Windows explorer a cessé de fonctionner ! - Page 2

Précédent
  • 1
  • 2
  1. fmounet007 Messages postés 22 Statut Membre
     
    bonjour!
    Je n'ai qu'une clé USB et un disque dur externe, dont je ne me sers que pour mettre des photos que j'ai prises et des doc word.
    Je doute que ce soit la source du problème.
    Cependant ma mémoire libre descend encore. J'avais 24Go de libres... maintenant il en reste 21.... sans rien télécharger, ni installer. Comment cela se fait?
    merci
    0
  2. Fish66 Messages postés 18337 Statut Contributeur sécurité 1 318
     
    Bonjour,
    1/
    Tu lances USBFix sans rien inséré, merci
    2/
    Tu lances de nouveau combofix comme expliqué ici puis tu postes le rapport

    3/
    Cependant ma mémoire libre descend encore. J'avais 24Go de libres... maintenant il en reste 21.... sans rien télécharger, ni installer. Comment cela se fait? 

    C'est à cause des infections!

    @+
    0
  3. fmounet007 Messages postés 22 Statut Membre
     
    Usbfix a donné un rapport, le voici:
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (2888)
    C:\Program Files\Windows Media Player\wmpnscfg.exe (2896)
    C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (2960)
    C:\Windows\system32\svchost.exe (3008)
    C:\Windows\system32\svchost.exe (3028)
    C:\Windows\System32\svchost.exe (3076)
    C:\Windows\system32\SearchIndexer.exe (3112)
    C:\Program Files\Windows Media Player\wmpnetwk.exe (3944)
    C:\Windows\system32\wbem\unsecapp.exe (820)
    C:\Windows\system32\wbem\wmiprvse.exe (1936)
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (4092)
    C:\Windows\system32\svchost.exe (3604)
    C:\Windows\system32\wuauclt.exe (3916)
    C:\Program Files\Common Files\Java\Java Update\jucheck.exe (3692)
    C:\Program Files\Mozilla Firefox\firefox.exe (3536)
    C:\Windows\system32\svchost.exe (1300)
    C:\Program Files\Mozilla Firefox\plugin-container.exe (3940)
    C:\Windows\system32\SearchProtocolHost.exe (3308)
    C:\Windows\system32\SearchFilterHost.exe (264)
    C:\UsbFix\Go.exe (2992)
    C:\Windows\system32\wbem\wmiprvse.exe (2208)

    ################## | Éléments infectieux |

    Présent! E:\autorun.exe
    Présent! E:\autorun.inf

    ################## | Registre |

    Présent! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
    Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives

    ################## | Mountpoints2 |

    ################## | Vaccin |

    (!) Cet ordinateur n'est pas vacciné!

    ################## | E.O.F |
    0
  4. fmounet007 Messages postés 22 Statut Membre
     
