Fichier "hs_err_pid1348.log" sur mon bur

Bonjour a tous
Configuration: Windows XP
Internet Explorer 7.0

11 réponses

  1. Désolé
    Une mauvaise manip.
    Voila, un fichier "hs_err_pid1348.log apparait sur mon bureau"
    Je n'ai aucune idée de ce que c'est.
    Ca commence par :
    #
    # An unexpected error has been detected by HotSpot Virtual Machine:
    #
    # EXCEPTION_ACCESS_VIOLATION (0xc0000005) at pc=0x0a977ab9, pid=1348, tid=3172
    #
    # Java VM: Java HotSpot(TM) Client VM (1.5.0_06-b05 mixed mode)
    # Problematic frame:
    # C 0x0a977ab9
    #

    Et il y en a une pleine page toute en anglais.

    Je ne suis pas sur en fait que ce soit un probleme de sécurité.
    Mais j'ai fait un rapport hijackthis au cas ou.
    Si quelqu'un pouvait m'aider, ce serait sympa;

    J'ai mis en gras ce qui me parait bizarre.

    Logfile of HijackThis v1.99.1
    Scan saved at 11:03:35, on 08/01/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZONELABS\vsmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\system32\dslagent.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.acer.com/worldwide/selection.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    O4 - HKLM\..\Run: [Alaunch] C:\Windows\alaunch.exe
    O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
    O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O14 - IERESET.INF: START_PAGE_URL=https://www.acer.com/worldwide/selection.html
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe

    Merci pour toute aide qui pourra m'etre apporté.
    0
    1. Contributeur
      slt,

      Relance Hijack,choisi « do a scan only » ou « scanner seulement » coches ces lignes :

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)


      Ferme toutes les fenêtres actives autres que HijackThis!, navigateur inclus, puis clique « Fix checked » ou « fixer objet ». Ferme HijackThis!

      la 011 correspond a Internet explorer 7 (elle est légitime).

      par contre désinstalle ewido vu que tu as AVG antispyware est qu'ils font le même boulot.

      Et désactive AVG du démarrage et empeche le tourner comme un service (comme suit)

      Arrête ce service

      AVG Anti-Spyware Guard

      pour ça fais cette manip :

      Démarrer -> executer tape services.msc clic droit sur le service cité - > propriétés et dans "type de démarrage" et mets le sur "manuel".

      Ainsi que dans l'onglet "démarrage" décoche "avgas".

      redémarre ton PC.

      ===================================

      ensuite :

      Télécharges smitfraudfix:(merci a S!RI pour ce programme)

      En image :
      http://siri.urz.free.fr/Fix/SmitfraudFix.php

      tu le décompresses tu doubles cliques sur smitfraudfix.cmd et tu choisis l option 1
      cela vas générer un rapport.
      Si tu vois des lignes avec PRESENT!

      - > Continue la manip qui suit.

      * Redémarres le PC en mode sans échec : Au démarrage tu tapotes sur la touche F8 de ton clavier (ou F5 ) et tu choisis le [mode sans échec]

      * Ouvre le dossier [SmitfraudFix] et double clic sur Smitfraudfix.cmd, choisit l’option 2 et tu réponds oui à tout.

      Copie/colle le rapport sur le forum stp.

      a+
      0
      1. Bonjour Sèb08 et merci pour ta réponse.
        Désolé de ne pas t'avoir repondu tout de suite mais quand j'ai un problème sur mon ordi je préfère communiquer via l'ordinateur du boulot pour ne pas tenter le diable.

        J'ai fais tout ce que tu m'a dit mais je n'ai pas trouvé de ligne marqué "présent"
        voila le rapport
        (comme ici j'utilise mac la police est un peu différente)
        SmitFraudFix v2.128

        Rapport fait ‡ 22:30:59,12, 08/01/2007
        ExecutÈ ‡ partir de C:\Documents and Settings\StÇphane\Bureau\Smitfraudfix\SmitfraudFix
        OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
        Le type du systËme de fichiers est FAT32
        Fix executÈ en mode normal

