Windows explorer a cessé de fonctionner ! - Page 2

  1. bonjour!
    Je n'ai qu'une clé USB et un disque dur externe, dont je ne me sers que pour mettre des photos que j'ai prises et des doc word.
    Je doute que ce soit la source du problème.
    Cependant ma mémoire libre descend encore. J'avais 24Go de libres... maintenant il en reste 21.... sans rien télécharger, ni installer. Comment cela se fait?
    merci
    0
    1. Contributeur sécurité
      Bonjour,
      1/
      Tu lances USBFix sans rien inséré, merci
      2/
      Tu lances de nouveau combofix comme expliqué ici puis tu postes le rapport

      3/
      Cependant ma mémoire libre descend encore. J'avais 24Go de libres... maintenant il en reste 21.... sans rien télécharger, ni installer. Comment cela se fait? 

      C'est à cause des infections!

      @+
      0
      1. Usbfix a donné un rapport, le voici:
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (2888)
        C:\Program Files\Windows Media Player\wmpnscfg.exe (2896)
        C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (2960)
        C:\Windows\system32\svchost.exe (3008)
        C:\Windows\system32\svchost.exe (3028)
        C:\Windows\System32\svchost.exe (3076)
        C:\Windows\system32\SearchIndexer.exe (3112)
        C:\Program Files\Windows Media Player\wmpnetwk.exe (3944)
        C:\Windows\system32\wbem\unsecapp.exe (820)
        C:\Windows\system32\wbem\wmiprvse.exe (1936)
        C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (4092)
        C:\Windows\system32\svchost.exe (3604)
        C:\Windows\system32\wuauclt.exe (3916)
        C:\Program Files\Common Files\Java\Java Update\jucheck.exe (3692)
        C:\Program Files\Mozilla Firefox\firefox.exe (3536)
        C:\Windows\system32\svchost.exe (1300)
        C:\Program Files\Mozilla Firefox\plugin-container.exe (3940)
        C:\Windows\system32\SearchProtocolHost.exe (3308)
        C:\Windows\system32\SearchFilterHost.exe (264)
        C:\UsbFix\Go.exe (2992)
        C:\Windows\system32\wbem\wmiprvse.exe (2208)

        ################## | Éléments infectieux |

        Présent! E:\autorun.exe
        Présent! E:\autorun.inf

        ################## | Registre |

        Présent! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
        Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives

        ################## | Mountpoints2 |

        ################## | Vaccin |

        (!) Cet ordinateur n'est pas vacciné!

