Pb de démarage vista

BankaiJO Messages postés 48 Statut Membre -  
Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   -
Bonjour,
voila mon probleme , losque je met en marche mon pc , je sui obligé de faire une manip pour lancer explorer.exe sinon il ne maffiche qu'une fenetre ,celle de mes documents et rien dautre , par ailleur je nai plus de connection internet ,....que faire ???
Configuration: Windows Vista Internet Explorer 7.0

3 réponses

  1. Utilisateur anonyme
     
    tu fais : ctrl+alt+supp onglet applications >> nouvelle tache >> explorer.exe
    0
    1. BankaiJO Messages postés 48 Statut Membre
       
      c justement cette manipulation ke je suis obligé de faire (il ny a plus de probleme de connection =) apparement explorer.exe ne tien pa sur mes reboot g aussi fait un rapport HijackThis.....
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 23:01:43, on 29/06/2009
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\explorer.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Windows\RtHDVCpl.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Electronic Arts\EADM\Core.exe
      C:\Program Files\Microsoft Office\Office\1036\OLFSNT40.EXE
      C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\OpenOffice.org 3\program\soffice.exe
      C:\Program Files\OpenOffice.org 3\program\soffice.bin
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\Windows\system32\SearchFilterHost.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      F2 - REG:system.ini: Shell=Explorer.exe "C:\Windows\KesenjanganSosial.exe"
      O1 - Hosts: ::1 localhost
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
      O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
      O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
      O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
      O4 - HKLM\..\Run: [Bron-Spizaetus] "C:\Windows\ShellNew\RakyatKelaparan.exe"
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe -silent
      O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
      O4 - HKCU\..\Run: [Tok-Cirrhatus-1398] "C:\Users\User\AppData\Local\br3819on.exe"
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
      O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1036\OLFSNT40.EXE
      O4 - Global Startup: ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
      O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
      O13 - Gopher Prefix:
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
      O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
      O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
      0
    2. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236 > BankaiJO Messages postés 48 Statut Membre
       
      Hello,




      • Télécharge et installe FindyKill

      (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d'avoir été infectées sans les ouvrir

      • Double clic sur le raccourci FindyKill présent sur ton bureau .

      • Choisis l'option 1 ( Recherche )

      • Laisse travailler l'outil.

      • Ensuite post le rapport FindyKill.txt qui apparaitra.

      • Note : Le rapport FindyKill.txt est sauvegardé a la racine du disque. ( C:\FindyKill.txt )

      ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

      • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
      Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
      Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
      0
    3. BankaiJO Messages postés 48 Statut Membre > Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention  
       
      salut avan de démaré la recherche ya une fenetre ki dit veillez branché tous vos périph. externes...clé usb , disque dur etc...veillez retiré la protection en écriture de ceux ci , mettez sous tension vos disquedur externe (jen ai pa) en cliquan sur OK il me dit ke le programme sapprète a démaré et ...boum!! accées refusée :-(
      0
    4. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236 > BankaiJO Messages postés 48 Statut Membre
       
      Désolé, Un oubli de ma part:

      Désactive l'UAC :
      • Va dans Panneau de Configuration puis Comptes d'Utilisateurs.
      • Clique sur "Activer" ou "désactiver" le contrôle des comptes utilisateurs.
      • Décoche la case "Utiliser le contrôle des comptes utilisateurs pour vous aider à protéger votre ordinateur".
      • Clique sur OK pour enregistrer la modification et redémarre ton PC lorsque cela t'est demandé.

      aide en cas de problèmes


      Ensuite, après redémarrage, tu peux relancer Findykill.

      Si cela ne fonctionne toujours pas, fais un clic droit sur Findykill et choisi "exécuter en tant qu'administrateur".

