Perte resolution affichage images et videos

Bonjour,

Hello,

Je suis desesperé par ce qui m'arrive. Il y a une semaine j'ai remarqué que mes videos, mes images affichés par windows ou les images des sites web s'affichaient avec une moins bonne resolution comme cela [img]http://laforgue.lionel.neuf.fr/image/Exemple.bmp[/img].
Et aujourd'hui en allumant mon ordinateur je constate sur mon fond d'ecran que ca a encore empiré comme cela:
[img]http://laforgue.lionel.neuf.fr/image/Exemple2.bmp[/img]

Je decide de lancer adaware et la pendant la verif mon anti-virus AVG detecte un troyen. Je l'elimine et ensuite je passe l'antivirus sur tout mon disque encore un autre de detecté. Je delete les fichers concernés mais le probleme est toujours là.

Comment revenir a ma configuration initiale de haute resolution.
En allant dans le panneau de config tout semble correct. Alors je ne sais plus quoi faire. Est-ce que c vraiment lié au virus.

Je suis vraiment désespéré...
Merci d'avance pour vos precieux conseils

Jeff

7 réponses

  1. Bonjour,

    Mieux vaut être prudent :
    Pour cela,télécharge HijackThis ici:
    http://www.hijackthis.de/downloads/hijackthis_199.zip

    Dézippe le dans un dossier prévu à cet effet.
    Par exemple C:\hijackthis < Enregistre le bien dans c : !
    Lance le puis:
    clique sur "do a system scan and save logfile" (cf démo)
    faire un copier coller du log entier sur le forum

    Démo : (merci à balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/demohijack.htm

    Voila !
    Bonne Chance
    0
    1. Merci bcp pour cette reponse rapide.

      J'espere que vous comprenez quelquechose?

      Voici le rapport HiJackThis

      Logfile of HijackThis v1.99.1
      Scan saved at 15:44:26, on 20/10/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\System32\Ati2evxx.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      C:\Norman\Bin\Zanda.exe
      C:\WINDOWS\system32\pctspk.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\wdfmgr.exe
      C:\Norman\bin\NJEEVES.EXE
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\Explorer.EXE
      C:\Norman\bin\ZLH.EXE
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Norman\Nvc\bin\nvcoas.exe
      C:\Norman\Nvc\BIN\NVCSCHED.EXE
      C:\Norman\Nvc\BIN\NIP.EXE
      C:\Norman\Nvc\BIN\nipsvc.exe
      C:\Norman\Nvc\bin\cclaw.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\All Users\Documents\Utiliataires AntiVirus et Trojan\hijackthis_199\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEInt.dll
      O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [dwcrnt.exe] dwcrnt.exe
      O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
      O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      O4 - HKLM\..\Run: [Piolet] C:\Program Files\Piolet\Piolet.exe SILENT
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
      O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{98F56D80-9E35-44FE-9AFA-246E967BDAC3}: NameServer = 192.168.1.1
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
      O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
      O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe
      O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
      O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
      O23 - Service: PACSPTISVR - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\PACSPT~1.EXE
      O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
      O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
      0
      1. Merci bcp pour cette reponse rapide.

        J'espere que vous comprenez quelquechose?

        Voici le rapport HiJackThis

        Logfile of HijackThis v1.99.1
        Scan saved at 15:44:26, on 20/10/2005
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\System32\Ati2evxx.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        C:\Norman\Bin\Zanda.exe
        C:\WINDOWS\system32\pctspk.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\wdfmgr.exe
        C:\Norman\bin\NJEEVES.EXE
        C:\WINDOWS\System32\alg.exe
        C:\WINDOWS\Explorer.EXE
        C:\Norman\bin\ZLH.EXE
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Norman\Nvc\bin\nvcoas.exe
        C:\Norman\Nvc\BIN\NVCSCHED.EXE
        C:\Norman\Nvc\BIN\NIP.EXE
        C:\Norman\Nvc\BIN\nipsvc.exe
        C:\Norman\Nvc\bin\cclaw.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Documents and Settings\All Users\Documents\Utiliataires AntiVirus et Trojan\hijackthis_199\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEInt.dll
        O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [dwcrnt.exe] dwcrnt.exe
        O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
        O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
        O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        O4 - HKLM\..\Run: [Piolet] C:\Program Files\Piolet\Piolet.exe SILENT
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
        O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{98F56D80-9E35-44FE-9AFA-246E967BDAC3}: NameServer = 192.168.1.1
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
        O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
        O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
        O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe
        O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
        O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
        O23 - Service: PACSPTISVR - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\PACSPT~1.EXE
        O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
        O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
        0
        1. ¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked

          O4 - HKLM\..\Run: [dwcrnt.exe] dwcrnt.exe

          ¤Recherche et supprime ceci:
          attention seulement les fichiers (si présents)
          supprilme le .exe

          à vérifier
          0
          1. Bonsoir,

            J'ai fait ce que vous m'avez recommandé avec HiJackThis, mais je n'ai pas trouvé de fichier dwcrnt.exe.

            Et mon probleme est tjs là!

            Pour vous rendre compte j'ai pris une photo d'ecran
            http://laforgue.lionel.neuf.fr/image/Exemple3.bmp

            Merci encore pour vos réponses.

            A bientot!
            Jeff
            0
            1. Contributeur
              ce que tu peux faire :

              Telecharge: Pocket Killbox ici
              http://www.downloads.subratam.org/KillBox.exe

              les diverses facons d utiliser la killbox
              demo http://pageperso.aol.fr/balltrap34/killbox.htm

              deconnecte toi d'internet:

              1- Double-clic sur KillBox.exe
              2- tape : dwcrnt.exe
              3- Selectionne "Delete on Reboot"
              4- clic sur le rond rouge
              6- une fenetre va apparaitre pour confirmation clic sur OUI
              7- une seconde fenetre te demande si tu veux redemarrer clic sur OUI
              0