        ################## | E.O.F |
        0
        1. voici le rapprt combofix:
          ComboFix 12-01-16.05 - FV 22/01/2012 11:33:02.2.2 - x86
          Microsoft® Windows Vista(TM) Édition Familiale Basique 6.0.6002.2.1252.32.1036.18.1790.927 [GMT 1:00]
          Lancé depuis: c:\users\FV\Desktop\ComboFix.exe
          AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
          SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
          SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
          .
          - Mode FONCTIONNALITES REDUITES -
          .
          .
          ((((((((((((((((((((((((((((( Fichiers créés du 2011-12-22 au 2012-01-22 ))))))))))))))))))))))))))))))))))))
          .
          .
          2012-01-22 10:34 . 2012-01-22 10:34 -------- d-----w- c:\users\Default\AppData\Local\temp
          2012-01-22 09:45 . 2012-01-22 09:50 -------- d-----w- C:\UsbFix
          2012-01-21 16:59 . 2012-01-06 04:19 6557240 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9D5CC768-018F-4587-B5B7-42234388CCF5}\mpengine.dll
          2012-01-20 11:37 . 2012-01-20 11:42 -------- d-----w- C:\Kill'em
          2012-01-20 11:26 . 2012-01-20 11:26 -------- d-----w- C:\_OTM
          2012-01-18 14:05 . 2012-01-18 14:07 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys
          2012-01-14 11:23 . 2011-11-17 06:48 440192 ----a-w- c:\windows\system32\drivers\ksecdd.sys
          2012-01-14 11:23 . 2011-11-16 16:23 377344 ----a-w- c:\windows\system32\winhttp.dll
          2012-01-14 11:23 . 2011-11-16 16:23 72704 ----a-w- c:\windows\system32\secur32.dll
          2012-01-14 11:23 . 2011-11-16 16:23 278528 ----a-w- c:\windows\system32\schannel.dll
          2012-01-14 11:23 . 2011-11-16 16:21 1259008 ----a-w- c:\windows\system32\lsasrv.dll
          2012-01-14 11:23 . 2011-11-16 14:12 9728 ----a-w- c:\windows\system32\lsass.exe
          2012-01-11 07:37 . 2011-10-14 16:03 189952 ----a-w- c:\windows\system32\winmm.dll
          2012-01-11 07:37 . 2011-10-14 16:00 23552 ----a-w- c:\windows\system32\mciseq.dll
          2012-01-11 07:37 . 2011-11-18 20:23 1205064 ----a-w- c:\windows\system32\ntdll.dll
          2012-01-11 07:37 . 2011-11-18 17:47 66560 ----a-w- c:\windows\system32\packager.dll
          2012-01-11 07:37 . 2011-11-25 15:59 376320 ----a-w- c:\windows\system32\winsrv.dll
          2012-01-11 07:37 . 2011-12-01 15:21 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
          2012-01-11 07:36 . 2011-10-25 15:58 1314816 ----a-w- c:\windows\system32\quartz.dll
          2012-01-11 07:36 . 2011-10-25 15:58 497152 ----a-w- c:\windows\system32\qdvd.dll
          2012-01-08 09:00 . 2012-01-08 09:00 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll
          2012-01-08 09:00 . 2012-01-08 09:00 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll
          2012-01-08 09:00 . 2012-01-08 09:00 43992 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll
          2012-01-08 09:00 . 2012-01-08 09:00 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll
          .
          .
          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2012-01-06 04:19 . 2011-10-03 10:15 6557240 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
          2012-01-04 06:01 . 2011-09-18 08:47 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
          2011-12-10 14:24 . 2011-05-29 14:37 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
          2011-11-23 13:37 . 2011-12-14 07:41 2043904 ----a-w- c:\windows\system32\win32k.sys
          2011-11-08 14:42 . 2011-12-14 07:41 2048 ----a-w- c:\windows\system32\tzres.dll
          2011-11-03 06:22 . 2011-12-14 07:41 916992 ----a-w- c:\windows\system32\wininet.dll
          2011-11-03 06:17 . 2011-12-14 07:41 43520 ----a-w- c:\windows\system32\licmgr10.dll
          2011-11-03 06:17 . 2011-12-14 07:41 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
          2011-11-03 06:17 . 2011-12-14 07:41 109056 ----a-w- c:\windows\system32\iesysprep.dll
          2011-11-03 06:17 . 2011-12-14 07:41 71680 ----a-w- c:\windows\system32\iesetup.dll
          2011-11-03 05:22 . 2011-12-14 07:41 385024 ----a-w- c:\windows\system32\html.iec
          2011-11-03 04:45 . 2011-12-14 07:41 133632 ----a-w- c:\windows\system32\ieUnatt.exe
          2011-11-03 04:43 . 2011-12-14 07:41 1638912 ----a-w- c:\windows\system32\mshtml.tlb
          2011-10-27 08:01 . 2011-12-14 07:41 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
          2011-10-27 08:01 . 2011-12-14 07:41 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
          2011-10-25 15:56 . 2011-12-14 07:41 49152 ----a-w- c:\windows\system32\csrsrv.dll
          2012-01-08 09:00 . 2011-10-02 09:07 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
          .
          .
          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
          REGEDIT4
          .
          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
          "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-13 68856]
          "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
          .
          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-02-13 1033512]
          "RtHDVCpl"="RtHDVCpl.exe" [2008-08-06 6265376]
          "BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-06 34040]
          "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-20 13543968]
          "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-08-20 92704]
          "WarReg_PopUp"="c:\program files\eMachines\WR_PopUp\WarReg_PopUp.exe" [2008-05-09 49152]
          "LManager"="c:\progra~1\LAUNCH~1\QtZyEmachine.EXE" [2008-06-24 817672]
          "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-24 30192]
          "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
          "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
          "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
          "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-12-24 981680]
          "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
          "ConsentPromptBehaviorAdmin"= 0 (0x0)
          "EnableLUA"= 0 (0x0)
          "PromptOnSecureDesktop"= 0 (0x0)
          "EnableUIADesktopToggle"= 0 (0x0)
          .
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
          @="Service"
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
          LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
          LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
          .
          Contenu du dossier 'Tâches planifiées'
          .
          2012-01-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
          - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-21 16:20]
          .
          2012-01-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
          - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-21 16:20]
          .
          .
          ------- Examen supplémentaire -------
          .
          uStart Page = hxxp://www.google.com/
          uInternet Settings,ProxyOverride = *.local
          IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
          TCP: DhcpNameServer = 192.168.1.1
          DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab
          FF - ProfilePath - c:\users\FV\AppData\Roaming\Mozilla\Firefox\Profiles\7ezrw9ux.default\
          FF - prefs.js: browser.search.selectedEngine - Web Search
          FF - prefs.js: network.proxy.type - 0
          .
          - - - - ORPHELINS SUPPRIMES - - - -
          .
          HKLM-RunOnce-<NO NAME> - (no file)
          .
          .
          .
          **************************************************************************
          .
          catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2012-01-22 11:34
          Windows 6.0.6002 Service Pack 2 NTFS
          .
          Recherche de processus cachés ...
          .
          Recherche d'éléments en démarrage automatique cachés ...
          .
          Recherche de fichiers cachés ...
          .
          Scan terminé avec succès
          Fichiers cachés: 0
          .
          **************************************************************************
          .
          [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc]
          "ImagePath"="c:\windows\system32\GameMon.des -service"
          .
          --------------------- CLES DE REGISTRE BLOQUEES ---------------------
          .
          [HKEY_USERS\S-1-5-21-1424949869-300242620-2581555811-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
          @Allowed: (Read) (RestrictedCode)
          "??"=hex:4c,0b,86,89,b6,97,53,8b,8e,cd,26,18,aa,59,fd,d0,a0,47,48,9f,e4,d6,ee,
          0f,e1,07,76,5d,d2,31,d1,19,69,0f,af,e1,04,e5,c9,28,3d,ac,ef,33,b4,fc,19,c9,\
          "??"=hex:d5,ca,29,05,79,32,36,4d,92,58,b4,49,7f,2e,99,a3
          .
          [HKEY_USERS\S-1-5-21-1424949869-300242620-2581555811-1000\Software\SecuROM\License information*]
          @Allowed: (Read) (RestrictedCode)
          "datasecu"=hex:6e,6e,cb,54,a4,35,24,67,a5,c9,8c,27,b3,fb,bb,27,ed,bf,4e,54,f9,
          cf,23,b6,69,0d,c9,53,9a,b1,d6,d7,83,d2,bb,41,82,f9,c3,de,05,16,a8,97,23,70,\
          "rkeysecu"=hex:6f,5c,8a,0f,80,9f,9a,90,27,6c,32,0e,25,49,4f,db
          .
          [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
          @Denied: (A) (Users)
          @Denied: (A) (Everyone)
          @Allowed: (B 1 2 3 4 5) (S-1-5-20)
          "BlindDial"=dword:00000000
          .
          Heure de fin: 2012-01-22 11:37:16
          ComboFix-quarantined-files.txt 2012-01-22 10:37
          ComboFix2.txt 2012-01-17 10:10
          .
          Avant-CF: 24.725.348.352 octets libres
          Après-CF: 24.703.844.352 octets libres
          .
          - - End Of File - - 98215ACD33343F0BC86F32221DACADC2
          0
          1. Contributeur sécurité
            Re,
            1/
            (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

