Scan ZHP Diag inquétant
yoann090 Messages postés 10597 Statut Contributeur sécurité -
Désolé si j'ai fait un doublon une autre fois. J'ai posté et je n'arrivais plus à retrouver la page (mise en favori)
Bref, voici mon scan :
http://cjoint.com/?CArxBAVPIRh
End of the scan (2670 lines in 18mn 18s)(0)
- Scan ZHP Diag inquétant
- User diag - Télécharger - Informations & Diagnostic
- Zhp cleaner - Télécharger - Nettoyage
- Scan now - Guide
- Scan qr code pc - Guide
- Google traduction photo scan - Guide
29 réponses
- 1
- 2
L’analyse ZHPDiag et les crash dumps répétés sur Windows 7 montrent une erreur KERNEL_DATA_INPAGE_ERROR associée à ntoskrnl.exe et discache.sys, suggérant un problème potentiel au niveau du pilote ou du matériel. Des éléments de réponse indiquent que douze dumps ont été analysés et qu’aucun pilote tiers n’a été identifié, avec une recommandation d’activer un dump mémoire complet. En pratique, le diagnostic suggère que le problème peut provenir d’un pilote indisponible ou d’un souci de mémoire, et propose d’ajouter des outils comme Malwarebytes et VirusTotal pour vérifier des composants. Une information utile supplémentaire précise que l’analyse ne décelait pas de pilotes actifs problématiques mais recommande de sauvegarder les dumps et d’observer les éventuels crashs pour guider une résolution durable.
Tu as des adwares (pubs, toolbar, ...)
Télécharge AdwCleaner ici : http://general-changelog-team.fr/fr/downloads/viewdownload/20-outils-de-xplode/2-adwcleaner
( d'Xplode ) sur ton bureau :
Lance le, clique sur *[Suppression]* puis patiente le temps du scan.
Une fois le scan fini, un rapport s'ouvrira. Poste moi son contenu dans ta prochaine réponse.
Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt
Les toolbars, c'est pas obligatoire ( par Malekal ) :https://forum.malekal.com/viewtopic.php?t=6173&start=
Pour eviter de perdre un sujet, laisse la case recevoir les reponses par mail cochée ou inscrit toi, tu auras ainsi tes discussions gardées en mémoire.
Suis ce tutoriel et donne le rapport dans ta prochaine reponse :
http://www.security-helpzone.com/Thread-MalwareBytes-Anti-Malware-MBAM-Scan-complet
@+
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre questionCette fois-ci, j'ai mis le sujet dans mes favoris et j'ai activé la réponse par mail.
Je vais suivre ce tuto
EDIT : Le scan complet est bien en cours. Les deux Updates de Java 6 ont bien été supprimés.
Merci pour l'aide et l'attention que tu me portes.
Exécute https://forum.malekal.com/viewtopic.php?t=16793&start=#p132880 who crashed et poste le rapport
@+
System Information (local)
--------------------------------------------------------------------------------
computer name: CAMILLE-PC
windows version: Windows 7 Service Pack 1, 6.1, build: 7601
windows dir: C:\Windows
CPU: GenuineIntel Intel(R) Core(TM) i5-2410M CPU @ 2.30GHz Intel586, level: 6
4 logical processors, active mask: 15
RAM: 4139630592 total
VM: 2147352576, free: 1913663488
--------------------------------------------------------------------------------
Crash Dump Analysis
--------------------------------------------------------------------------------
Crash dump directory: C:\Windows\Minidump
Crash dumps are enabled on your computer.
On Mon 21/01/2013 21:36:21 GMT your computer crashed
crash dump file: C:\Windows\Minidump\012113-78218-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x7EFC0)
Bugcheck code: 0x7A (0x4, 0x0, 0xFFFFFA800B9B1D20, 0xFFFFF8A011C6B744)
Error: KERNEL_DATA_INPAGE_ERROR
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This bug check indicates that the requested page of kernel data from the paging file could not be read into memory.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.
On Mon 21/01/2013 21:36:21 GMT your computer crashed
crash dump file: C:\Windows\memory.dmp
This was probably caused by the following module: discache.sys (discache+0x52DA)
Bugcheck code: 0x7A (0x4, 0x0, 0xFFFFFA800B9B1D20, 0xFFFFF8A011C6B744)
Error: KERNEL_DATA_INPAGE_ERROR
file path: C:\Windows\system32\drivers\discache.sys
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: System Indexer/Cache Driver
Bug check description: This bug check indicates that the requested page of kernel data from the paging file could not be read into memory.
The crash took place in a standard Microsoft module. Your system configuration may be incorrect. Possibly this problem is caused by another driver on your system that cannot be identified at this time.