    voici le rapprt combofix:
    ComboFix 12-01-16.05 - FV 22/01/2012 11:33:02.2.2 - x86
    Microsoft® Windows Vista(TM) Édition Familiale Basique 6.0.6002.2.1252.32.1036.18.1790.927 [GMT 1:00]
    Lancé depuis: c:\users\FV\Desktop\ComboFix.exe
    AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
    SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    - Mode FONCTIONNALITES REDUITES -
    .
    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2011-12-22 au 2012-01-22 ))))))))))))))))))))))))))))))))))))
    .
    .
    2012-01-22 10:34 . 2012-01-22 10:34 -------- d-----w- c:\users\Default\AppData\Local\temp
    2012-01-22 09:45 . 2012-01-22 09:50 -------- d-----w- C:\UsbFix
    2012-01-21 16:59 . 2012-01-06 04:19 6557240 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9D5CC768-018F-4587-B5B7-42234388CCF5}\mpengine.dll
    2012-01-20 11:37 . 2012-01-20 11:42 -------- d-----w- C:\Kill'em
    2012-01-20 11:26 . 2012-01-20 11:26 -------- d-----w- C:\_OTM
    2012-01-18 14:05 . 2012-01-18 14:07 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys
    2012-01-14 11:23 . 2011-11-17 06:48 440192 ----a-w- c:\windows\system32\drivers\ksecdd.sys
    2012-01-14 11:23 . 2011-11-16 16:23 377344 ----a-w- c:\windows\system32\winhttp.dll
    2012-01-14 11:23 . 2011-11-16 16:23 72704 ----a-w- c:\windows\system32\secur32.dll
    2012-01-14 11:23 . 2011-11-16 16:23 278528 ----a-w- c:\windows\system32\schannel.dll
    2012-01-14 11:23 . 2011-11-16 16:21 1259008 ----a-w- c:\windows\system32\lsasrv.dll
    2012-01-14 11:23 . 2011-11-16 14:12 9728 ----a-w- c:\windows\system32\lsass.exe
    2012-01-11 07:37 . 2011-10-14 16:03 189952 ----a-w- c:\windows\system32\winmm.dll
    2012-01-11 07:37 . 2011-10-14 16:00 23552 ----a-w- c:\windows\system32\mciseq.dll
    2012-01-11 07:37 . 2011-11-18 20:23 1205064 ----a-w- c:\windows\system32\ntdll.dll
    2012-01-11 07:37 . 2011-11-18 17:47 66560 ----a-w- c:\windows\system32\packager.dll
    2012-01-11 07:37 . 2011-11-25 15:59 376320 ----a-w- c:\windows\system32\winsrv.dll
    2012-01-11 07:37 . 2011-12-01 15:21 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
    2012-01-11 07:36 . 2011-10-25 15:58 1314816 ----a-w- c:\windows\system32\quartz.dll
    2012-01-11 07:36 . 2011-10-25 15:58 497152 ----a-w- c:\windows\system32\qdvd.dll
    2012-01-08 09:00 . 2012-01-08 09:00 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll
    2012-01-08 09:00 . 2012-01-08 09:00 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll
    2012-01-08 09:00 . 2012-01-08 09:00 43992 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll
    2012-01-08 09:00 . 2012-01-08 09:00 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-01-06 04:19 . 2011-10-03 10:15 6557240 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2012-01-04 06:01 . 2011-09-18 08:47 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-12-10 14:24 . 2011-05-29 14:37 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-11-23 13:37 . 2011-12-14 07:41 2043904 ----a-w- c:\windows\system32\win32k.sys
    2011-11-08 14:42 . 2011-12-14 07:41 2048 ----a-w- c:\windows\system32\tzres.dll
    2011-11-03 06:22 . 2011-12-14 07:41 916992 ----a-w- c:\windows\system32\wininet.dll
    2011-11-03 06:17 . 2011-12-14 07:41 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2011-11-03 06:17 . 2011-12-14 07:41 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
    2011-11-03 06:17 . 2011-12-14 07:41 109056 ----a-w- c:\windows\system32\iesysprep.dll
    2011-11-03 06:17 . 2011-12-14 07:41 71680 ----a-w- c:\windows\system32\iesetup.dll
    2011-11-03 05:22 . 2011-12-14 07:41 385024 ----a-w- c:\windows\system32\html.iec
    2011-11-03 04:45 . 2011-12-14 07:41 133632 ----a-w- c:\windows\system32\ieUnatt.exe
    2011-11-03 04:43 . 2011-12-14 07:41 1638912 ----a-w- c:\windows\system32\mshtml.tlb
    2011-10-27 08:01 . 2011-12-14 07:41 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2011-10-27 08:01 . 2011-12-14 07:41 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
    2011-10-25 15:56 . 2011-12-14 07:41 49152 ----a-w- c:\windows\system32\csrsrv.dll
    2012-01-08 09:00 . 2011-10-02 09:07 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    .
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-13 68856]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-02-13 1033512]
    "RtHDVCpl"="RtHDVCpl.exe" [2008-08-06 6265376]
    "BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-06 34040]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-20 13543968]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-08-20 92704]
    "WarReg_PopUp"="c:\program files\eMachines\WR_PopUp\WarReg_PopUp.exe" [2008-05-09 49152]
    "LManager"="c:\progra~1\LAUNCH~1\QtZyEmachine.EXE" [2008-06-24 817672]
    "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-24 30192]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
    "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-12-24 981680]
    "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "EnableLUA"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @="Service"
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
    .
    Contenu du dossier 'Tâches planifiées'
    .
    2012-01-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-21 16:20]
    .
    2012-01-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-21 16:20]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.google.com/
    uInternet Settings,ProxyOverride = *.local
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    TCP: DhcpNameServer = 192.168.1.1
    DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab
    FF - ProfilePath - c:\users\FV\AppData\Roaming\Mozilla\Firefox\Profiles\7ezrw9ux.default\
    FF - prefs.js: browser.search.selectedEngine - Web Search
    FF - prefs.js: network.proxy.type - 0
    .
    - - - - ORPHELINS SUPPRIMES - - - -
    .
    HKLM-RunOnce-<NO NAME> - (no file)
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2012-01-22 11:34
    Windows 6.0.6002 Service Pack 2 NTFS
    .
    Recherche de processus cachés ...
    .
    Recherche d'éléments en démarrage automatique cachés ...
    .
    Recherche de fichiers cachés ...
    .
    Scan terminé avec succès
    Fichiers cachés: 0
    .
    **************************************************************************
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc]
    "ImagePath"="c:\windows\system32\GameMon.des -service"
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------
    .
    [HKEY_USERS\S-1-5-21-1424949869-300242620-2581555811-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
    @Allowed: (Read) (RestrictedCode)
    "??"=hex:4c,0b,86,89,b6,97,53,8b,8e,cd,26,18,aa,59,fd,d0,a0,47,48,9f,e4,d6,ee,
    0f,e1,07,76,5d,d2,31,d1,19,69,0f,af,e1,04,e5,c9,28,3d,ac,ef,33,b4,fc,19,c9,\
    "??"=hex:d5,ca,29,05,79,32,36,4d,92,58,b4,49,7f,2e,99,a3
    .
    [HKEY_USERS\S-1-5-21-1424949869-300242620-2581555811-1000\Software\SecuROM\License information*]
    @Allowed: (Read) (RestrictedCode)
    "datasecu"=hex:6e,6e,cb,54,a4,35,24,67,a5,c9,8c,27,b3,fb,bb,27,ed,bf,4e,54,f9,
    cf,23,b6,69,0d,c9,53,9a,b1,d6,d7,83,d2,bb,41,82,f9,c3,de,05,16,a8,97,23,70,\
    "rkeysecu"=hex:6f,5c,8a,0f,80,9f,9a,90,27,6c,32,0e,25,49,4f,db
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    Heure de fin: 2012-01-22 11:37:16
    ComboFix-quarantined-files.txt 2012-01-22 10:37
    ComboFix2.txt 2012-01-17 10:10
    .
    Avant-CF: 24.725.348.352 octets libres
    Après-CF: 24.703.844.352 octets libres
    .
    - - End Of File - - 98215ACD33343F0BC86F32221DACADC2
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Fish66 Messages postés 18337 Statut Contributeur sécurité 1 318
     