            * Double clique sur le raccourci UsbFix sur ton Bureau (clique droit avec la souris

            :exécuter en tant qu'administrateur pour vista/seven), l'installation se fera

            automatiquement

            * Clique sur "Suppression"

            * Laisse travailler l'outil

            * A la fin, le rapport va s'afficher : poste le dans ta prochaine réponse (il est aussi sauvegardé a la racine du disque dur)

            2/
            fais glisser une icone n'importe quel fichier sur Pre_scan , pre_script va apparaitre

            ouvre Pre_script et colle ce qui suit en gras, à l'interieur du texte qui s'ouvre ,
            sans les lignes , en une seule fois en le mettant en surbrillance :
            ___________________________________________________
            Kill::
            Registry::
            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
            "ITBar7Layout"=-
            "IT Bar7Height"=-
            [-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\0c62630e-45d6-4a74-826e-6812f9cdf2b5]
            [-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\3d792946-75f9-4d46-9643-c81d87508934]
            [-HKLM\Software\BrowserChoice]

            folder::
            C:\Program Files\Softonic_France
            C:\ProgramData\08s8760v80874e8ca0sdtd431
            C:\Users\FV\AppData\Local\08s8760v80874e8ca0sdtd431

            attrib::
            ___________________________________________________

            copie-le (ctrl+c ou clique droit sur la selection puis => copier)

            puis onglet fichier => enregistrer (pas enregistrer sous...) , puis ferme le texte

            des fenetres noires risquent de clignoter , c'est normal , c'est le programme qui travaille

            poste Pre_Script.txt qui apparaitra sur le bureau en fin de travail

            si ton bureau ne reapparait pas => ctrl+alt+supp , gestionnaire des taches => onglet fichier => nouvelle tache puis tape explorer

            0
            1. ma mémoire est de nouveau descendue à 21Go :-(
              Ok je branche mes trucs externes et je suis la démarche. merci
              0
              Précédent
              • 1
              • 2