On Mon 21/01/2013 07:56:56 GMT your computer crashed
crash dump file: C:\Windows\Minidump\012113-82306-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x7EFC0)
Bugcheck code: 0x7A (0x4, 0x0, 0xFFFFFA80050C4E90, 0x317AF00)
Error: KERNEL_DATA_INPAGE_ERROR
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This bug check indicates that the requested page of kernel data from the paging file could not be read into memory.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.
On Sun 20/01/2013 11:42:46 GMT your computer crashed
crash dump file: C:\Windows\Minidump\012013-81260-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x7EFC0)
Bugcheck code: 0x7A (0x4, 0x0, 0xFFFFFA800AA59110, 0x253C7C2)
Error: KERNEL_DATA_INPAGE_ERROR
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This bug check indicates that the requested page of kernel data from the paging file could not be read into memory.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.
On Sun 20/01/2013 00:47:39 GMT your computer crashed
crash dump file: C:\Windows\Minidump\012013-87625-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x7EFC0)
Bugcheck code: 0x7A (0x4, 0x0, 0xFFFFFA80092AF010, 0x2C66664)
Error: KERNEL_DATA_INPAGE_ERROR
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This bug check indicates that the requested page of kernel data from the paging file could not be read into memory.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.
On Fri 18/01/2013 23:02:29 GMT your computer crashed
crash dump file: C:\Windows\Minidump\011913-100121-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x7EFC0)
Bugcheck code: 0x7A (0x4, 0x0, 0xFFFFFA800A354010, 0x9F844F0)
Error: KERNEL_DATA_INPAGE_ERROR
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This bug check indicates that the requested page of kernel data from the paging file could not be read into memory.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.
On Fri 18/01/2013 22:23:09 GMT your computer crashed
crash dump file: C:\Windows\Minidump\011813-107141-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x7EFC0)
Bugcheck code: 0x7A (0x4, 0x0, 0xFFFFFA80087AEB60, 0xFF34FF8)
Error: KERNEL_DATA_INPAGE_ERROR
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This bug check indicates that the requested page of kernel data from the paging file could not be read into memory.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.
On Fri 18/01/2013 00:15:53 GMT your computer crashed
crash dump file: C:\Windows\Minidump\011813-90340-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x7EFC0)
Bugcheck code: 0x7A (0x4, 0x0, 0xFFFFFA800A0EB1D0, 0x79F684)
Error: KERNEL_DATA_INPAGE_ERROR
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This bug check indicates that the requested page of kernel data from the paging file could not be read into memory.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.
On Thu 17/01/2013 23:42:36 GMT your computer crashed
crash dump file: C:\Windows\Minidump\011813-119761-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x7EFC0)
Bugcheck code: 0x7A (0x4, 0x0, 0xFFFFFA80078D2C30, 0x422A114)
Error: KERNEL_DATA_INPAGE_ERROR
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This bug check indicates that the requested page of kernel data from the paging file could not be read into memory.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.
On Wed 09/01/2013 22:45:45 GMT your computer crashed
crash dump file: C:\Windows\Minidump\011013-74693-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x7EFC0)
Bugcheck code: 0x9F (0x3, 0xFFFFFA8004D48A10, 0xFFFFF800048BF3D8, 0xFFFFFA800BB1B2A0)
Error: DRIVER_POWER_STATE_FAILURE
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This bug check indicates that the driver is in an inconsistent or invalid power state.
This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.
On Wed 09/01/2013 18:43:49 GMT your computer crashed
crash dump file: C:\Windows\Minidump\010913-79014-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x7EFC0)
Bugcheck code: 0x7A (0x4, 0x0, 0xFFFFFA800AF40010, 0x133162A8)
Error: KERNEL_DATA_INPAGE_ERROR
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This bug check indicates that the requested page of kernel data from the paging file could not be read into memory.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.
On Tue 01/01/2013 15:49:15 GMT your computer crashed
crash dump file: C:\Windows\Minidump\010113-98920-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x7EFC0)
Bugcheck code: 0x7A (0x4, 0x0, 0xFFFFFA800A505B50, 0x15F37F44)
Error: KERNEL_DATA_INPAGE_ERROR
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This bug check indicates that the requested page of kernel data from the paging file could not be read into memory.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.
--------------------------------------------------------------------------------
Conclusion
--------------------------------------------------------------------------------
12 crash dumps have been found and analyzed. No offending third party drivers have been found. Consider configuring your system to produce a full memory dump for better analysis.
touches Windows + pause pour afficher les propriétés système
clique sur onglet "avancé" puis sur "paramètres " du paragraphe "performances"
clique sur le nouveau bouton "avancé" et clique sur "modifier" du paragraphe "mémoire virtuelle"
augmente la taille du fichier d'échange. genre tu mets 4 gb.
Fais analyser le(s) fichier(s) suivants sur Virustotal :
Virus Total
clique sur "Parcourir" et trouve puis selectionne ce(s) fichier(s) :
C:\Windows\system32\drivers\discache.sys
*
* Clique maintenant sur Envoyer le fichier. et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
* Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
* Lorsque l'analyse est terminée colle le lien de(s)( la) page(s) dans ta prochaine réponse.