      @+


      EDIT: Et s'il te plait, fais moi le plaisir d'écrire PROPREMENT, je ne tolérerai pas le langage SMS, de plus j'adore la ponctuation (virgules accents, majuscules).
      Merci.
      0
    5. BankaiJO Messages postés 48 Statut Membre > Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention  
       
      Voilà le rapport,

      ############################## | FindyKill V6.001 |

      # User : User (Administrateurs) # USER1
      # Update on 30/06/09 by Chiquitine29 & C_XX
      # Start at: 11:46:23 | 01/07/2009
      # Website : http://pagesperso-orange.fr/NosTools/index.html

      # Intel(R) Pentium(R) Dual CPU E2200 @ 2.20GHz
      # Microsoft® Windows Vista™ Édition Familiale Basique (6.0.6001 32-bit) # Service Pack 1
      # Internet Explorer 7.0.6001.18000
      # Windows Firewall Status : Disabled
      # AV : Bitdefender Antivirus 8.0 [ Enabled | Updated ]
      # FW : Bitdefender Firewall[ Enabled ]8.0

      # C:\ # Disque fixe local # 167,07 Go (4,36 Go free) [OS_Install] # NTFS
      # D:\ # Disque fixe local # 131,02 Go (130,93 Go free) [Nouveau nom] # NTFS
      # E:\ # Disque CD-ROM

      ############################## | Processus actifs |

      C:\Windows\System32\smss.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\wininit.exe
      C:\Windows\system32\services.exe
      C:\Windows\system32\lsass.exe
      C:\Windows\system32\lsm.exe
      C:\Windows\system32\winlogon.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\SLsvc.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\Windows\System32\spoolsv.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\SearchIndexer.exe
      C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
      C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
      C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\explorer.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Electronic Arts\EADM\Core.exe
      C:\Program Files\Microsoft Office\Office\1036\OLFSNT40.EXE
      C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
      C:\Program Files\OpenOffice.org 3\program\soffice.exe
      C:\Program Files\OpenOffice.org 3\program\soffice.bin
      C:\Windows\System32\rundll32.exe
      C:\Windows\system32\wbem\wmiprvse.exe
      C:\Windows\system32\conime.exe
      C:\Windows\system32\wuauclt.exe
      C:\Windows\system32\wbem\wmiprvse.exe

      ################## | Registre Startup |

      HKCU_Main: "Local Page"="C:\\Windows\\system32\\blank.htm"
      HKCU_Main: "Search Page"="https://www.google.com/?gws_rd=ssl"
      HKCU_Main: "Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
      HKLM_logon: "Userinit"="C:\\Windows\\system32\\userinit.exe,"
      HKLM_logon: "LegalNoticeCaption"=""
      HKLM_logon: "LegalNoticeText"=""
      HKLM_Run: Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
      HKLM_Run: RtHDVCpl=RtHDVCpl.exe
      HKLM_Run: NeroFilterCheck=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
      HKLM_Run: NvSvc=RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
      HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      HKLM_Run: NvMediaCenter=RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      HKLM_Run: CanonSolutionMenu=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
      HKLM_Run: CanonMyPrinter=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
      HKLM_Run: BitDefender Antiphishing Helper="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
      HKLM_Run: BDAgent="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
      HKLM_Run: Bron-Spizaetus="C:\Windows\ShellNew\RakyatKelaparan.exe"
      HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
      HKCU_Run: Sidebar=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      HKCU_Run: EA Core=C:\Program Files\Electronic Arts\EADM\Core.exe -silent
      HKCU_Run: WindowsWelcomeCenter=rundll32.exe oobefldr.dll,ShowWelcomeCenter
      HKCU_Run: Tok-Cirrhatus-1398="C:\Users\User\AppData\Local\br3819on.exe"
      HKCU_Run: Tok-Cirrhatus=

      ################## | Fichiers # Dossiers infectieux |


      ################## | C:\Users\User\Temporary Internet Files |


      ################## | All Drives ... |


      ################## | Registre # Clés Run infectieuses |

      Présent ! HKCU\SOFTWARE\...\CurrentVersion\Policies\System "DisableRegistryTools" ( 0x1 )