        ªªªªªªªªªªªªªªªªªªªªªªªª C:\

        ªªªªªªªªªªªªªªªªªªªªªªªª C:\WINDOWS

        ªªªªªªªªªªªªªªªªªªªªªªªª C:\WINDOWS\system

        ªªªªªªªªªªªªªªªªªªªªªªªª C:\WINDOWS\Web

        ªªªªªªªªªªªªªªªªªªªªªªªª C:\WINDOWS\system32

        ªªªªªªªªªªªªªªªªªªªªªªªª C:\WINDOWS\system32\LogFiles

        ªªªªªªªªªªªªªªªªªªªªªªªª C:\Documents and Settings\StÇphane

        ªªªªªªªªªªªªªªªªªªªªªªªª C:\Documents and Settings\StÇphane\Application Data

        ªªªªªªªªªªªªªªªªªªªªªªªª Menu DÈmarrer

        ªªªªªªªªªªªªªªªªªªªªªªªª C:\DOCUME~1\ST…PHANE\FAVORIS

        ªªªªªªªªªªªªªªªªªªªªªªªª Bureau

        ªªªªªªªªªªªªªªªªªªªªªªªª C:\Program Files

        ªªªªªªªªªªªªªªªªªªªªªªªª ClÈs corrompues

        ªªªªªªªªªªªªªªªªªªªªªªªª ElÈments du bureau

        ªªªªªªªªªªªªªªªªªªªªªªªª Sharedtaskscheduler
        !!!Attention, les clÈs qui suivent ne sont pas forcÈment infectÈes!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        ªªªªªªªªªªªªªªªªªªªªªªªª AppInit_DLLs
        !!!Attention, les clÈs qui suivent ne sont pas forcÈment infectÈes!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
        "AppInit_DLLs"=""

        ªªªªªªªªªªªªªªªªªªªªªªªª Winlogon.System
        !!!Attention, les clÈs qui suivent ne sont pas forcÈment infectÈes!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
        "System"=""

        ªªªªªªªªªªªªªªªªªªªªªªªª pe386-msguard-lzx32

        ªªªªªªªªªªªªªªªªªªªªªªªª Recherche infection wininet.dll

        ªªªªªªªªªªªªªªªªªªªªªªªª Fin

        ---------------------------------------------------------------------

        Je n'ai donc rien supprimé mais je suis toujour inquiet a cause du fichier qui est apparu sur mon bureau
        J'ai fait un scan (avast) en mode sans echec mais il n'a rien détecté.

        Voila, je me demande si je peux me connecté en toute sécurité?

        Encore merci a toi
        0
    2. Contributeur
      La version de smitfraudfix n'est pas la bonne...
      tu as bien pris celle de mon lien ?

      Le fix a bien été utilisé de ton PC ?

      a+
      0
      1. Bonjour Seb08
        Oui je l'ai bien utilisé sur le bon PC
        Par contre j'ai utilisé une version que m'avait donné lyonnais92 le mois dernier pour un autre probleme.
        je suis désolé, je ne pensais pas que c'était différent.
        Je vais téléchargé le tien et l'appliquer ce soir.

        Par contre, j'ai Spybot search&destroy qui a détecté un problème.
        Nom affiché : 32bit Systembus driver
        Clé du registre : sysbus 32.
        Il me dit ensuite qu'il a réparé mais il le redétecte a chaque scan
        Je ne sais pas si ca a un rapport.

        En tout cas merci a toi.
        0
        1. Contributeur
          donne moi un rapport de smitfraudfix avec le lien que je t'ai mis au <2>.

          Pour Spybot met le à jour et vaccine (voir démo)

          voir demo d utilisation (merci Balltrap)
          http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

          Ensuite redémarre en mode sans echec ->lance spybot et répare tout ce qu'il te trouve.