    Re,
    1/
    (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

    * Double clique sur le raccourci UsbFix sur ton Bureau (clique droit avec la souris

    :exécuter en tant qu'administrateur pour vista/seven), l'installation se fera

    automatiquement

    * Clique sur "Suppression"

    * Laisse travailler l'outil

    * A la fin, le rapport va s'afficher : poste le dans ta prochaine réponse (il est aussi sauvegardé a la racine du disque dur)

    2/
    fais glisser une icone n'importe quel fichier sur Pre_scan , pre_script va apparaitre

    ouvre Pre_script et colle ce qui suit en gras, à l'interieur du texte qui s'ouvre ,
    sans les lignes , en une seule fois en le mettant en surbrillance :
    ___________________________________________________
    Kill::
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
    "ITBar7Layout"=-
    "IT Bar7Height"=-
    [-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\0c62630e-45d6-4a74-826e-6812f9cdf2b5]
    [-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\3d792946-75f9-4d46-9643-c81d87508934]
    [-HKLM\Software\BrowserChoice]

    folder::
    C:\Program Files\Softonic_France
    C:\ProgramData\08s8760v80874e8ca0sdtd431
    C:\Users\FV\AppData\Local\08s8760v80874e8ca0sdtd431

    attrib::
    ___________________________________________________

    copie-le (ctrl+c ou clique droit sur la selection puis => copier)

    puis onglet fichier => enregistrer (pas enregistrer sous...) , puis ferme le texte

    des fenetres noires risquent de clignoter , c'est normal , c'est le programme qui travaille

    poste Pre_Script.txt qui apparaitra sur le bureau en fin de travail

    si ton bureau ne reapparait pas => ctrl+alt+supp , gestionnaire des taches => onglet fichier => nouvelle tache puis tape explorer

    0
  7. fmounet007 Messages postés 22 Statut Membre
     
    ma mémoire est de nouveau descendue à 21Go :-(
    Ok je branche mes trucs externes et je suis la démarche. merci
    0
Précédent
  • 1
  • 2