On Tue 22/01/2013 02:25:55 GMT your computer crashed
crash dump file: C:\Windows\Minidump\012213-109918-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x7EFC0)
Bugcheck code: 0x7A (0x4, 0x0, 0xFFFFFA8004A6F890, 0x41A1C4F)
Error: KERNEL_DATA_INPAGE_ERROR
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This bug check indicates that the requested page of kernel data from the paging file could not be read into memory.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.
On Tue 22/01/2013 02:25:55 GMT your computer crashed
crash dump file: C:\Windows\memory.dmp
This was probably caused by the following module: ntkrnlmp.exe (nt!KeBugCheckEx+0x0)
Bugcheck code: 0x7A (0x4, 0x0, 0xFFFFFA8004A6F890, 0x41A1C4F)
Error: KERNEL_DATA_INPAGE_ERROR
Bug check description: This bug check indicates that the requested page of kernel data from the paging file could not be read into memory.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.
File already analysed
This file was already analysed by VirusTotal on 2013-01-21 14:55:31.
Detection ratio: 0/46
You can take a look at the last analysis or analyse it again now.
Et voilà ce qui s'affiche lorsque je clique sur last analysis :
SHA256: 1e44981b684f3e56f5d2439bb7fa78bd1bc876bb2265ae089aec68f241b05b26
SHA1: 5ac369d76d668f41ac51ec03e5baee01eeb23539
MD5: 13096b05847ec78f0977f2c0f79e9ab3
File size: 39.5 KB ( 40448 bytes )
File name: syscache.sys
File type: unknown
Tags: signed mz
Detection ratio: 0 / 46
Analysis date: 2013-01-21 14:55:31 UTC ( 1 jour, 8 heures ago )
Je tiens à préciser que je n'ai jamais réussi à faire ce test auparavant et qu'à 14h55, j'étais en cours.
Pour Malwarebyte vu qu'il crash a chaque fois en mode normal essaye de faire le scan en mode sans échec.
https://www.commentcamarche.net/informatique/windows/113-demarrer-windows-10-en-mode-sans-echec/#demarrer-en-mode-sans-echec-avec-windows-7-vista-et-xp
Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
Options d'examen désactivées: P2P
Elément(s) analysé(s): 650863
Temps écoulé: 2 heure(s), 57 minute(s), 19 seconde(s)
Processus mémoire détecté(s): 0
(Aucun élément nuisible détecté)
Module(s) mémoire détecté(s): 0
(Aucun élément nuisible détecté)
Clé(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)
Valeur(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)
Elément(s) de données du Registre détecté(s): 0
(Aucun élément nuisible détecté)
Dossier(s) détecté(s): 0
(Aucun élément nuisible détecté)
Fichier(s) détecté(s): 24
C:\Program Files\Adobe\Adobe After Effects CS6\Support Files\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\AMTLib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files\Adobe\Adobe Encore CS6\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files\Adobe\Adobe Illustrator CS6 (64 Bit)\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files\Adobe\Adobe Media Encoder CS6\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files\Adobe\Adobe Premiere Pro CS6\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files\Adobe\Adobe Premiere Pro CS6\Legal\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files\Adobe\Adobe SpeedGrade CS6\bin\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files (x86)\Adobe\Adobe Audition CS6\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files (x86)\Adobe\Adobe Bridge CS6\AMTLib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files (x86)\Adobe\Adobe Fireworks CS6\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files (x86)\Adobe\Adobe Flash CS6\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files (x86)\Adobe\Adobe Illustrator CS6\Support Files\Contents\Windows\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files (x86)\Adobe\Adobe InDesign CS6\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files (x86)\Adobe\Adobe Photoshop CS6\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files (x86)\Adobe\Adobe Prelude CS6\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files (x86)\Adobe\Adobe Utilities - CS6\ExtendScript Toolkit CS6\amtlib.dll (PUP.RiskwareTool.CK) -> Aucune action effectuée.
C:\Program Files (x86)\MaxTV\Common\hstart.exe (PUP.HiddenStart.H) -> Aucune action effectuée.
C:\Program Files (x86)\MaxTV\MaxTV4\tools\hstart.exe (PUP.HiddenStart.H) -> Aucune action effectuée.
C:\Users\Camille\Documents\Ancien PC\Downloads\VLCSetup.exe (Adware.Hotbar) -> Aucune action effectuée.
C:\Users\Camille\Downloads\Naruto_Shippuden_119_120_VostFr_HQ_MP4_Kakashi_Gaiden_Special_by_nitrat_mp4.exe (PUP.Adware.Agent) -> Aucune action effectuée.
(fin)
- 1
- 2
Java 6 Update 29
Java 6 Update 35