          A+
          0
          1. Bonjour Seb08
            Voila le rapport :
            SmitFraudFix v2.132

            Rapport fait à 23:39:23,60, 10/01/2007
            Executé à partir de C:\Documents and Settings\St‚phane\Bureau\Smitfraudfix
            OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
            Le type du système de fichiers est FAT32
            Fix executé en mode normal

            »»»»»»»»»»»»»»»»»»»»»»»» C:\

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\St‚phane

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\St‚phane\Application Data

            »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

            »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\STÉPHANE\FAVORIS

            »»»»»»»»»»»»»»»»»»»»»»»» Bureau

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

            »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

            »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLs"=""

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "System"=""

            »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

            »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

            »»»»»»»»»»»»»»»»»»»»»»»» Fin

            J'ai mis a jour Spybot, je vais maintenant l'appliquer en mode sans echec
            0
            1. Je comprend plus rien.
              J'ai mis a jour Spybot (en fait pas de MAJ a installer)
              J'ai redemarré en mode sans echec
              Et la il ne trouve plus rien....
              J'ai réessayé en mode normal.
              Il ne trouve rien non plus
              Je ne sais plus quoi penser.

              En fait, si il n'y avait pas ce fichier "hs_err_pid1348.log" qui s'était installé sur mon bureau, il n'y aurait rien d'anormal
              0
              1. Contributeur
                Peux tu scanner ce fichier :

                hs_err_pid1348.log

                en suivant ce chemin ->C:\Documents and Settings\Nom d'utilisateur\Bureau\hs_err_pid1348.log

                Avec ceci :

                http://www.virustotal.com/en/virustotalx.html

                clique sur « parcourir » va rechercher le fichier en question et ensuite clique sur « send ».

                Copie colle moi le rapport généré.

                A+
                0
                1. Bon, j'ai eu trop de boulot ces derniers jours.
                  Alors voila j'ai fait le scan ce matin :

                  AntiVir 7.3.0.21 01.09.2007 no virus found
                  Authentium 4.93.8 01.12.2007 no virus found
                  Avast 4.7.936.0 01.12.2007 no virus found
                  AVG 386 01.12.2007 no virus found
                  BitDefender 7.2 01.13.2007 no virus found
                  CAT-QuickHeal 9.00 01.12.2007 no virus found
                  ClamAV devel-20060426 01.12.2007 no virus found
                  DrWeb 4.33 01.13.2007 no virus found
                  eSafe 7.0.14.0 01.10.2007 no virus found
                  eTrust-InoculateIT 23.73.113 01.13.2007 no virus found
                  eTrust-Vet 30.3.3324 01.12.2007 no virus found
                  Ewido 4.0 01.12.2007 no virus found
                  Fortinet 2.82.0.0 01.13.2007 no virus found
                  F-Prot 3.16f 01.12.2007 no virus found
                  F-Prot4 4.2.1.29 01.12.2007 no virus found
                  Ikarus T3.1.0.27 01.09.2007 no virus found
                  Kaspersky 4.0.2.24 01.13.2007 no virus found
                  McAfee 4938 01.12.2007 no virus found
                  Microsoft 1.1904 01.13.2007 no virus found
                  NOD32v2 1975 01.13.2007 no virus found
                  Norman 5.80.02 01.12.2007 no virus found
                  Panda 9.0.0.4 01.12.2007 no virus found
                  Prevx1 V2 01.13.2007 no virus found
                  Sophos 4.13.0 01.11.2007 no virus found
                  Sunbelt 2.2.907.0 01.12.2007 no virus found
                  TheHacker 6.0.3.147 01.11.2007 no virus found
                  UNA 1.83 01.12.2007 no virus found
                  VBA32 3.11.2 01.12.2007 no virus found
                  VirusBuster 4.3.19:9 01.12.2007 no virus found

                  Aditional Information
                  File size: 14308 bytes
                  MD5: 5f8f278209b9576f4bd05ac015b9f641
                  SHA1: 4054260dd84eef19bba1d0aa04b5b6ef7098093d

                  Bref pas de virus
                  0
                  1. Contributeur
                    et lorsque tu double clic dessus pour l'ouvrir qu'est ce qu'il se passe ?

                    a+
                    0
                    1. bonjour,

                      viens de lire ton poste car meme pb ce jour ...
                      j'ai supp automatiquement ce fichier sans l'ouvrir (car Bit ne pouvait pas le scanner!) puis j'ai fais analyses (ewido, hijack, spy..) = rien detecté anormal

                      mais cela ne me dit pas comment est apparu ce fichier (failles, peer ?)
                      As tu infos ++ ?
                      Est il revenu depuis sur ton bureau?
                      0