HJT.exe" afin de lancer l'installation

    -> Clique sur Install ensuite sur "I Accept"

    -> Clique sur" Do a scan system and save log file"

    -> Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse

    http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm

    0
  2. la poisse du 89
     
    Bonjour, merci pour ton aide,
    voila le rapport:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:56:53, on 28/05/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\PhnxCDSvr.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\VIA\RAID\raid_tool.exe
    C:\WINDOWS\system32\VTtrayp.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\Program Files\VIAudioi\SBADeck\ADeck.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
    C:\DOCUME~1\florent\LOCALS~1\Temp\Rar$EX01.437\rav.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dartybox.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
    O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-21-2767137411-2969763777-3073499316-1007\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User '?')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\508\G2AWinLogon.dll
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
    O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
    O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\508\g2aservice.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Phoenix VCD Service (PhnxVCDService) - Phoenix Technologies Ltd. - C:\WINDOWS\system32\PhnxCDSvr.exe
    0
  3. sherred Messages postés 8605 Statut Membre 351
     
    Télécharge Superantispyware (SAS)
    https://www.superantispyware.com/superantispywarefreevspro.html

    une fois l'installation et la mise a jour effectuée

    clic sur « scanner votre ordinateur »
    coche scan complete
    et suivant

    Le rapport :
    "Preferences" "Statistics/journaux de bord".
    double-clique sur le dernier SUPERAntiSpyware Scan Log.
    0
  4. la poisse du 89 Messages postés 14 Statut Membre
     
    Voila le rapport:
    SUPERAntiSpyware Scan Log
    https://www.superantispyware.com/

    Generated 05/28/2009 at 02:16 PM

    Application Version : 4.26.1004

    Core Rules Database Version : 3913
    Trace Rules Database Version: 1857

    Scan type : Complete Scan
    Total Scan Time : 00:43:46

    Memory items scanned : 533
    Memory threats detected : 0
    Registry items scanned : 6116
    Registry threats detected : 0
    File items scanned : 21193
    File threats detected : 44

    Adware.Tracking Cookie
    C:\Documents and Settings\florent\Cookies\florent@www.laverie-discount[2].txt
    C:\Documents and Settings\florent\Cookies\florent@advertising[1].txt
    C:\Documents and Settings\florent\Cookies\florent@smartadserver[1].txt
    C:\Documents and Settings\florent\Cookies\florent@samsung.solution.weborama[2].txt
    C:\Documents and Settings\florent\Cookies\florent@CAHN2ZY5.txt
    C:\Documents and Settings\florent\Cookies\florent@tradedoubler[2].txt
    C:\Documents and Settings\florent\Cookies\florent@tacoda[1].txt
    C:\Documents and Settings\florent\Cookies\florent@bluestreak[1].txt
    C:\Documents and Settings\florent\Cookies\florent@weborama[1].txt
    C:\Documents and Settings\florent\Cookies\florent@smartadserver[2].txt
    C:\Documents and Settings\florent\Cookies\florent@fl01.ct2.comclick[1].txt
    C:\Documents and Settings\florent\Cookies\florent@doubleclick[1].txt
    C:\Documents and Settings\florent\Cookies\florent@xiti[1].txt
    C:\Documents and Settings\florent\Cookies\florent@advertising[2].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@atdmt[2].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@ad.zanox[2].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@2o7[1].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@clickintext[1].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@sextv2424[1].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@canoe.112.2o7[2].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@webo.solution.weborama[2].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@weborama[1].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@mediaplex[2].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@fr.classic.clickintext[1].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@cetelem.solution.weborama[2].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@xiti[1].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@doubleclick[2].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@bluestreak[1].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@guigoz.solution.weborama[2].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@tradedoubler[2].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@fl01.ct2.comclick[1].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@aimfar.solution.weborama[1].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@yatahonga.sexy.easyrencontre[2].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@track.effiliation[1].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@advertstream[1].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@624.stats.stats[1].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@adultfriendfinder[2].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@apmebf[1].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@advertising[2].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@3635.stats.misstrends[2].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@yourmedia[1].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@ads.pointroll[1].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@adtech[1].txt
    C:\Documents and Settings\gwenael\Cookies\gwenael@tracking.publicidees[2].txt

    J'ai supprimer ces 44 fichiers, ça patine toujours autan..
    0