      ################## | Registre # Mountpoints2 |

      HKCU\...\Explorer\MountPoints2\{494e589a-c3ba-11dd-b2da-0021855b014a}\Shell\AutoRun\Command
      HKCU\...\Explorer\MountPoints2\{494e589a-c3ba-11dd-b2da-0021855b014a}\Shell\explore\Command
      HKCU\...\Explorer\MountPoints2\{494e589a-c3ba-11dd-b2da-0021855b014a}\Shell\open\Command
      HKCU\...\Explorer\MountPoints2\{50a2dde4-4e9e-11de-a22d-0021855b014a}\Shell\AutoRun\Command
      HKCU\...\Explorer\MountPoints2\{587d30ce-c9a1-11dd-81d5-0021855b014a}\Shell\AutoRun\Command
      HKCU\...\Explorer\MountPoints2\{587d30ce-c9a1-11dd-81d5-0021855b014a}\Shell\open\Command
      HKCU\...\Explorer\MountPoints2\{7df85ce5-c422-11dd-96e1-0021855b014a}\Shell\Auto\Command
      HKCU\...\Explorer\MountPoints2\{7df85ce5-c422-11dd-96e1-0021855b014a}\Shell\AutoRun\Command
      HKCU\...\Explorer\MountPoints2\{b4436c75-d4f6-11dd-89e5-0021855b014a}\Shell\AutoRun\Command
      HKCU\...\Explorer\MountPoints2\{d3ef7873-e96e-11dd-9b36-0021855b014a}\Shell\AutoRun\Command
      HKCU\...\Explorer\MountPoints2\{d3ef7873-e96e-11dd-9b36-0021855b014a}\Shell\explore\Command
      HKCU\...\Explorer\MountPoints2\{d3ef7873-e96e-11dd-9b36-0021855b014a}\Shell\open\Command

      ################## | Etat / Services / Informations |

      # Affichage des fichiers cachés : OK

      # Mode sans echec : OK

      # (!) Uac = 0x0

      # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
      # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
      # Wlansvc -> Start = 3 ( Good = 2 | Bad = 4 )
      # (!) SharedAccess -> Start = 4 ( Good = 2 | Bad = 4 )
      # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
      # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
      # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

      ################## | Cracks / Keygens / Serials |

      "C:\Users\User\Desktop\Nouveau dossier\logicieles\ATOMIX DJ\keygen.exe"
      09/01/2003 19:11 |Size 40359 |Crc32 42ad695c |Md5 7f8ec61519c559fbd3a1448f18530f39


      Que faut-il faire ensuite,...
      0
  2. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236
     
    Quand tu m'auras posté ton rapport deFindykill exécute ensuite ceci:

    - Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

    - Double-clique sur RSIT.exe afin de lancer le programme.

    - Clique sur Continue à l'écran Disclaimer.

    -Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    - Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches) dans deux messages différents.
    0
  3. BankaiJO Messages postés 48 Statut Membre
     
    cooooool!!!! Alors voilà,j'ai fait une manipulation assez risqué avec autoruns.exe ,en faite moi j'ai décoché explorer.exe du tableau et redémaré mon pc et voilà tous se relance correctement comme avant, merci a tous pour l'aide
    Comment ca marche aide vraiment les personnes ;-) Bravo!! lol A plus
    0
    1. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236
       
      Fais ce que je te demande, il faut terminer.

      Ton pc est infecté, contamine les autres, qui en contaminent d'autres.

      Poste moi le rapport de suppression de Findykill ainsi que les 2 rapports d'Rsit.

      Pas mal de gens partent d'ici sans terminer et on les recroise ici ou ailleurs peu de temps après en nous disant qu'ils auraient dû nous écouter.

      Alors on termine et quand c'est clean , on se dit Adieu :)
      0